CVE-2008-5789: Code Injection
Multiple PHP remote file inclusion vulnerabilities in the Recly Interactive Feederator (comfeederator) component 1.0.5 for Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the (1) mosConfigabsolutepath parameter to (a) addtmsp.php, (b) edittmsp.php and (c) tmsp.php in includes/tmsp/; and the (2) GLOBALS[mosConfigabsolutepath] parameter to (d) includes/tmsp/subscription.php.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-5789?
CVE-2008-5789 is classified as a high severity vulnerability due to its potential for remote code execution.
How do I fix CVE-2008-5789?
To fix CVE-2008-5789, upgrade the affected Recly Interactive Feederator component to its latest version.
Which versions are affected by CVE-2008-5789?
CVE-2008-5789 affects version 1.0.5 of the Recly Interactive Feederator component.
What types of attacks can exploit CVE-2008-5789?
CVE-2008-5789 can be exploited through remote file inclusion attacks that allow execution of arbitrary PHP code.
What components are vulnerable in CVE-2008-5789?
The vulnerable components in CVE-2008-5789 include add_tmsp.php, edit_tmsp.php, and tmsp.php in the Recly Interactive Feederator.