CVE-2008-6347: Code Injection
Published Mar 2, 2009
·Updated
PHP remote file inclusion vulnerability in lib/onguma.class.php in the Onguma Time Sheet (comongumatimesheet20) 2.0 4b component for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfigabsolutepath parameter.
Affected Software
4 affected components
Joomla joomla
Luigi Massa Onguma Time Sheet=2.04-beta
All of the following
Joomla joomla
Luigi Massa Onguma Time Sheet=2.04-beta
Event History
Mar 2, 2009
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Data Sourced
04:30 PM
DescriptionWeaknessAffected Software
Data Sourced
via NVD·04:30 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2008-6347?
The severity of CVE-2008-6347 is rated high with a CVSS score of 7.5.
2
How do I fix CVE-2008-6347?
To fix CVE-2008-6347, update the Onguma Time Sheet component to the latest version provided by the vendor.
3
What type of vulnerability is CVE-2008-6347?
CVE-2008-6347 is classified as a PHP remote file inclusion vulnerability.
4
What are the consequences of exploiting CVE-2008-6347?
Exploiting CVE-2008-6347 could allow remote attackers to execute arbitrary PHP code on the server.
5
Which Joomla! versions are affected by CVE-2008-6347?
CVE-2008-6347 affects the Onguma Time Sheet component for Joomla! version 2.0 4b.