CVE-2009-2635: Code Injection
PHP remote file inclusion vulnerability in toolbarext.php in the RealEstateManager (comrealestatemanager) component 1.0 Basic for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfigabsolutepath parameter.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2009-2635?
CVE-2009-2635 is considered a critical vulnerability as it allows remote attackers to execute arbitrary PHP code.
How do I fix CVE-2009-2635?
To fix CVE-2009-2635, you should update the RealEstateManager component to a version that addresses this vulnerability.
Who is affected by CVE-2009-2635?
CVE-2009-2635 specifically affects users of the RealEstateManager component version 1.0 Basic for Joomla!.
What is the nature of the vulnerability in CVE-2009-2635?
CVE-2009-2635 is a remote file inclusion vulnerability caused by improper handling of the mosConfig_absolute_path parameter.
Are there any known exploits for CVE-2009-2635?
Yes, there are known exploits for CVE-2009-2635 that leverage the vulnerability to execute unauthorized PHP code.