CVE-2009-3333: Code Injection
Published Sep 23, 2009
·Updated
PHP remote file inclusion vulnerability in koesubmit.php in the koeSubmit (comkoesubmit) component 1.0 for Mambo allows remote attackers to execute arbitrary PHP code via a URL in the mosConfigabsolutepath parameter.
Affected Software
2 affected components
Mambo Mambo
Alibasta Com Koesubmit=1.0
Event History
Sep 23, 2009
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Data Sourced
12:08 PM
DescriptionWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2009-3333?
CVE-2009-3333 is considered a critical vulnerability due to its potential for remote code execution.
2
How do I fix CVE-2009-3333?
To mitigate CVE-2009-3333, upgrade to a patched version of the koeSubmit component that is not susceptible to remote file inclusion.
3
What systems are affected by CVE-2009-3333?
CVE-2009-3333 affects Mambo installations using the koeSubmit component version 1.0.
4
What type of vulnerability is CVE-2009-3333?
CVE-2009-3333 is classified as a remote file inclusion vulnerability.
5
Who can exploit CVE-2009-3333?
Remote attackers can exploit CVE-2009-3333 to execute arbitrary PHP code by manipulating the mosConfig_absolute_path parameter.