CVE-2009-4604: Code Injection
PHP remote file inclusion vulnerability in mamboleto.php in the Fernando Soares Mamboleto (commamboleto) component 2.0 RC3 for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfigabsolutepath parameter.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2009-4604?
CVE-2009-4604 is considered a critical vulnerability due to its potential to allow remote code execution.
How do I fix CVE-2009-4604?
To fix CVE-2009-4604, you should update the Fernando Soares Mamboleto component to a version that is not vulnerable, or remove it if it is not in use.
Which software versions are affected by CVE-2009-4604?
CVE-2009-4604 specifically affects the Fernando Soares Mamboleto component version 2.0 RC3 for Joomla!.
What types of attacks can exploit CVE-2009-4604?
CVE-2009-4604 can be exploited through remote file inclusion attacks, allowing an attacker to execute arbitrary PHP code.
Is my Joomla! installation at risk for CVE-2009-4604?
Your Joomla! installation is at risk for CVE-2009-4604 only if the vulnerable version of the Mamboleto component is installed.