CVE-2009-4789: Code Injection
Multiple PHP remote file inclusion vulnerabilities in the MojoBlog component RC 0.15 for Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the mosConfigabsolutepath parameter to (1) wp-comments-post.php and (2) wp-trackback.php.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2009-4789?
CVE-2009-4789 is classified as a high severity vulnerability due to the potential for remote code execution.
How do I fix CVE-2009-4789?
To fix CVE-2009-4789, you should update the MojoBlog component to a patched version that resolves the remote file inclusion vulnerabilities.
What software is affected by CVE-2009-4789?
CVE-2009-4789 affects the MojoBlog component version RC 0.15 for Joomla! installations.
Can CVE-2009-4789 lead to data compromise?
Yes, exploitation of CVE-2009-4789 can lead to arbitrary PHP code execution, which may result in data compromise.
Is CVE-2009-4789 specific to certain Joomla! versions?
CVE-2009-4789 specifically targets the MojoBlog component and is not dependent on the Joomla! version itself.