Multiple PHP remote file inclusion vulnerabilities in the Taskhopper 1.1 component for Mambo and Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the mosConfigabsolutepath parameter to (1) contacttype.php, (2) itemstatustype.php, (3) projectstatustype.php, (4) requesttype.php, (5) responsestype.php, (6) timelogtype.php, or (7) urgencytype.php in inc/.