This application requires Javascript for optimal performance.

Mambo.MosConfig.Absolute.Path.Remote.File.Include

Release Date

Oct 28, 2011

Severity

low

Impact

System Compromise: Remote code execution.

Description

This indicates a possible attempt to exploit a File Inclusion vulnerability in Mambo Email Publisher.

The vulnerability may allow a remote attacker to execute arbitrary PHP code by sending a specially crafted URL.

Affected Products

MamboXChange Mambo eMail Publisher 1.2

Recommended Actions

Currently, we are not aware of any vendor supplied patches for this issue.

Coverage

IPS
VCM

Common Vulnerabilities and Exposures (CVE)

CVE-2006-3980

Reference/s

http://www.securityfocus.com/bid/19502 (BugTraq)
http://www.securityfocus.com/bid/19224 (BugTraq)
http://www.securityfocus.com/bid/20018 (BugTraq)
http://www.securityfocus.com/bid/20072 (BugTraq)

Reference: VID-29612