Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Hendrik Jan Verheij

Researcher fromBWSS B.V.
#35710of 53,633
7.5Total CVSS
Vulnerabilities · 1
PT-2008-6723
7.5
2008-12-18
Open Source Matters · Joomla! · CVE-2008-5671
**Name of the Vulnerable Software and Affected Versions** Joomla! versions 1.0.11 through 1.0.14 **Description** The issue allows remote attackers to execute arbitrary PHP code via a URL in the `mosConfig absolute path` parameter when `RG EMULATION` is enabled in `configuration.php`. This is a result of a remote file inclusion vulnerability in `index.php`. **Recommendations** For Joomla! versions 1.0.11 through 1.0.14, consider disabling the `RG EMULATION` setting in `configuration.php` as a temporary workaround to minimize the risk of exploitation. Restrict access to the `mosConfig absolute path` parameter in the affected `index.php` file until a fix is available.