PT-2006-5058 · Mambo Joomla · Jim

Xoron

·

Published

2006-08-21

·

Updated

2024-08-07

·

CVE-2006-4242

CVSS v2.0
5.1
VectorAV:N/AC:H/Au:N/C:P/I:P/A:P

Name of the Vulnerable Software and Affected Versions:

JIM component for Joomla or Mambo version 1.0.1

Description:

The issue allows remote attackers to execute arbitrary PHP code via a URL in the `mosConfig absolute path` parameter in the install.jim.php file.

Recommendations:

For version 1.0.1, consider restricting access to the install.jim.php file to minimize the risk of exploitation. Avoid using the `mosConfig absolute path` parameter in the affected component until the issue is resolved.

Exploit

Fix

Related Identifiers

CVE-2006-4242

Affected Products

Jim