PT-2007-6440 · Joomla · Swmenufree
Str0Kestr0Ke
·
Published
2007-10-12
·
Updated
2024-08-07
·
CVE-2007-5389
CVSS v2.0
6.8
Vector | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Code Injection
Weakness Enumeration
Related Identifiers
Affected Products
Swmenufree
Str0Kestr0Ke
·
Published
2007-10-12
·
Updated
2024-08-07
·
CVE-2007-5389
6.8
Medium
Base vector | Vector | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
Joomla! component swMenuFree (com swmenufree) version 4.6
Description:
A remote file inclusion issue in the preview.php file of the swMenuFree component allows remote attackers to execute arbitrary PHP code via a URL in the `mosConfig absolute path` parameter. However, it's noted that a reliable third party disputes this issue because preview.php tests a certain constant to prevent direct requests.
Recommendations:
For version 4.6 of the swMenuFree component, consider restricting access to the `preview.php` file to minimize the risk of exploitation. Additionally, avoid using the `mosConfig absolute path` parameter in the affected API endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Code Injection