vendor:
Peoplebook Component
by:
Matdhule
9
CVSS
CRITICAL
Remote File Include
CWE
Product Name: Peoplebook Component
Affected Version From: 1
Affected Version To: 1
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
2006
Peoplebook Mambo Component <= v1.0 Remote File Include Vulnerabilities
Variables $mosConfig_absolute_path are not properly sanitized, allowing an attacker to inject a simple PHP script and gain system access. The vulnerability can be exploited when register_globals=on and allow_fopenurl=on.
Mitigation:
Sanitize variable $mosConfig_absolute_path in param.peoplebook.php