vendor:
com_mosmedia
by:
Unknown
7.5
CVSS
HIGH
Remote File Include
22
CWE
Product Name: com_mosmedia
Affected Version From:
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
2007
com_mosmedia for Mambo & Jommla <= Remote File Include Vulnerability
The com_mosmedia component for Mambo and Joomla allows remote attackers to include arbitrary files via the mosConfig_absolute_path parameter in (1) media.tab.php or (2) media.divs.php. This vulnerability can be exploited by an attacker to execute arbitrary code on the target system.
Mitigation:
Update to the latest version of the com_mosmedia component to fix this vulnerability. Avoid using outdated or unsupported components.