vendor:
Visitor Data
by:
Chip D3 Bi0s
N/A
CVSS
N/A
Remote Code Execution
78
CWE
Product Name: Visitor Data
Affected Version From: 1.1
Affected Version To: 1.1
Patch Exists: YES
Related CWE: N/A
CPE: a:camp26:visitor_data:1.1
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Joomla 1.5.x
2010
Joomla Module Camp26 Visitor Data 1.1 Remote code Execution
Module Camp26 Visitor Data For Joomla 1.5.x contains a vulnerability that allows remote attackers to execute arbitrary code without authentication. The vulnerability is due to improper input validation in the default.php file, which allows attackers to inject malicious code into the HTTP_X_FORWARDED_FOR header and execute it using the exec() function.
Mitigation:
The vendor has released a patch to address this vulnerability.