Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2006-4378

Опубликовано: 26 авг. 2006
Источник: nvd
CVSS2: 7.5
EPSS Низкий

Описание

Multiple PHP remote file inclusion vulnerabilities in the Rssxt component for Joomla! (com_rssxt), possibly 2.0 Beta 1 or 1.0 and earlier, allow remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter in (1) pinger.php, (2) RPC.php, or (3) rssxt.php. NOTE: another researcher has disputed this issue, saying that the attacker can not control this parameter. In addition, as of 20060825, the original researcher has appeared to be unreliable with some other past reports. CVE has not performed any followup analysis with respect to this issue

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:joomla:rssxt_component:*:*:*:*:*:*:*:*
Версия до 2.0_beta_1 (включая)
cpe:2.3:a:joomla:rssxt_component:1.0:*:*:*:*:*:*:*

EPSS

Процентиль: 78%
0.01195
Низкий

7.5 High

CVSS2

Дефекты

NVD-CWE-Other

Связанные уязвимости

github
почти 4 года назад

** DISPUTED ** Multiple PHP remote file inclusion vulnerabilities in the Rssxt component for Joomla! (com_rssxt), possibly 2.0 Beta 1 or 1.0 and earlier, allow remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter in (1) pinger.php, (2) RPC.php, or (3) rssxt.php. NOTE: another researcher has disputed this issue, saying that the attacker can not control this parameter. In addition, as of 20060825, the original researcher has appeared to be unreliable with some other past reports. CVE has not performed any followup analysis with respect to this issue.

EPSS

Процентиль: 78%
0.01195
Низкий

7.5 High

CVSS2

Дефекты

NVD-CWE-Other