Mosconfig_absolute_path http
Hendrik-jan Verheij has spawned a photo in Joomla!, which can be exploited by malicious citizenry to compromise a vulnerable system. Stimulus passed to the "mosconfig_absolute_path" parameter in index.php is not properly verified before beingness used to include files. That can be exploited to include arbitrary files from international resources. Successful development craves this RG_EMULATION is either switched on or undefined. NOTE: Both situations case surety warnings to be displayed in Joomla!'s establishment section. The photograph is noticed in Joomla! 1.0.x in versions 1.0.14 and 1.0.13. Anterior versions may too be affected.
Solvent :
Joomla! 1.0.x: Updating to adaptation 1.0.15.
Provided and/or created by :
Hendrik-jan Verheij
Pilot Advisory :
Joomla!: http://www.joomla.org/content/vi ew/4609/1/ Hendrik-jan Verheij: http://seclists.org/bugtraq/2008 /feb/0207.html
Please note: The info this that Secunia Advisory is based on originates from a tierce pack unless stated otherwise.
Secunia collects, validates, and verifies all photo info arrived by warrantor query groups, vendors, and others.
Related sites:
<< Home