CVE-2009-4789

Severity CVSS v4.0:
Pending analysis
Type:
CWE-94 Code Injection
Publication date:
21/04/2010
Last modified:
03/06/2010

Description

Multiple PHP remote file inclusion vulnerabilities in the MojoBlog component RC 0.15 for Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter to (1) wp-comments-post.php and (2) wp-trackback.php.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:mojoblog:mojoblog:rc0.15:*:*:*:*:*:*:*
cpe:2.3:a:joomla:joomla:*:*:*:*:*:*:*:*