CVE Database
/

CVE-2006-4269

Back to search

CVE-2006-4269

Published: Aug 21, 2006

Modified: Aug 7, 2024

PUBLISHED

Description

PHP remote file inclusion vulnerability in admin.x-shop.php in the x-shop component (com_x-shop) 1.7 and earlier for Mambo and Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter. NOTE: this issue has been disputed by third party researchers, stating that there is no mosConfig_absolute_path parameter and no admin.x-shop.php file in the reported package

VendorProductVersions

n/a

n/a

affected
n/a

References

28095
vdb-entry
x_refsource_OSVDB
xshop-admin-file-include(28451)
vdb-entry
x_refsource_XF
19588
vdb-entry
x_refsource_BID

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now