Sploitus

CVE-2007-1699

1 known exploit for CVE-2007-1699

Multiple PHP remote file inclusion vulnerabilities in the SWmenu (com_swmenupro and com_swmenufree) 4.0 component for Mambo and Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter to ImageManager/Classes/ImageManager.php under the (1) components/ or (2) administrator/components/ directory trees.

Affected products
Joomla!, Mambo, Swmenu
Joomla Swmenu Component
= 4.0
Mambo Swmenu Component
= 4.0
Fix
Available
CVSS 2.0
10.0 HIGH
EPSS
10.6% (95th percentile)
NVD status
Modified
Published
2007-03-27
CVE-2007-1699 at NVD
Authoritative description, scoring and affected products

1 known exploit for CVE-2007-1699

Proof-of-concept code and exploit modules indexed by Sploitus