Unrated severityNVD Advisory· Published Apr 12, 2007· Updated Apr 23, 2026
CVE-2007-2005
CVE-2007-2005
Description
Multiple PHP remote file inclusion vulnerabilities in the Taskhopper 1.1 component for Mambo and Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter to (1) contact_type.php, (2) itemstatus_type.php, (3) projectstatus_type.php, (4) request_type.php, (5) responses_type.php, (6) timelog_type.php, or (7) urgency_type.php in inc/.
Affected products
2- cpe:2.3:a:joomla:taskhopper_component:1.1:*:*:*:*:*:*:*
- cpe:2.3:a:mambo:taskhopper_component:1.1:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
12- attrition.org/pipermail/vim/2007-April/001504.htmlnvd
- www.osvdb.org/34795nvd
- www.osvdb.org/34796nvd
- www.osvdb.org/34797nvd
- www.osvdb.org/34798nvd
- www.osvdb.org/34799nvd
- www.osvdb.org/34800nvd
- www.osvdb.org/34801nvd
- www.securityfocus.com/bid/23408nvd
- www.vupen.com/english/advisories/2007/1346nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/33552nvd
- www.exploit-db.com/exploits/3703nvd
News mentions
0No linked articles in our index yet.