VYPR
Unrated severityNVD Advisory· Published Dec 19, 2008· Updated Apr 23, 2026

CVE-2008-5671

CVE-2008-5671

Description

PHP remote file inclusion vulnerability in index.php in Joomla! 1.0.11 through 1.0.14, when RG_EMULATION is enabled in configuration.php, allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.

Affected products

4
  • Joomla/Joomla!4 versions
    cpe:2.3:a:joomla:joomla:*:*:*:*:*:*:*:*+ 3 more
    • cpe:2.3:a:joomla:joomla:*:*:*:*:*:*:*:*range: <=1.0.14
    • cpe:2.3:a:joomla:joomla:1.0.11:*:*:*:*:*:*:*
    • cpe:2.3:a:joomla:joomla:1.0.12:*:*:*:*:*:*:*
    • cpe:2.3:a:joomla:joomla:1.0.13:*:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

6

News mentions

0

No linked articles in our index yet.