Mambo "mosConfig_absolute_path" Remote File Inclusion Vulnerability
Description
A vulnerability has been identified in Mambo, which may be exploited by attackers to execute arbitrary commands. This flaw is due to an error in the "register_globals" emulation layer in "globals.php" that does not perform safety checks on certain values, which may be exploited by remote attackers to overwrite arbitrary variables, include malicious files via the "mosConfig_absolute_path" parameter, and execute arbitrary commands with the privileges of the web server.
Note : A fully functional exploit has been released.
Vulnerable Products
Vulnerable Software: Mambo version 4.5.2.3 and prior