ARTICLE
A vulnerability has been identified in Article (module for Joomla), which could be exploited by remote attackers to execute arbitrary commands. This issue is caused by input validation errors in the "components/com_articles.php" and "classes/html/com_articles.php" scripts when processing the "absolute_path" parameter, which could be exploited by remote attackers to include malicious PHP scripts and execute arbitrary commands with the privileges of the web server.
Affected Products
Article (module for Joomla) version 1.1 and prior
See:
http://www.milw0rm.com/exploits/3736http://www.frsirt.com/english/advisories/2007/1394AUTOSTAND
A vulnerability has been identified in AutoStand (module for Joomla), which could be exploited by remote attackers to execute arbitrary commands. This issue is caused by an input validation error in the "mod_as_category.php" script that does not validate the "mosConfig_absolute_path" parameter, which could be exploited by remote attackers to include malicious PHP scripts and execute arbitrary commands with the privileges of the web server.
Affected Products
AutoStand (module for Joomla) version 1.1 and prior
See:
http://www.milw0rm.com/exploits/3734http://www.frsirt.com/english/advisories/2007/1392JoomlaPack for Joomla "mosConfig_absolute_path" PHP File Inclusion Vulnerability
A vulnerability has been identified in JoomlaPack (module for Joomla), which could be exploited by remote attackers to execute arbitrary commands. This issue is caused by an input validation error in the "includes/CAltInstaller.php" script when processing the "mosConfig_absolute_path" parameter, which could be exploited by remote attackers to include malicious PHP scripts and execute arbitrary commands with the privileges of the web server.
Affected Products
JoomlaPack (module for Joomla) version 1.0.4a2 RE and prior
NOTE: 1.0.4.a3 is OUT and doesn't seem to have any problem at all (contacting the author about it).
Info:
http://www.frsirt.com/english/advisories/2007/1429I could be useful to update 3rd party vulnerability list.
Take care,
ArMyBoT