CVE-2006-3530

Severity CVSS v4.0:
Pending analysis
Type:
CWE-94 Code Injection
Publication date:
12/07/2006
Last modified:
03/04/2025

Description

PHP remote file inclusion vulnerability in com_pccookbook/pccookbook.php in the PccookBook Component for Mambo and Joomla 0.3 and possibly up to 1.3.1, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via the mosConfig_absolute_path parameter.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:joomla:pc_cookbook:0.3:*:*:*:*:*:*:*
cpe:2.3:a:joomla:pc_cookbook:1.3.1:*:*:*:*:*:*:*