PHP remote file inclusion vulnerability in contentpublisher.php in the contentpublisher component (com_contentpublisher) for Mambo allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter. NOTE: this issue has been disputed by third parties who state that contentpublisher.php protects against direct request in the most recent version. The original researcher is known to be frequently inaccurate
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Mambo | Mambo | 4.0.14 (including) | 4.0.14 (including) |
| Mambo | Mambo | 4.5.0.2 (including) | 4.5.0.2 (including) |
| Mambo | Mambo | 4.5.1.3 (including) | 4.5.1.3 (including) |
| Mambo | Mambo | 4.5.1_1.0.9 (including) | 4.5.1_1.0.9 (including) |
| Mambo | Mambo | 4.5.1a (including) | 4.5.1a (including) |
| Mambo | Mambo | 4.5.1a-a (including) | 4.5.1a-a (including) |
| Mambo | Mambo | 4.5.1a-beta (including) | 4.5.1a-beta (including) |
| Mambo | Mambo | 4.5.1a-beta_2 (including) | 4.5.1a-beta_2 (including) |
| Mambo | Mambo | 4.5.2 (including) | 4.5.2 (including) |
| Mambo | Mambo | 4.5.2.1 (including) | 4.5.2.1 (including) |
| Mambo | Mambo | 4.5.2.2 (including) | 4.5.2.2 (including) |
| Mambo | Mambo | 4.5.2.3 (including) | 4.5.2.3 (including) |
| Mambo | Mambo | 4.5.3h (including) | 4.5.3h (including) |
| Mambo | Mambo | 4.5.3h-h (including) | 4.5.3h-h (including) |
| Mambo | Mambo | 4.5_1.0.0 (including) | 4.5_1.0.0 (including) |
| Mambo | Mambo | 4.5_1.0.1 (including) | 4.5_1.0.1 (including) |
| Mambo | Mambo | 4.5_1.0.2 (including) | 4.5_1.0.2 (including) |
| Mambo | Mambo | 4.5_1.0.3_beta (including) | 4.5_1.0.3_beta (including) |
| Mambo | Mambo | 4.5_1.0.3_beta-beta (including) | 4.5_1.0.3_beta-beta (including) |
| Mambo | Mambo | 4.5_1.0.9 (including) | 4.5_1.0.9 (including) |
| Mambo | Mambo | 4.6-rc1 (including) | 4.6-rc1 (including) |