Joomla! before 1.0.11 omits some checks for whether _VALID_MOS is defined, which allows attackers to have an unknown impact, possibly resulting in PHP remote file inclusion.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Joomla! | Joomla | * | 1.0.11 (excluding) |