CVE-2008-5793
Multiple PHP remote file inclusion vulnerabilities in the Clickheat - Heatmap stats (com_clickheat) component 1.0.1 for Joomla!
Description
Multiple PHP remote file inclusion vulnerabilities in the Clickheat - Heatmap stats (com_clickheat) component 1.0.1 for Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the (1) GLOBALS[mosConfig_absolute_path] parameter to (a) install.clickheat.php, (b) Cache.php and (c) Clickheat_Heatmap.php in Recly/Clickheat/, and (d) Recly/common/GlobalVariables.php; and the (2) mosConfig_absolute_path parameter to (e) _main.php and (f) main.php in includes/heatmap, and (g) includes/overview/main.php.
Sévérité
AV:N/AC:M/Au:N/C:P/I:P/A:P
Score retenu : NVD
| Source | Sévérité d'origine | CVSS |
|---|---|---|
| NVD | MEDIUM | 6.8 (v2.0) |
Produit et versions
- Produit
- com_clickheat
- Type
- Composant
- Corrigée dans
- Non précisée
- Publiée
- 31/12/2008
- Modifiée
- 16/06/2026
- CWE
- CWE-94
Versions concernées
- clickheat-heatmap — 1.0.1 – 1.0.1
Sources
- NVD CVE-2008-5793 vu
Ces informations proviennent des sources ci-dessus ; CVE Oyer n'y ajoute aucune interprétation.
Historique
- Détectée via nvd26/09/2026 09:27 UTC