Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2007-5389


Vulnerability Score 6.8 6.8
CVE Id CVE-2007-5389
Last Modified 15 Nov 2008 02:00:50
Published 12 Oct 2007 06:17:00
Confidentiality Impact PARTIAL PARTIAL
Integrity Impact PARTIAL PARTIAL
Availability Impact PARTIAL PARTIAL
Access Vector NETWORK
Access Complexity MEDIUM
Authentication NONE



** DISPUTED ** PHP remote file inclusion vulnerability in preview.php in the swMenuFree (com_swmenufree) 4.6 component for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter. NOTE: a reliable third party disputes this issue because preview.php tests a certain constant to prevent direct requests.

Vulnerable Systems


  • Joomla

  • Swmenupro Swmenufree 4.6


BUGTRAQ - 20071011 Joomla! swMenuFree 4.6 Component Remote File Include

OSVDB - 37903

BUGTRAQ - 20071012 Re: Joomla! swMenuFree 4.6 Component Remote File Include

SREASON - 3210

Last Updated: 27 May 2016 10:46:10