An issue was discovered in Joomla! 2.5.0 through 3.8.8 before 3.8.9. The autoload code checks classnames to be valid, using the "class_exists" function in PHP. In PHP 5.3, this function validates invalid names as valid, which can result in a Local File Inclusion.
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
Link | Tags |
---|---|
http://www.securitytracker.com/id/1041245 | vdb entry third party advisory |
https://developer.joomla.org/security-centre/741-20180601-core-local-file-inclusion-with-php-5-3 | vendor advisory |
http://www.securityfocus.com/bid/104566 | vdb entry third party advisory |