Input passed to the "mosConfig_absolute_path" parameter in /components/com_ajaxchat/tests/ajcuser.php is not properly verified before being used to include files. This can be exploited to include arbitrary files from local or external resources. GLOBALS[mosConfig_absolute_path] Joomla Component com_ajaxchat 1.0 Edit the source code to ensure that input is properly verified.
Input passed to the "mosConfig_absolute_path" parameter in /components/com_ajaxchat/tests/ajcuser.php is not properly verified before being used to include files. This can be exploited to include arbitrary files from local or external resources. GLOBALS[mosConfig_absolute_path] Joomla Component com_ajaxchat 1.0 Edit the source code to ensure that input is properly verified.