CVE-2008-6080
NUCLEIcom_ionfiles 4.4.2 - Path Traversal via File Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-6080. PoCs published by Vrs-hCk. A Nuclei detection template is also available.
AI-analyzed exploit summary This exploit demonstrates an arbitrary file download vulnerability in ionFiles 4.4.2 for Joomla! due to improper input validation in the 'file' parameter. Attackers can download sensitive files like configuration.php or /etc/passwd via directory traversal.
Description
Directory traversal vulnerability in download.php in the ionFiles (com_ionfiles) 4.4.2 component for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter.
Exploits (1)
This exploit demonstrates an arbitrary file download vulnerability in ionFiles 4.4.2 for Joomla! due to improper input validation in the 'file' parameter. Attackers can download sensitive files like configuration.php or /etc/passwd via directory traversal.