CVE-2010-0467
MEDIUM NUCLEIcom_ccnewsletter 1.0.5 - Path Traversal via Controller Parameter
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2010-0467. PoCs published by AtT4CKxT3rR0r1ST, B-HUNT3|2. A Nuclei detection template is also available.
AI-analyzed exploit summary This exploit demonstrates a Local File Inclusion (LFI) vulnerability in the Joomla component com_ccnewsletter. It allows an attacker to read arbitrary files on the server by manipulating the 'controller' parameter.
Description
Directory traversal vulnerability in the ccNewsletter (com_ccnewsletter) component 1.0.5 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter in a ccnewsletter action to index.php.
Exploits (2)
This exploit demonstrates a Local File Inclusion (LFI) vulnerability in the Joomla component com_ccnewsletter. It allows an attacker to read arbitrary files on the server by manipulating the 'controller' parameter.
This advisory describes a directory traversal vulnerability in Joomla's com_ccnewsletter component, where the 'controller' parameter is vulnerable. The PoC is a URL example without executable exploit code.
Nuclei Templates (1)
References (6)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N