CVE-2010-1607
NUCLEIcom_wmi 1.5.0 - Path Traversal via Controller Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2010-1607. PoCs published by wishnusakti + inc0mp13te. A Nuclei detection template is also available.
AI-analyzed exploit summary This exploit demonstrates a Local File Inclusion (LFI) vulnerability in the Joomla component wmi (com_wmi). The vulnerability arises from improper input validation in the 'controller' parameter, allowing an attacker to include arbitrary files.
Description
Directory traversal vulnerability in wmi.php in the Webmoney Web Merchant Interface (aka WMI or com_wmi) component 1.5.0 for Joomla! allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the controller parameter to index.php.
Exploits (1)
This exploit demonstrates a Local File Inclusion (LFI) vulnerability in the Joomla component wmi (com_wmi). The vulnerability arises from improper input validation in the 'controller' parameter, allowing an attacker to include arbitrary files.