CVE-2010-1652

Helpcenterlive Hcl - Path Traversal

Title source: rule
STIX 2.1

Description

Directory traversal vulnerability in the HelpCenter module in Help Center Live (HCL) 2.0.6 and 2.1.7 allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the file parameter to module.php. NOTE: some of these details are obtained from third party information.

Exploits (1)

exploitdb WORKING POC VERIFIED
by 41.w4r10r · textwebappsphp
https://www.exploit-db.com/exploits/12421

References (5)

Core 5
Core References
Vendor Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2010/1009
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/39615
Exploit exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/12421
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/39732

Scores

EPSS 0.0353
EPSS Percentile 87.7%

Details

CWE
CWE-22
Status published
Products (2)
helpcenterlive/hcl 2.0.6
helpcenterlive/hcl 2.1.7
Published May 03, 2010
Tracked Since Feb 18, 2026