CVE-2010-1653

NUCLEI

Graphics (com_graphics) 1.0.6 and 1.5.0 - Path Traversal via Controller Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2010-1653. PoCs published by wishnusakti + inc0mp13te. A Nuclei detection template is also available.

AI-analyzed exploit summary This exploit demonstrates a Local File Inclusion (LFI) vulnerability in Joomla Component graphics (com_graphics) v1.0.6. The vulnerability arises from improper input validation in the 'controller' parameter, allowing directory traversal to read arbitrary files.

Description

Directory traversal vulnerability in graphics.php in the Graphics (com_graphics) component 1.0.6 and 1.5.0 for Joomla! allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the controller parameter to index.php. NOTE: some of these details are obtained from third party information.

Exploits (1)

exploitdb WORKING POC
by wishnusakti + inc0mp13te · textwebappsphp
https://www.exploit-db.com/exploits/12430

This exploit demonstrates a Local File Inclusion (LFI) vulnerability in Joomla Component graphics (com_graphics) v1.0.6. The vulnerability arises from improper input validation in the 'controller' parameter, allowing directory traversal to read arbitrary files.

Classification
Working Poc 90%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: Joomla Component graphics (com_graphics) v1.0.6
No auth needed
Prerequisites: Joomla installation with vulnerable com_graphics component
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Nuclei Templates (1)

Joomla! Component Graphics 1.0.6 - Local File Inclusion
HIGHby daffainfo

References (5)

Core 5
Core References
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/39743
Vendor Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2010/1004
Exploit exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/12430
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/39585

Scores

EPSS 0.0323
EPSS Percentile 87.4%

Details

CWE
CWE-22
Status published
Products (2)
htmlcoderhelper/com_graphics 1.0.6
htmlcoderhelper/com_graphics 1.5.0
Published May 03, 2010
Tracked Since Feb 18, 2026