CVE-2010-1717
NUCLEIIF Surfalert - Path Traversal
Title source: ruleDescription
Directory traversal vulnerability in the iF surfALERT (com_if_surfalert) component 1.2 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the controller parameter to index.php.
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by AntiSecurity · textwebappsphp
https://www.exploit-db.com/exploits/12291
Nuclei Templates (1)
Joomla! Component iF surfALERT 1.2 - Local File Inclusion
HIGHby daffainfo
Scores
EPSS
0.0451
EPSS Percentile
89.2%
Details
CWE
CWE-22
Status
published
Products (1)
if_surfalert_project/if_surfalert
1.2
Published
May 04, 2010
Tracked Since
Feb 18, 2026