CVE-2010-1875

NUCLEI

Real Estate Property (com_properties) 3.1.22-03 - Path Traversal via Controller Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2010-1875. PoCs published by Chip d3 bi0s. A Nuclei detection template is also available.

AI-analyzed exploit summary This is a writeup describing a Local File Inclusion (LFI) vulnerability in the Joomla Property component. The exploit involves manipulating the 'controller' parameter to include arbitrary files, potentially exposing sensitive information.

Description

Directory traversal vulnerability in the Real Estate Property (com_properties) component 3.1.22-03 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the controller parameter to index.php. NOTE: some of these details are obtained from third party information.

Exploits (1)

exploitdb WRITEUP VERIFIED
by Chip d3 bi0s · textwebappsphp
https://www.exploit-db.com/exploits/11851

This is a writeup describing a Local File Inclusion (LFI) vulnerability in the Joomla Property component. The exploit involves manipulating the 'controller' parameter to include arbitrary files, potentially exposing sensitive information.

Classification
Writeup 90%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: Joomla Property component (version not specified)
No auth needed
Prerequisites: Access to the vulnerable Joomla instance
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Nuclei Templates (1)

Joomla! Component Property - Local File Inclusion
HIGHby daffainfo

References (5)

Core 5
Core References
Exploit, Third Party Advisory exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/11851
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/57110
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/39074
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/38912
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/63143

Scores

EPSS 0.0092
EPSS Percentile 76.5%

Details

CWE
CWE-22
Status published
Products (1)
com-property/com_properties 3.1.22-03
Published May 12, 2010
Tracked Since Feb 18, 2026