CVE-2010-2033
NUCLEIPercha com_perchacategoriestree 0.6 - Path Traversal via Controller Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2010-2033. PoCs published by AntiSecurity. A Nuclei detection template is also available.
AI-analyzed exploit summary This is a vulnerability writeup describing multiple local file inclusion (LFI) vulnerabilities in various Percha components for Joomla. The example URL demonstrates how an attacker can exploit the vulnerability to read arbitrary files (e.g., /etc/passwd) due to improper input sanitization.
Description
Directory traversal vulnerability in the Percha Multicategory Article (com_perchacategoriestree) component 0.6 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the controller parameter to index.php.
Exploits (1)
This is a vulnerability writeup describing multiple local file inclusion (LFI) vulnerabilities in various Percha components for Joomla. The example URL demonstrates how an attacker can exploit the vulnerability to read arbitrary files (e.g., /etc/passwd) due to improper input sanitization.