Record summary

CVE-2010-2050 has a selected CVSS score of 7.5; EIP currently links 1 catalogued exploit and 1 Nuclei template.

Description

Directory traversal vulnerability in the Moron Solutions MS Comment (com_mscomment) component 0.8.0b for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1
Nuclei templates
1

Proofs of concept

1

Catalogued exploits

ExploitDBJoomla! Component MS Comment 0.8.0b - Local File InclusionExploitDB exploitby Xr0b0tNot analyzed1 file
ExploitDB

PoC details

Nuclei templates

1
ProjectDiscoveryHIGHJoomla! Component MS Comment 0.8.0b - Local File InclusionCVSS 7.5

A directory traversal vulnerability in the Moron Solutions MS Comment (com_mscomment) component 0.8.0b for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.

Impact

Successful exploitation of this vulnerability can lead to unauthorized access to sensitive files and potentially execute arbitrary code.

Remediation

Upgrade to the latest version to mitigate this vulnerability.

WeaknessesCWE-22
Authorsdaffainfo
Template tagscvecve2010joomlalfiedbpacketstormm0r0nvuln
CVSS vector: CVSS:2.0/AV:N/AC:L/Au:N/C:P/I:P/A:P
CPE: cpe:2.3:a:m0r0n:com_mscomment:0.8.0:b:*:*:*:*:*:*

Source: ProjectDiscovery

References

6