CVE-2010-2050
Joomla! Component MS Comment 0.8.0b - Local File Inclusion
Record summary
CVE-2010-2050 has a selected CVSS score of 7.5; EIP currently links 1 catalogued exploit and 1 Nuclei template.
Description
Directory traversal vulnerability in the Moron Solutions MS Comment (com_mscomment) component 0.8.0b for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.
Exploitation context
Proofs of concept
1Catalogued exploits
ExploitDBJoomla! Component MS Comment 0.8.0b - Local File InclusionExploitDB exploitby Xr0b0tNot analyzed1 file
Nuclei templates
1ProjectDiscoveryHIGHJoomla! Component MS Comment 0.8.0b - Local File InclusionCVSS 7.5
A directory traversal vulnerability in the Moron Solutions MS Comment (com_mscomment) component 0.8.0b for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.
Impact
Successful exploitation of this vulnerability can lead to unauthorized access to sensitive files and potentially execute arbitrary code.
Remediation
Upgrade to the latest version to mitigate this vulnerability.
Source: ProjectDiscovery