CVE-2010-2259
NUCLEIcom_bfsurvey_profree - Path Traversal via Controller Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2010-2259. PoCs published by FL0RiX. A Nuclei detection template is also available.
AI-analyzed exploit summary This is a writeup describing a Local File Inclusion (LFI) vulnerability in the Joomla component com_bfsurvey. The vulnerability allows an attacker to include local files via the 'controller' parameter in the URL.
Description
Directory traversal vulnerability in the BF Survey (com_bfsurvey) component for Joomla! allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the controller parameter to index.php.
Exploits (1)
This is a writeup describing a Local File Inclusion (LFI) vulnerability in the Joomla component com_bfsurvey. The vulnerability allows an attacker to include local files via the 'controller' parameter in the URL.