CVE-2010-2507

NUCLEI

Masselink Com Picasa2gallery < 1.2.8 - Path Traversal

Title source: rule

Description

Directory traversal vulnerability in the Picasa2Gallery (com_picasa2gallery) component 1.2.8 and earlier for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the controller parameter to index.php.

Exploits (1)

exploitdb WORKING POC VERIFIED
by kaMtiEz · textwebappsphp
https://www.exploit-db.com/exploits/13981

Nuclei Templates (1)

Joomla! Component Picasa2Gallery 1.2.8 - Local File Inclusion
MEDIUMby daffainfo

Scores

EPSS 0.0192
EPSS Percentile 83.4%

Details

CWE
CWE-22
Status published
Products (9)
masselink/com_picasa2gallery 1.0.0
masselink/com_picasa2gallery 1.1.0
masselink/com_picasa2gallery 1.1.7
masselink/com_picasa2gallery 1.1.9
masselink/com_picasa2gallery 1.2.1
masselink/com_picasa2gallery 1.2.2
masselink/com_picasa2gallery 1.2.5
masselink/com_picasa2gallery 1.2.7
masselink/com_picasa2gallery < 1.2.8
Published Jun 28, 2010
Tracked Since Feb 18, 2026