Record summary

CVE-2010-2682 has a selected CVSS score of 7.5; EIP currently links 1 catalogued exploit and 1 Nuclei template.

Description

Directory traversal vulnerability in the Realtyna Translator (com_realtyna) component 1.0.15 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the controller parameter to index.php.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1
Nuclei templates
1

Proofs of concept

1

Catalogued exploits

ExploitDBJoomla! Component Realtyna Translator 1.0.15 - Local File Inclusion (2)ExploitDB exploitby MISTERFRIBONot analyzed1 file
ExploitDB

PoC details

Nuclei templates

1
ProjectDiscoveryHIGHJoomla! Component Realtyna Translator 1.0.15 - Local File InclusionCVSS 7.5

A directory traversal vulnerability in the Realtyna Translator (com_realtyna) component 1.0.15 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impacts via a .. (dot dot) in the controller parameter to index.php.

Impact

Successful exploitation of this vulnerability can lead to unauthorized access to sensitive files, remote code execution, and compromise of the Joomla! website.

Remediation

Upgrade to the latest version to mitigate this vulnerability.

WeaknessesCWE-22
Authorsdaffainfo
Template tagscvecve2010joomlalfiedbpacketstormrealtynavuln
CVSS vector: CVSS:2.0/AV:N/AC:L/Au:N/C:P/I:P/A:P
CPE: cpe:2.3:a:realtyna:com_realtyna:1.0.15:*:*:*:*:*:*:*

Source: ProjectDiscovery

References

5