Record summary

CVE-2010-3203 has a selected CVSS score of 5.0; EIP currently links 1 catalogued exploit and 1 Nuclei template.

Description

Directory traversal vulnerability in the PicSell (com_picsell) component 1.0 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the dflink parameter in a prevsell dwnfree action to index.php.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1
Nuclei templates
1

Proofs of concept

1

Catalogued exploits

ExploitDBJoomla! Component PicSell 1.0 - Local File DisclosureExploitDB exploitby CrawNot analyzed1 file
ExploitDB

PoC details

Nuclei templates

1
ProjectDiscoveryMEDIUMJoomla! Component PicSell 1.0 - Arbitrary File RetrievalCVSS 5

A directory traversal vulnerability in the PicSell (com_picsell) component 1.0 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the dflink parameter in a prevsell dwnfree action to index.php.

Impact

Successful exploitation of this vulnerability could allow an attacker to retrieve arbitrary files from the server.

Remediation

Upgrade to the latest version to mitigate this vulnerability.

WeaknessesCWE-22
Authorsdaffainfo
Template tagscvecve2010edbjoomlalfixmlswfvuln
CVSS vector: CVSS:2.0/AV:N/AC:L/Au:N/C:P/I:N/A:N
CPE: cpe:2.3:a:xmlswf:com_picsell:1.0:*:*:*:*:*:*:*

Source: ProjectDiscovery

References

3