CVE-2010-3203
Joomla! Component PicSell 1.0 - Local File Disclosure
Record summary
CVE-2010-3203 has a selected CVSS score of 5.0; EIP currently links 1 catalogued exploit and 1 Nuclei template.
Description
Directory traversal vulnerability in the PicSell (com_picsell) component 1.0 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the dflink parameter in a prevsell dwnfree action to index.php.
Exploitation context
Proofs of concept
1Catalogued exploits
ExploitDBJoomla! Component PicSell 1.0 - Local File DisclosureExploitDB exploitby CrawNot analyzed1 file
Nuclei templates
1ProjectDiscoveryMEDIUMJoomla! Component PicSell 1.0 - Arbitrary File RetrievalCVSS 5
A directory traversal vulnerability in the PicSell (com_picsell) component 1.0 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the dflink parameter in a prevsell dwnfree action to index.php.
Impact
Successful exploitation of this vulnerability could allow an attacker to retrieve arbitrary files from the server.
Remediation
Upgrade to the latest version to mitigate this vulnerability.
Source: ProjectDiscovery