Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Xr0B0T

#18771de 53,639
14.3CVSS total
Vulnerabilidades · 2
Média
1
Alta
1
PT-2010-3732
6.8
2010-06-01
Joomla · Joomla! Simpledownload · CVE-2010-2122
**Name of the Vulnerable Software and Affected Versions** Joomla! SimpleDownload component versions prior to 0.9.6 **Description** A directory traversal issue exists in the SimpleDownload component for Joomla!, allowing remote attackers to include and execute arbitrary local files. This is achieved by using a .. (dot dot) in the `controller` parameter to `index.php`. **Recommendations** For versions prior to 0.9.6, update the SimpleDownload component to version 0.9.6 or later to resolve the issue.
PT-2010-3669
7.5
2010-05-25
Moron Solutions · Ms Comment · CVE-2010-2050
**Name of the Vulnerable Software and Affected Versions** Moron Solutions MS Comment (com mscomment) component version 0.8.0b for Joomla! **Description** The issue allows remote attackers to read arbitrary files via a .. (dot dot) in the `controller` parameter to "index.php". **Recommendations** For version 0.8.0b, consider restricting access to the "index.php" endpoint until a patch is available. Avoid using the `controller` parameter in the affected endpoint until the issue is resolved.