PT-2012-1490 · Joomla · Community Builder Enhanced
Delf Tonder
·
Publicado
2012-11-26
·
Atualizado
2018-10-10
·
CVE-2010-5280
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Community Builder Enhanced (CBE) (com cbe) component versions 1.4.8 through 1.4.10 for Joomla!
Description
The issue allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the
tabname parameter in a "userProfile" action to "index.php". This can be leveraged to execute arbitrary code by using the file upload feature.Recommendations
For versions 1.4.8 through 1.4.10, avoid using the
tabname parameter in the "userProfile" action to "index.php" until the issue is resolved. As a temporary workaround, consider restricting access to the file upload feature to minimize the risk of exploitation.Exploit
Correção
Path traversal
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Community Builder Enhanced