PT-2010-2496 · Jquery Foundation+2 · Jquery+2

Published

2010-02-27

·

Updated

2010-03-01

·

CVE-2010-0760

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Core Design Scriptegrator plugin version 1.4.1 for Joomla!
Description The issue allows remote attackers to include and execute arbitrary local files via directory traversal sequences. This can be achieved through the "file" parameter to "libraries/jquery/js/ui/jsloader.php" and the "files[]" parameter to "libraries/jquery/js/jsloader.php".
Recommendations For Core Design Scriptegrator plugin version 1.4.1, consider disabling access to the "libraries/jquery/js/ui/jsloader.php" and "libraries/jquery/js/jsloader.php" scripts until a patch is available. Avoid using the file and files[] parameters in the affected API endpoints until the issue is resolved.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2010-0760

Affected Products

Core Design Scriptegrator
Joomla!
Jquery