PT-2012-1490 · Joomla · Community Builder Enhanced
Delf Tonder
·
Published
2012-11-26
·
Updated
2018-10-10
·
CVE-2010-5280
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Community Builder Enhanced (CBE) (com cbe) component versions 1.4.8 through 1.4.10 for Joomla!
Description
The issue allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the
tabname parameter in a "userProfile" action to "index.php". This can be leveraged to execute arbitrary code by using the file upload feature.Recommendations
For versions 1.4.8 through 1.4.10, avoid using the
tabname parameter in the "userProfile" action to "index.php" until the issue is resolved. As a temporary workaround, consider restricting access to the file upload feature to minimize the risk of exploitation.Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Community Builder Enhanced