CVE-2010-0467

Directory traversal vulnerability in the ccNewsletter (com_ccnewsletter) component 1.0.5 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter in a ccnewsletter action to index.php.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:chillcreations:com_ccnewsletter:1.0.5:*:*:*:*:*:*:*
cpe:2.3:a:joomla:joomla\!:*:*:*:*:*:*:*:*

Information

Published : 2010-02-02 17:30

Updated : 2019-09-27 16:53


NVD link : CVE-2010-0467

Mitre link : CVE-2010-0467


JSON object : View

Products Affected

joomla

  • joomla\!

chillcreations

  • com_ccnewsletter
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')