5
CVSSv2

CVE-2010-0696

Published: 23/02/2010 Updated: 21/08/2013
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Directory traversal vulnerability in includes/download.php in the JoomlaWorks AllVideos (Jw_allVideos) plugin 3.0 up to and including 3.2 for Joomla! allows remote malicious users to read arbitrary files via a ./../.../ (modified dot dot) in the file parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

joomlaworks jw_allvideos 3.2

joomlaworks jw_allvideos 3.1

joomlaworks jw_allvideos 3.0

Exploits

################################################################# # Securitylabir ################################################################# # Application Info: # Name: Joomla (jw_allvideos Plugin) # Version: 10 ################################################################# # Vulnerability Info: # Type: Remote File Download # Risk: Medi ...