7.5
CVSSv2

CVE-2010-0759

Published: 27/02/2010 Updated: 17/08/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Directory traversal vulnerability in plugins/system/cdscriptegrator/libraries/highslide/js/jsloader.php in the Core Design Scriptegrator plugin 1.4.1 for Joomla! allows remote malicious users to read, and possibly include and execute, arbitrary files via directory traversal sequences in the files[] parameter, a different vector than CVE-2010-0760.

Vulnerable Product Search on Vulmon Subscribe to Product

greatjoomla scriptegrator_plugin 1.4.1

Exploits

# Exploit Title: Core Design Scriptegrator plugin for Joomla! 15 file inclusion # Author: S2 Crew [Hungary] # Tested on: Debian Linux, Apache, Joomla! 15 # Code: There's a file called jsloaderphp which takes an array of file names from the HTTP GET parameters and calls include() on every one of them -----------------8<-------------------- ...