4.3
CVSSv2

CVE-2010-0982

Published: 16/03/2010 Updated: 17/03/2010
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N

Vulnerability Summary

Directory traversal vulnerability in the CARTwebERP (com_cartweberp) component 1.56.75 for Joomla! allows remote malicious users to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.

Vulnerable Product Search on Vulmon Subscribe to Product

joomlamo com_cartweberp 1.56.75

Exploits

@~~=======================================~~@ @~~=Script : Joomla Component com_cartweberp @~~=Author : FL0RiX @~~=Greez : Deep-Power ,KaCaK,Wretch-x & All Friends @~~=Bug Type : Local File Inlusion(LFI) @~~=Dork : inurl:"com_cartweberp" @~~=======================================~~@ @~~=Vuln :server/ [Yol] /indexphp?option=co ...