7.5
CVSSv2

CVE-2010-1306

Published: 08/04/2010 Updated: 17/08/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Directory traversal vulnerability in the Picasa (com_joomlapicasa2) component 2.0 and 2.0.5 for Joomla! allows remote malicious users to read arbitrary local files via a .. (dot dot) in the controller parameter to index.php. NOTE: some of these details are obtained from third party information.

Vulnerable Product Search on Vulmon Subscribe to Product

roberto aloi com joomlapicasa2 2.0.0

roberto aloi com joomlapicasa2 2.0.1

roberto aloi com joomlapicasa2 2.0.2

roberto aloi com joomlapicasa2 2.0.3

roberto aloi com joomlapicasa2 2.0.4

roberto aloi com joomlapicasa2 2.0.5

Exploits

# Exploit Title: Joomla Component Picasa 20 LFI Vulnerability # Date: Monday, 05 April 2010 # Author: Vrs-hCk # Software Link: prof3tanetsonsorg/ # Version: Joomla Component Picasa version 20 # Tested on: # CVE : # Code : ================================================================================================ Title : Jooml ...