6.8
CVSSv2

CVE-2010-1607

Published: 29/04/2010 Updated: 17/08/2017
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Directory traversal vulnerability in wmi.php in the Webmoney Web Merchant Interface (aka WMI or com_wmi) component 1.5.0 for Joomla! allows remote malicious users to include and execute arbitrary local files via a .. (dot dot) in the controller parameter to index.php.

Vulnerable Product Search on Vulmon Subscribe to Product

paysyspro com_wmi 1.5.0

Exploits

================================================================================================ Title : Joomla Component wmi (com_wmi) LFI Vulnerability Vendor : wwwpaysysprocom/ Download : wwwpaysysprocom/jotloader/filesdownload/3 Date : Sunday, 21 April 2010 - GMT +07:00 Jakarta, Indonesia Author : wishnusak ...