7.5
CVSSv2

CVE-2010-5280

Published: 26/11/2012 Updated: 10/10/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Directory traversal vulnerability in the Community Builder Enhanced (CBE) (com_cbe) component 1.4.8, 1.4.9, and 1.4.10 for Joomla! allows remote malicious users to include and execute arbitrary local files via a .. (dot dot) in the tabname parameter in a userProfile action to index.php. NOTE: this can be leveraged to execute arbitrary code by using the file upload feature.

Vulnerable Product Search on Vulmon Subscribe to Product

joomla-cbe com_cbe 1.4.9

joomla-cbe com_cbe 1.4.10

joomla-cbe com_cbe 1.4.8

Exploits

Description: Joomla CBE suffers from a local file inclusion vulnerability As CBE also offers file uploading functionality that allows to upload files that contain php-code, this can be used to execute arbitary system-commands on the host with the webservers privileges Risk: High Affected versions: - CBE v1410 - CBE v149 - CBE v148 (may ...