CVE-2010-0759
Directory traversal vulnerability in plugins/system/cdscriptegrator/libraries/highslide/js/jsloader.php in the Core Design Scriptegrator plugin 1.4.1 for Joomla! allows remote attackers to read, and possibly include and execute, arbitrary files via…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 15.2%, higher than 97% of all known CVEs. Patch or mitigate before the next change window.
Description
Directory traversal vulnerability in plugins/system/cdscriptegrator/libraries/highslide/js/jsloader.php in the Core Design Scriptegrator plugin 1.4.1 for Joomla! allows remote attackers to read, and possibly include and execute, arbitrary files via directory traversal sequences in the files[] parameter, a different vector than CVE-2010-0760.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 15.24% probability · 97th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-22
- Affected
- greatjoomla/scriptegrator plugin
- Source
- cve@mitre.org
References
- http://packetstormsecurity.org/1002-exploits/joomlascriptegrator-lfi.txtExploit
- http://secunia.com/advisories/38637Vendor Advisory
- http://www.exploit-db.com/exploits/11498
- http://www.osvdb.org/62486
- http://www.securityfocus.com/bid/38296Exploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/56380
- http://packetstormsecurity.org/1002-exploits/joomlascriptegrator-lfi.txtExploit
- http://secunia.com/advisories/38637Vendor Advisory
- http://www.exploit-db.com/exploits/11498
- http://www.osvdb.org/62486
- http://www.securityfocus.com/bid/38296Exploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/56380
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.