CVE-2006-1027: Medium severity Joomla joomla vulnerability
Published Mar 7, 2006
·Updated
feedcreator.class.php (aka the syndication component) in Joomla! 1.0.7 allows remote attackers to obtain sensitive information via a "/" (slash) in the feed parameter to index.php, which reveals the path in an error message.
Affected Software
1 affected component
Joomla joomla=1.0.7
Remediation
Patch Available
Event History
Mar 7, 2006
CVE Published
12:02 AM
CVE Published
via MITRE·05:00 AM
Data Sourced
via MITRE·05:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-1027?
CVE-2006-1027 has a moderate severity rating as it allows sensitive information disclosure.
2
How do I fix CVE-2006-1027?
To fix CVE-2006-1027, upgrade Joomla to a later version that does not contain this vulnerability.
3
What kinds of information can be exposed by CVE-2006-1027?
CVE-2006-1027 can expose the filesystem path of the server through error messages.
4
Is my Joomla site vulnerable if I am using version 1.0.7?
Yes, if you are using Joomla version 1.0.7, your site is vulnerable to CVE-2006-1027.
5
What is affected by CVE-2006-1027?
CVE-2006-1027 affects the feedcreator.class.php component in Joomla version 1.0.7.