First published: Wed Apr 16 2008(Updated: )
Directory traversal vulnerability in index.php in the joomlaXplorer (com_joomlaxplorer) Mambo/Joomla! component 1.6.2 and earlier allows remote attackers to list arbitrary directories via a .. (dot dot) in the dir parameter in a show_error action.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Joomla Explorer | <=1.6.2 | |
Joomla | ||
Mambo |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-1849 is considered a high severity vulnerability due to its potential to allow unauthorized directory traversal.
To mitigate CVE-2008-1849, upgrade to a patched version of the joomlaXplorer component that exceeds version 1.6.2.
CVE-2008-1849 affects the joomlaXplorer component in Joomla and Mambo installations up to version 1.6.2.
The exploit for CVE-2008-1849 involves manipulating the 'dir' parameter in the show_error action to perform directory traversal.
Yes, there are known exploits for CVE-2008-1849 which demonstrate how to leverage the directory traversal vulnerability.