CVE-2010-0696: Path Traversal
Directory traversal vulnerability in includes/download.php in the JoomlaWorks AllVideos (JwallVideos) plugin 3.0 through 3.2 for Joomla! allows remote attackers to read arbitrary files via a ./../.../ (modified dot dot) in the file parameter.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2010-0696?
CVE-2010-0696 is classified as a medium severity vulnerability due to its potential to allow unauthorized file access.
How do I fix CVE-2010-0696?
To fix CVE-2010-0696, update the JoomlaWorks AllVideos plugin to version 3.2 or later, which addresses the directory traversal vulnerability.
What versions of JoomlaWorks AllVideos are affected by CVE-2010-0696?
CVE-2010-0696 affects JoomlaWorks AllVideos plugin versions 3.0, 3.1, and 3.2.
What type of attack does CVE-2010-0696 enable?
CVE-2010-0696 enables remote attackers to exploit the vulnerability to read arbitrary files on the server.
Is the Joomla core software vulnerable to CVE-2010-0696?
No, the Joomla core software itself is not vulnerable to CVE-2010-0696.