First published: Tue Mar 16 2010(Updated: )
Directory traversal vulnerability in the Abbreviations Manager (com_abbrev) component 1.1 for Joomla! allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the controller parameter to index.php. NOTE: some of these details are obtained from third party information.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
chris simon com Abbrev | =1.1 | |
Joomla | ||
All of | ||
Chris Simon Com Abbrev | =1.1 | |
Joomla |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-0985 has a medium severity rating due to its potential for remote exploitation of local files.
To fix CVE-2010-0985, update the Abbreviations Manager component to a version that is not affected by this vulnerability.
CVE-2010-0985 affects Joomla! when using the Abbreviations Manager component version 1.1.
Yes, CVE-2010-0985 can be exploited remotely by attackers using a directory traversal attack.
Exploitation of CVE-2010-0985 can lead to unauthorized access and execution of arbitrary files on the server.