CVE-2010-1219: Path Traversal
Published Mar 30, 2010
·Updated
Directory traversal vulnerability in the JA News (comjanews) component 1.0 for Joomla! allows remote attackers to read arbitrary local files via a .. (dot dot) in the controller parameter to index.php. NOTE: some of these details are obtained from third party information.
Affected Software
4 affected components
Com Janews Com Janews=1.0
Joomla joomla
All of the following
Com Janews Com Janews=1.0
Joomla joomla
Event History
Mar 30, 2010
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
Description
Data Sourced
11:30 PM
DescriptionWeaknessAffected Software
Data Sourced
via NVD·11:30 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2010-1219?
CVE-2010-1219 is classified as having a medium severity due to its potential for exposing sensitive local files.
2
How do I fix CVE-2010-1219?
To fix CVE-2010-1219, update the JA News component to the latest version that addresses this vulnerability.
3
What type of vulnerability is CVE-2010-1219?
CVE-2010-1219 is a directory traversal vulnerability that allows attackers to read arbitrary local files.
4
Which versions of JA News are affected by CVE-2010-1219?
CVE-2010-1219 affects JA News version 1.0 specifically.
5
Can CVE-2010-1219 be exploited remotely?
Yes, CVE-2010-1219 can be exploited remotely by attackers using crafted requests.