CVE-2010-1304: Path Traversal
Published Apr 8, 2010
·Updated
Directory traversal vulnerability in userstatus.php in the User Status (comuserstatus) component 1.21.16 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.
Affected Software
4 affected components
Joomlamo Com Userstatus=1.21.16
Joomla Joomla\!
All of the following
Joomlamo Com Userstatus=1.21.16
Joomla Joomla\!
Event History
Apr 8, 2010
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Data Sourced
04:30 PM
DescriptionWeaknessAffected Software
Data Sourced
via NVD·04:30 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2010-1304?
CVE-2010-1304 has a medium severity rating as it allows remote attackers to read sensitive files.
2
How do I fix CVE-2010-1304?
To fix CVE-2010-1304, update the User Status component to the latest version or apply patches provided by the developer.
3
What types of attacks can exploit CVE-2010-1304?
CVE-2010-1304 can be exploited through directory traversal attacks that allow unauthorized file access.
4
Which Joomla! version is affected by CVE-2010-1304?
CVE-2010-1304 specifically affects the com_userstatus component version 1.21.16 for Joomla!
5
What is the primary impact of CVE-2010-1304?
The primary impact of CVE-2010-1304 is the unauthorized access and disclosure of sensitive files on the server.