CVE-2010-1315: Path Traversal
Directory traversal vulnerability in weberpcustomer.php in the webERPcustomer (comweberpcustomer) component 1.2.1 and 1.x before 1.06.02 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php. NOTE: some of these details are obtained from third party information.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2010-1315?
CVE-2010-1315 is classified as a medium severity vulnerability due to its potential to allow unauthorized file access.
How do I fix CVE-2010-1315?
To fix CVE-2010-1315, you should upgrade the webERPcustomer component to version 1.06.02 or later.
What systems are affected by CVE-2010-1315?
CVE-2010-1315 affects webERPcustomer component versions 1.2.1 and earlier in Joomla! installations.
What type of attack does CVE-2010-1315 enable?
CVE-2010-1315 enables remote attackers to exploit directory traversal to read arbitrary files on the server.
Is CVE-2010-1315 easily exploitable?
Yes, CVE-2010-1315 can be easily exploited by sending specially crafted requests to the vulnerable Joomla! component.