First published: Thu Apr 08 2010(Updated: )
Directory traversal vulnerability in weberpcustomer.php in the webERPcustomer (com_weberpcustomer) component 1.2.1 and 1.x before 1.06.02 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php. NOTE: some of these details are obtained from third party information.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
joomlamo com weberpcustomer | =1.2.1 | |
Joomla |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-1315 is classified as a medium severity vulnerability due to its potential to allow unauthorized file access.
To fix CVE-2010-1315, you should upgrade the webERPcustomer component to version 1.06.02 or later.
CVE-2010-1315 affects webERPcustomer component versions 1.2.1 and earlier in Joomla! installations.
CVE-2010-1315 enables remote attackers to exploit directory traversal to read arbitrary files on the server.
Yes, CVE-2010-1315 can be easily exploited by sending specially crafted requests to the vulnerable Joomla! component.