CVE-2010-1953: Path Traversal
Published May 18, 2010
·Updated
Directory traversal vulnerability in the iNetLanka Multiple Map (commultimap) component 1.0 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.
Affected Software
4 affected components
Joomlacomponent.inetlanka Com Multimap=1.0
Joomla Joomla\!
All of the following
Joomlacomponent.inetlanka Com Multimap=1.0
Joomla Joomla\!
Event History
May 18, 2010
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
May 19, 2010
Data Sourced
12:07 PM
DescriptionWeaknessAffected Software
Data Sourced
via NVD·12:07 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2010-1953?
CVE-2010-1953 is classified as a medium severity vulnerability.
2
How do I fix CVE-2010-1953?
To fix CVE-2010-1953, you should upgrade the iNetLanka Multiple Map component to a version that is not affected or implement access controls to restrict file reading.
3
What specific issue does CVE-2010-1953 exploit?
CVE-2010-1953 exploits a directory traversal vulnerability that allows remote attackers to read arbitrary files.
4
Which software is affected by CVE-2010-1953?
CVE-2010-1953 affects the iNetLanka Multiple Map component version 1.0 for Joomla!.
5
Can I be targeted by CVE-2010-1953 if I am not using Joomla!?
No, CVE-2010-1953 specifically impacts Joomla! websites using the vulnerable version of the iNetLanka component.