First published: Tue May 25 2010(Updated: )
Directory traversal vulnerability in the Percha Image Attach (com_perchaimageattach) component 1.1 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the controller parameter to index.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Percha com perchaimageattach | =1.1 | |
Joomla |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2010-2034 is classified as high due to the potential for remote attackers to access sensitive files.
To fix CVE-2010-2034, update the Percha Image Attach component to a version that does not have this vulnerability or apply any patches provided by the vendor.
The impact of CVE-2010-2034 includes unauthorized file access and the potential for further exploitation on the affected Joomla! site.
CVE-2010-2034 specifically affects Joomla! installations that utilize the vulnerable version of the Percha Image Attach component 1.1.
Yes, CVE-2010-2034 is exploitable remotely, allowing attackers to manipulate requests to gain access to arbitrary files.