First published: Tue May 25 2010(Updated: )
Directory traversal vulnerability in the Percha Fields Attach (com_perchafieldsattach) component 1.x for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the controller parameter to index.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Percha com perchafieldsattach | =1.0 | |
Joomla |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-2036 is classified as a medium severity vulnerability due to its potential to allow unauthorized file access.
To fix CVE-2010-2036, upgrade the Percha Fields Attach component to the latest version that addresses the directory traversal issue.
CVE-2010-2036 does not directly lead to remote code execution, but it allows attackers to read arbitrary files which could contain sensitive information.
CVE-2010-2036 specifically affects version 1.0 of the Percha Fields Attach component integrated with Joomla!.
Yes, there are known exploits for CVE-2010-2036 that demonstrate how attackers can leverage the vulnerability for unauthorized file access.