First published: Tue May 25 2010(Updated: )
Directory traversal vulnerability in the Dione Form Wizard (aka FDione or com_dioneformwizard) component 1.0.2 for Joomla! allows remote attackers to read arbitrary files via directory traversal sequences in the controller parameter to index.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Dioneformwizard | =1.0.2 | |
Joomla | ||
All of | ||
Dioneformwizard | =1.0.2 | |
Joomla |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-2045 is considered a medium severity vulnerability due to its ability to allow unauthorized file access.
To mitigate CVE-2010-2045, upgrade the Dione Form Wizard component to version 1.0.3 or later.
CVE-2010-2045 is a directory traversal vulnerability in the Dione Form Wizard component for Joomla! that allows attackers to read arbitrary files.
CVE-2010-2045 specifically affects Dione Form Wizard version 1.0.2 used with Joomla! installations.
Yes, CVE-2010-2045 can be exploited remotely by attackers to gain unauthorized access to file systems.