CVE-2010-2259: Path Traversal
Directory traversal vulnerability in the BF Survey (combfsurvey) component for Joomla! allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the controller parameter to index.php.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2010-2259?
CVE-2010-2259 is considered a critical vulnerability due to its potential for local file inclusion and remote code execution.
How do I fix CVE-2010-2259?
To fix CVE-2010-2259, update the BF Survey component to version 1.2.7 or later, as these versions address the directory traversal issue.
Which versions of Joomla are affected by CVE-2010-2259?
CVE-2010-2259 affects versions of the BF Survey component prior to 1.2.7, but Joomla itself is not directly vulnerable.
What type of attacks can exploit CVE-2010-2259?
CVE-2010-2259 can be exploited through directory traversal attacks, allowing attackers to include and execute arbitrary local files.
Is there a patch available for CVE-2010-2259?
Yes, a patch is available in the updated versions of the BF Survey component, specifically version 1.2.7 and above.