First published: Wed Jun 09 2010(Updated: )
Directory traversal vulnerability in the BF Survey (com_bfsurvey) component for Joomla! allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the controller parameter to index.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Tamlyncreative BFsurvey Pro Free | =1.2.6 | |
Joomla | ||
tamlyncreative com bfsurvey pro | <=1.3.0 | |
tamlyncreative com bfsurvey basic | <=1.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-2259 is considered a critical vulnerability due to its potential for local file inclusion and remote code execution.
To fix CVE-2010-2259, update the BF Survey component to version 1.2.7 or later, as these versions address the directory traversal issue.
CVE-2010-2259 affects versions of the BF Survey component prior to 1.2.7, but Joomla itself is not directly vulnerable.
CVE-2010-2259 can be exploited through directory traversal attacks, allowing attackers to include and execute arbitrary local files.
Yes, a patch is available in the updated versions of the BF Survey component, specifically version 1.2.7 and above.