CVE-2010-0467

Directory traversal vulnerability in the ccNewsletter (com_ccnewsletter) component 1.0.5 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter in a ccnewsletter action to index.php.
References
Link Resource
http://secunia.com/advisories/38378 Broken Link Third Party Advisory
http://www.chillcreations.com/en/blog/ccnewsletter-joomla-newsletter/ccnewsletter-106-security-release.html Broken Link Vendor Advisory
http://www.exploit-db.com/exploits/11277 Third Party Advisory VDB Entry
http://www.exploit-db.com/exploits/11282 Third Party Advisory VDB Entry
http://www.securityfocus.com/bid/37987 Broken Link Exploit Third Party Advisory VDB Entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/55953 Third Party Advisory VDB Entry
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:chillcreations:com_ccnewsletter:1.0.5:*:*:*:*:*:*:*
cpe:2.3:a:joomla:joomla\!:*:*:*:*:*:*:*:*

History

26 Jan 2024, 17:44

Type Values Removed Values Added
References () http://secunia.com/advisories/38378 - Third Party Advisory () http://secunia.com/advisories/38378 - Broken Link, Third Party Advisory
References () http://www.chillcreations.com/en/blog/ccnewsletter-joomla-newsletter/ccnewsletter-106-security-release.html - Vendor Advisory () http://www.chillcreations.com/en/blog/ccnewsletter-joomla-newsletter/ccnewsletter-106-security-release.html - Broken Link, Vendor Advisory
References () http://www.securityfocus.com/bid/37987 - Exploit, Third Party Advisory, VDB Entry () http://www.securityfocus.com/bid/37987 - Broken Link, Exploit, Third Party Advisory, VDB Entry

Information

Published : 2010-02-02 17:30

Updated : 2024-01-26 17:44


NVD link : CVE-2010-0467

Mitre link : CVE-2010-0467

CVE.ORG link : CVE-2010-0467


JSON object : View

Products Affected

joomla

  • joomla\!

chillcreations

  • com_ccnewsletter
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')