Joomla! 漏洞列表
共找到 98 个与 Joomla! 相关的漏洞
📅 加载漏洞趋势中...
-
CVE-2008-4764: Joomla! <=2.0.0 RC2 - Local File Inclusion POC
Joomla! 2.0.0 RC2 and earlier are susceptible to local file inclusion in the eXtplorer module (com_extplorer) that allows remote attackers to read arbitrary files via a .. (dot dot) in the dir parameter in a show_error action. -
CVE-2008-6080: Joomla! ionFiles 4.4.2 - Local File Inclusion POC
Joomla! ionFiles 4.4.2 is susceptible to local file inclusion in download.php in the ionFiles (com_ionfiles) that allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter. -
CVE-2008-6172: Joomla! Component RWCards 3.0.11 - Local File Inclusion POC
A directory traversal vulnerability in captcha/captcha_image.php in the RWCards (com_rwcards) 3.0.11 component for Joomla! when magic_quotes_gpc is disabled allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the img parameter. -
CVE-2008-6222: Joomla! ProDesk 1.0/1.2 - Local File Inclusion POC
Joomla! Pro Desk Support Center (com_pro_desk) component 1.0 and 1.2 allows remote attackers to read arbitrary files via a .. (dot dot) in the include_file parameter to index.php. -
CVE-2009-2015: Joomla! MooFAQ 1.0 - Local File Inclusion POC
Joomla! Ideal MooFAQ 1.0 via com_moofaq allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter (local file inclusion). -
CVE-2009-2100: Joomla! JoomlaPraise Projectfork 2.0.10 - Local File Inclusion POC
Joomla! JoomlaPraise Projectfork (com_projectfork) 2.0.10 allows remote attackers to read arbitrary files via local file inclusion in the section parameter to index.php. -
CVE-2009-3318: Joomla! Roland Breedveld Album 1.14 - Local File Inclusion POC
Joomla! Roland Breedveld Album 1.14 (com_album) is susceptible to local file inclusion because it allows remote attackers to access arbitrary directories and have unspecified other impact via a .. (dot dot) in the target parameter to index.php. -
CVE-2009-4202: Joomla! Omilen Photo Gallery 0.5b - Local File Inclusion POC
Joomla! Omilen Photo Gallery (com_omphotogallery) component Beta 0.5 allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the controller parameter to index.php. -
CVE-2009-4679: Joomla! Portfolio Nexus - Remote File Inclusion POC
Joomla! Portfolio Nexus 1.5 contains a remote file inclusion vulnerability in the inertialFATE iF (com_if_nexus) component that allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the controller parameter to index.php. -
CVE-2010-0157: Joomla! Component com_biblestudy - Local File Inclusion POC
A directory traversal vulnerability in the Bible Study (com_biblestudy) component 6.1 for Joomla! allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the controller parameter in a studieslist action to index.php. -
CVE-2010-0467: Joomla! Component CCNewsLetter - Local File Inclusion POC
A directory traversal vulnerability in the ccNewsletter (com_ccnewsletter) component 1.0.5 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter in a ccnewsletter action to index.php. -
CVE-2010-0696: Joomla! Component Jw_allVideos - Arbitrary File Retrieval POC
A directory traversal vulnerability in includes/download.php in the JoomlaWorks AllVideos (Jw_allVideos) plugin 3.0 through 3.2 for Joomla! allows remote attackers to read arbitrary files via a ./../.../ (modified dot dot) in the file parameter. -
CVE-2010-0759: Joomla! Plugin Core Design Scriptegrator - Local File Inclusion POC
A directory traversal vulnerability in plugins/system/cdscriptegrator/libraries/highslide/js/jsloader.php in the Core Design Scriptegrator plugin 1.4.1 for Joomla! allows remote attackers to read, and possibly include and execute, arbitrary files via directory traversal sequences in the files[] parameter. -
CVE-2010-0942: Joomla! Component com_jvideodirect - Directory Traversal POC
Directory traversal vulnerability in the jVideoDirect (com_jvideodirect) component for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php. -
CVE-2010-0943: Joomla! Component com_jashowcase - Directory Traversal POC
A directory traversal vulnerability in the JA Showcase (com_jashowcase) component for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter in a jashowcase action to index.php. -
CVE-2010-0944: Joomla! Component com_jcollection - Directory Traversal POC
A directory traversal vulnerability in the JCollection (com_jcollection) component for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php. -
CVE-2010-0982: Joomla! Component com_cartweberp - Local File Inclusion POC
A directory traversal vulnerability in the CARTwebERP (com_cartweberp) component 1.56.75 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php. -
CVE-2010-0985: Joomla! Component com_abbrev - Local File Inclusion POC
A directory traversal vulnerability in the Abbreviations Manager (com_abbrev) component 1.1 for Joomla! allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the controller parameter to index.php. -
CVE-2010-1081: Joomla! Component com_communitypolls 1.5.2 - Local File Inclusion POC
A directory traversal vulnerability in the Community Polls (com_communitypolls) component 1.5.2, and possibly earlier, for Core Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php. -
CVE-2010-1217: Joomla! Component & Plugin JE Tooltip 1.0 - Local File Inclusion POC
A directory traversal vulnerability in the JE Form Creator (com_jeformcr) component for Joomla!, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via directory traversal sequences in the view parameter to index.php. NOTE -- the original researcher states that the affected product is JE Tooltip, not Form Creator; however, the exploit URL suggests that Form Creator is affected. -
CVE-2010-1219: Joomla! Component com_janews - Local File Inclusion POC
A directory traversal vulnerability in the JA News (com_janews) component 1.0 for Joomla! allows remote attackers to read arbitrary local files via a .. (dot dot) in the controller parameter to index.php. -
CVE-2010-1302: Joomla! Component DW Graph - Local File Inclusion POC
A directory traversal vulnerability in dwgraphs.php in the DecryptWeb DW Graphs (com_dwgraphs) component 1.0 for Joomla! allows remote attackers to read arbitrary files via directory traversal sequences in the controller parameter to index.php. -
CVE-2010-1304: Joomla! Component User Status - Local File Inclusion POC
A directory traversal vulnerability in userstatus.php in the User Status (com_userstatus) component 1.21.16 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php. -
CVE-2010-1305: Joomla! Component JInventory 1.23.02 - Local File Inclusion POC
A directory traversal vulnerability in jinventory.php in the JInventory (com_jinventory) component 1.23.02 and possibly other versions before 1.26.03, a module for Joomla!, allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php. -
CVE-2010-1306: Joomla! Component Picasa 2.0 - Local File Inclusion POC
A directory traversal vulnerability in the Picasa (com_joomlapicasa2) component 2.0 and 2.0.5 for Joomla! allows remote attackers to read arbitrary local files via a .. (dot dot) in the controller parameter to index.php. -
CVE-2010-1307: Joomla! Component Magic Updater - Local File Inclusion POC
A directory traversal vulnerability in the Magic Updater (com_joomlaupdater) component for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php. -
CVE-2010-1312: Joomla! Component News Portal 1.5.x - Local File Inclusion POC
A directory traversal vulnerability in the iJoomla News Portal (com_news_portal) component 1.5.x for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php. -
CVE-2010-1313: Joomla! Component Saber Cart 1.0.0.12 - Local File Inclusion POC
A directory traversal vulnerability in the Seber Cart (com_sebercart) component 1.0.0.12 and 1.0.0.13 for Joomla!, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via a .. (dot dot) in the view parameter to index.php. -
CVE-2010-1315: Joomla! Component webERPcustomer - Local File Inclusion POC
A directory traversal vulnerability in weberpcustomer.php in the webERPcustomer (com_weberpcustomer) component 1.2.1 and 1.x before 1.06.02 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php. -
CVE-2010-1340: Joomla! Component com_jresearch - 'Controller' Local File Inclusion POC
A directory traversal vulnerability in jresearch.php in the J!Research (com_jresearch) component for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php. -
CVE-2010-1352: Joomla! Component Juke Box 1.7 - Local File Inclusion POC
A directory traversal vulnerability in the JOOFORGE Jutebox (com_jukebox) component 1.0 and 1.7 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php. -
CVE-2010-1354: Joomla! Component VJDEO 1.0 - Local File Inclusion POC
A directory traversal vulnerability in the VJDEO (com_vjdeo) component 1.0 and 1.0.1 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php. -
CVE-2010-1461: Joomla! Component Photo Battle 1.0.1 - Local File Inclusion POC
A directory traversal vulnerability in the Photo Battle (com_photobattle) component 1.0.1 for Joomla! allows remote attackers to read arbitrary files via the view parameter to index.php. -
CVE-2010-1470: Joomla! Component Web TV 1.0 - Local File Inclusion POC
A directory traversal vulnerability in the Web TV (com_webtv) component 1.0 for Joomla! allows remote attackers to read arbitrary files and have possibly other unspecified impacts via a .. (dot dot) in the controller parameter to index.php. -
CVE-2010-1471: Joomla! Component Address Book 1.5.0 - Local File Inclusion POC
A directory traversal vulnerability in the AddressBook (com_addressbook) component 1.5.0 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php. -
CVE-2010-1472: Joomla! Component Horoscope 1.5.0 - Local File Inclusion POC
A directory traversal vulnerability in the Daily Horoscope (com_horoscope) component 1.5.0 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php. -
CVE-2010-1473: Joomla! Component Advertising 0.25 - Local File Inclusion POC
A directory traversal vulnerability in the Advertising (com_advertising) component 0.25 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impacts via a .. (dot dot) in the controller parameter to index.php. -
CVE-2010-1474: Joomla! Component Sweetykeeper 1.5 - Local File Inclusion POC
A directory traversal vulnerability in the Sweety Keeper (com_sweetykeeper) component 1.5.x for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impacts via a .. (dot dot) in the controller parameter to index.php. -
CVE-2010-1478: Joomla! Component Jfeedback 1.2 - Local File Inclusion POC
A directory traversal vulnerability in the Ternaria Informatica Jfeedback! (com_jfeedback) component 1.2 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impacts via a .. (dot dot) in the controller parameter to index.php. -
CVE-2010-1491: Joomla! Component MMS Blog 2.3.0 - Local File Inclusion POC
A directory traversal vulnerability in the MMS Blog (com_mmsblog) component 2.3.0 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impacts via a .. (dot dot) in the controller parameter to index.php. -
CVE-2010-1495: Joomla! Component Matamko 1.01 - Local File Inclusion POC
A directory traversal vulnerability in the Matamko (com_matamko) component 1.01 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php. -
CVE-2010-1531: Joomla! Component redSHOP 1.0 - Local File Inclusion POC
A directory traversal vulnerability in the redSHOP (com_redshop) component 1.0.x for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the view parameter to index.php. -
CVE-2010-1532: Joomla! Component PowerMail Pro 1.5.3 - Local File Inclusion POC
A directory traversal vulnerability in the givesight PowerMail Pro (com_powermail) component 1.5.3 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impacts via a .. (dot dot) in the controller parameter to index.php. -
CVE-2010-1534: Joomla! Component Shoutbox Pro - Local File Inclusion POC
A directory traversal vulnerability in the Shoutbox Pro (com_shoutbox) component for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php. -
CVE-2010-1535: Joomla! Component TRAVELbook 1.0.1 - Local File Inclusion POC
A directory traversal vulnerability in the TRAVELbook (com_travelbook) component 1.0.1 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impacts via a .. (dot dot) in the controller parameter to index.php. -
CVE-2010-1540: Joomla! Component com_blog - Directory Traversal POC
A directory traversal vulnerability in index.php in the MyBlog (com_myblog) component 3.0.329 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the task parameter. -
CVE-2010-1602: Joomla! Component ZiMB Comment 0.8.1 - Local File Inclusion POC
A directory traversal vulnerability in the ZiMB Comment (com_zimbcomment) component 0.8.1 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impacts via a .. (dot dot) in the controller parameter to index.php. -
CVE-2010-1603: Joomla! Component ZiMBCore 0.1 - Local File Inclusion POC
A directory traversal vulnerability in the ZiMB Core (aka ZiMBCore or com_zimbcore) component 0.1 in the ZiMB Manager collection for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impacts via a .. (dot dot) in the controller parameter to index.php. -
CVE-2010-1653: Joomla! Component Graphics 1.0.6 - Local File Inclusion POC
A directory traversal vulnerability in graphics.php in the Graphics (com_graphics) component 1.0.6 and 1.5.0 for Joomla! allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the controller parameter to index.php. -
CVE-2010-1657: Joomla! Component SmartSite 1.0.0 - Local File Inclusion POC
A directory traversal vulnerability in the SmartSite (com_smartsite) component 1.0.0 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php. -
CVE-2010-1658: Joomla! Component NoticeBoard 1.3 - Local File Inclusion POC
A directory traversal vulnerability in the Code-Garage NoticeBoard (com_noticeboard) component 1.3 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impacts via a .. (dot dot) in the controller parameter to index.php. -
CVE-2010-1714: Joomla! Component Arcade Games 1.0 - Local File Inclusion POC
A directory traversal vulnerability in the Arcade Games (com_arcadegames) component 1.0 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php. -
CVE-2010-1715: Joomla! Component Online Exam 1.5.0 - Local File Inclusion POC
A directory traversal vulnerability in the Online Examination (aka Online Exam or com_onlineexam) component 1.5.0 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php. -
CVE-2010-1717: Joomla! Component iF surfALERT 1.2 - Local File Inclusion POC
A directory traversal vulnerability in the iF surfALERT (com_if_surfalert) component 1.2 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impacts via a .. (dot dot) in the controller parameter to index.php. -
CVE-2010-1718: Joomla! Component Archery Scores 1.0.6 - Local File Inclusion POC
A directory traversal vulnerability in archeryscores.php in the Archery Scores (com_archeryscores) component 1.0.6 for Joomla! allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the controller parameter to index.php. -
CVE-2010-1719: Joomla! Component MT Fire Eagle 1.2 - Local File Inclusion POC
A directory traversal vulnerability in the MT Fire Eagle (com_mtfireeagle) component 1.2 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impacts via a .. (dot dot) in the controller parameter to index.php. -
CVE-2010-1722: Joomla! Component Online Market 2.x - Local File Inclusion POC
A directory traversal vulnerability in the Online Market (com_market) component 2.x for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impacts via a .. (dot dot) in the controller parameter to index.php. -
CVE-2010-1723: Joomla! Component iNetLanka Contact Us Draw Root Map 1.1 - Local File Inclusion POC
A directory traversal vulnerability in the iNetLanka Contact Us Draw Root Map (com_drawroot) component 1.1 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impacts via a .. (dot dot) in the controller parameter to index.php. -
CVE-2010-1858: Joomla! Component SMEStorage - Local File Inclusion POC
A directory traversal vulnerability in the SMEStorage (com_smestorage) component before 1.1 for Joomla! allows remote attackers to read arbitrary files via directory traversal sequences in the controller parameter to index.php. -
CVE-2010-1875: Joomla! Component Property - Local File Inclusion POC
A directory traversal vulnerability in the Real Estate Property (com_properties) component 3.1.22-03 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impacts via a .. (dot dot) in the controller parameter to index.php. -
CVE-2010-1878: Joomla! Component OrgChart 1.0.0 - Local File Inclusion POC
A directory traversal vulnerability in the OrgChart (com_orgchart) component 1.0.0 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php. -
CVE-2010-1953: Joomla! Component iNetLanka Multiple Map 1.0 - Local File Inclusion POC
A directory traversal vulnerability in the iNetLanka Multiple Map (com_multimap) component 1.0 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php. -
CVE-2010-1954: Joomla! Component iNetLanka Multiple root 1.0 - Local File Inclusion POC
A directory traversal vulnerability in the iNetLanka Multiple root (com_multiroot) component 1.0 and 1.1 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php. -
CVE-2010-1955: Joomla! Component Deluxe Blog Factory 1.1.2 - Local File Inclusion POC
A directory traversal vulnerability in the Deluxe Blog Factory (com_blogfactory) component 1.1.2 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php. -
CVE-2010-1979: Joomla! Component Affiliate Datafeeds 880 - Local File Inclusion POC
A directory traversal vulnerability in the Affiliate Datafeeds (com_datafeeds) component build 880 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php. -
CVE-2010-1980: Joomla! Component Joomla! Flickr 1.0 - Local File Inclusion POC
A directory traversal vulnerability in joomlaflickr.php in the Joomla! Flickr (com_joomlaflickr) component 1.0.3 for Joomla! allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the controller parameter to index.php. -
CVE-2010-1982: Joomla! Component JA Voice 2.0 - Local File Inclusion POC
A directory traversal vulnerability in the JA Voice (com_javoice) component 2.0 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the view parameter to index.php. -
CVE-2010-1983: Joomla! Component redTWITTER 1.0 - Local File Inclusion POC
A drectory traversal vulnerability in the redTWITTER (com_redtwitter) component 1.0.x including 1.0b11 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the view parameter to index.php. -
CVE-2010-2033: Joomla! Percha Categories Tree 0.6 - Local File Inclusion POC
A directory traversal vulnerability in the Percha Fields Attach (com_perchafieldsattach) component 1.x for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impacts via a .. (dot dot) in the controller parameter to index.php. -
CVE-2010-2034: Joomla! Component Percha Image Attach 1.1 - Directory Traversal POC
A directory traversal vulnerability in the Percha Image Attach (com_perchaimageattach) component 1.1 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impacts via a .. (dot dot) in the controller parameter to index.php. -
CVE-2010-2035: Joomla! Component Percha Gallery 1.6 Beta - Directory Traversal POC
A directory traversal vulnerability in the Percha Gallery (com_perchagallery) component 1.6 Beta for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impacts via a .. (dot dot) in the controller parameter to index.php. -
CVE-2010-2036: Joomla! Component Percha Fields Attach 1.0 - Directory Traversal POC
A directory traversal vulnerability in the Percha Fields Attach (com_perchafieldsattach) component 1.x for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impacts via a .. (dot dot) in the controller parameter to index.php. -
CVE-2010-2045: Joomla! Component FDione Form Wizard 1.0.2 - Local File Inclusion POC
A directory traversal vulnerability in the Dione Form Wizard (aka FDione or com_dioneformwizard) component 1.0.2 for Joomla! allows remote attackers to read arbitrary files via directory traversal sequences in the controller parameter to index.php. -
CVE-2010-2050: Joomla! Component MS Comment 0.8.0b - Local File Inclusion POC
A directory traversal vulnerability in the Moron Solutions MS Comment (com_mscomment) component 0.8.0b for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php. -
CVE-2010-2122: Joomla! Component simpledownload <=0.9.5 - Arbitrary File Retrieval POC
A directory traversal vulnerability in the SimpleDownload (com_simpledownload) component before 0.9.6 for Joomla! allows remote attackers to retrieve arbitrary files via a .. (dot dot) in the controller parameter to index.php. -
CVE-2010-2128: Joomla! Component JE Quotation Form 1.0b1 - Local File Inclusion POC
A directory traversal vulnerability in the JE Quotation Form (com_jequoteform) component 1.0b1 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impacts via a .. (dot dot) in the view parameter to index.php. -
CVE-2010-2507: Joomla! Component Picasa2Gallery 1.2.8 - Local File Inclusion POC
A directory traversal vulnerability in the Picasa2Gallery (com_picasa2gallery) component 1.2.8 and earlier for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impacts via a .. (dot dot) in the controller parameter to index.php. -
CVE-2010-2680: Joomla! Component jesectionfinder - Local File Inclusion POC
A directory traversal vulnerability in the JExtensions JE Section/Property Finder (jesectionfinder) component for Joomla! allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the view parameter to index.php. -
CVE-2010-2682: Joomla! Component Realtyna Translator 1.0.15 - Local File Inclusion POC
A directory traversal vulnerability in the Realtyna Translator (com_realtyna) component 1.0.15 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impacts via a .. (dot dot) in the controller parameter to index.php. -
CVE-2010-2857: Joomla! Component Music Manager - Local File Inclusion POC
A directory traversal vulnerability in the Music Manager component for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impacts via a .. (dot dot) in the cid parameter to album.html. -
CVE-2010-2918: Joomla! Component Visites 1.1 - MosConfig_absolute_path Remote File Inclusion POC
A PHP remote file inclusion vulnerability in core/include/myMailer.class.php in the Visites (com_joomla-visites) component 1.1 RC2 for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter. -
CVE-2010-2920: Joomla! Component Foobla Suggestions 1.5.1.2 - Local File Inclusion POC
A directory traversal vulnerability in the Foobla Suggestions (com_foobla_suggestions) component 1.5.1.2 for Joomla! allows remote attackers to read arbitrary files via directory traversal sequences in the controller parameter to index.php. -
CVE-2010-3426: Joomla! Component Jphone 1.0 Alpha 3 - Local File Inclusion POC
A directory traversal vulnerability in jphone.php in the JPhone (com_jphone) component 1.0 Alpha 3 for Joomla! allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the controller parameter to index.php. -
CVE-2010-4617: Joomla! Component JotLoader 2.2.1 - Local File Inclusion POC
A directory traversal vulnerability in the JotLoader (com_jotloader) component 2.2.1 for Joomla! allows remote attackers to read arbitrary files via directory traversal sequences in the section parameter to index.php. -
CVE-2010-4719: Joomla! Component JRadio - Local File Inclusion POC
A directory traversal vulnerability in JRadio (com_jradio) component before 1.5.1 for Joomla! allows remote attackers to read arbitrary files via directory traversal sequences in the controller parameter to index.php. -
CVE-2010-4769: Joomla! Component Jimtawl 1.0.2 - Local File Inclusion POC
A directory traversal vulnerability in the Jimtawl (com_jimtawl) component 1.0.2 Joomla! allows remote attackers to read arbitrary files and possibly unspecified other impacts via a .. (dot dot) in the task parameter to index.php. -
CVE-2010-4977: Joomla! Component Canteen 1.0 - Local File Inclusion POC
A SQL injection vulnerability in menu.php in the Canteen (com_canteen) component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the mealid parameter to index.php. -
CVE-2010-5028: Joomla! Component JE Job 1.0 - Local File Inclusion POC
A SQL injection vulnerability in the JExtensions JE Job (com_jejob) component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter in an item action to index.php. -
CVE-2010-5286: Joomla! Component Jstore - 'Controller' Local File Inclusion POC
A directory traversal vulnerability in Jstore (com_jstore) component for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impacts via a .. (dot dot) in the controller parameter to index.php. -
CVE-2011-4804: Joomla! Component com_kp - 'Controller' Local File Inclusion POC
A directory traversal vulnerability in the obSuggest (com_obsuggest) component before 1.8 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php. -
CVE-2015-4074: Joomla! Helpdesk Pro plugin <1.4.0 - Local File Inclusion POC
Directory traversal vulnerability in the Helpdesk Pro plugin before 1.4.0 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the filename parameter in a ticket.download_attachment task. -
CVE-2015-7297: Joomla! Core SQL Injection POC
A SQL injection vulnerability in Joomla! 3.2 before 3.4.4 allows remote attackers to execute arbitrary SQL commands. -
CVE-2018-17254: Joomla! JCK Editor SQL Injection POC
The JCK Editor component 6.4.4 for Joomla! allows SQL Injection via the jtreelink/dialogs/links.php parent parameter. -
CVE-2018-6008: Joomla! Jtag Members Directory 5.3.7 - Local File Inclusion POC
Joomla! Jtag Members Directory 5.3.7 is vulnerable to local file inclusion via the download_file parameter. -
CVE-2018-6605: Joomla! Component Zh BaiduMap 3.0.0.1 - SQL Injection POC
SQL Injection exists in the Zh BaiduMap 3.0.0.1 component for Joomla! via the id parameter in a getPlacemarkDetails, getPlacemarkHoverText, getPathHoverText, or getPathDetails request. -
CVE-2018-7314: Joomla! Component PrayerCenter 3.0.2 - SQL Injection POC
SQL Injection exists in the PrayerCenter 3.0.2 component for Joomla! via the sessionid parameter, a different vulnerability than CVE-2008-6429. -
CVE-2020-23972: Joomla! Component GMapFP 3.5 - Arbitrary File Upload POC
Joomla! Component GMapFP 3.5 is vulnerable to arbitrary file upload vulnerabilities. An attacker can access the upload function of the application without authentication and can upload files because of unrestricted file upload which can be bypassed by changing Content-Type & name file too double ext. -
CVE-2021-28377: Joomla! ChronoForums 2.0.11 - Local File Inclusion POC
Joomla! ChronoForums 2.0.11 avatar function is vulnerable to local file inclusion through unauthenticated path traversal attacks. This enables an attacker to read arbitrary files, for example the Joomla! configuration file which contains credentials.