vendor:
Joomla
by:
irk4z[at]yahoo.pl
7.5
CVSS
HIGH
Local Directory Traversal
22
CWE
Product Name: Joomla
Affected Version From: 1.5.2008
Affected Version To: 1.5.2008
Patch Exists: YES
Related CWE: N/A
CPE: a:joomla:joomla
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2009
Joomla <= 1.5.8 (xstandard editor) Local Directory Traversal Vulnerability
This vulnerability allows an attacker to traverse the local directory of the vulnerable Joomla version 1.5.8 using the xstandard editor. The attacker can send a specially crafted HTTP request with the X_CMS_LIBRARY_PATH header set to the desired directory and the server will respond with the contents of the directory. This vulnerability can be exploited to gain access to sensitive information stored in the server.
Mitigation:
Upgrade to the latest version of Joomla.