vendor:
Jvehicles
by:
Chip D3 Bi0s
N/A
CVSS
N/A
Local File Inclusion
CWE
Product Name: Jvehicles
Affected Version From: 1.0
Affected Version To: 1.0
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
2010
Joomla Component Jvehicles Local File Inclusion
This vulnerability allows an attacker to include local files on the server by exploiting an error in the 'jvehicles.php' file of the Jvehicles component in Joomla. By manipulating the 'controller' parameter in the URL, an attacker can traverse the file system and access sensitive files, such as the '/etc/passwd' file.
Mitigation:
To mitigate this vulnerability, it is recommended to update to a patched version of the Jvehicles component or to remove the vulnerable component from the Joomla installation.