vendor:
com_pcchess
by:
team_elite
5.5
CVSS
MEDIUM
Local File Inclusion
CWE
Product Name: com_pcchess
Affected Version From:
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
joomla Component com_pcchess Local File Inclusion Vulnerability
The exploit allows an attacker to include local files by manipulating the 'controller' parameter in the URL. The vulnerability can be exploited by appending '../../../../../../../../../../../' to the 'controller' parameter.
Mitigation:
Apply the latest patch or update provided by the vendor. Restrict access to the affected component.