CVE-2010-0696: Joomla! Component Jw_allVideos – Arbitrary File Retrieval

CVE-2010-0696: Joomla! Component Jw_allVideos - Arbitrary File Retrieval-渗透云记 - 专注于网络安全与技术分享
CVE-2010-0696: Joomla! Component Jw_allVideos – Arbitrary File Retrieval
此内容为付费阅读,请付费后查看
100积分
付费阅读

漏洞标题

CVE-2010-0696: Joomla! Component Jw_allVideos – Arbitrary File Retrieval

漏洞描述

A directory traversal vulnerability in includes/download.php in the JoomlaWorks AllVideos (Jw_allVideos) plugin 3.0 through 3.2 for Joomla! allows remote attackers to read arbitrary files via a ./../…/ (modified dot dot) in the file parameter.

PoC代码

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享