CVE-2010-1217: Joomla! Component & Plugin JE Tooltip 1.0 – Local File Inclusion

CVE-2010-1217: Joomla! Component & Plugin JE Tooltip 1.0 - Local File Inclusion-渗透云记 - 专注于网络安全与技术分享
CVE-2010-1217: Joomla! Component & Plugin JE Tooltip 1.0 – Local File Inclusion
此内容为付费阅读,请付费后查看
100积分
付费阅读

漏洞标题

CVE-2010-1217: Joomla! Component & Plugin JE Tooltip 1.0 – Local File Inclusion

漏洞描述

A directory traversal vulnerability in the JE Form Creator (com_jeformcr) component for Joomla!, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via directory traversal sequences in the view parameter to index.php. NOTE — the original researcher states that the affected product is JE Tooltip, not Form Creator; however, the exploit URL suggests that Form Creator is affected.

PoC代码

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享