CVE Database
/

CVE-2010-3426

Back to search

CVE-2010-3426

Published: Sep 16, 2010

Modified: Aug 7, 2024

PUBLISHED

Description

Directory traversal vulnerability in jphone.php in the JPhone (com_jphone) component 1.0 Alpha 3 for Joomla! allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the controller parameter to index.php.

VendorProductVersions

n/a

n/a

affected
n/a

References

14964
exploit
x_refsource_EXPLOIT-DB
43147
vdb-entry
x_refsource_BID
jphone-index-file-include(61723)
vdb-entry
x_refsource_XF

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now