JE Story submit Component for Joomla! Unspecified Local File Include Vulnerability
BID:47978
Info
JE Story submit Component for Joomla! Unspecified Local File Include Vulnerability
| Bugtraq ID: | 47978 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 25 2011 12:00AM |
| Updated: | May 25 2011 12:00AM |
| Credit: | Joomla |
| Vulnerable: |
Harmis Technology JE Story submit 1.4 |
| Not Vulnerable: |
Harmis Technology JE Story submit 1.8 |
Discussion
JE Story submit Component for Joomla! Unspecified Local File Include Vulnerability
The JE Story submit component for Joomla! is prone to an unspecified local file-include vulnerability because it fails to properly sanitize user-supplied input.
An attacker can exploit this vulnerability to obtain potentially sensitive information and execute arbitrary local scripts in the context of the webserver process.
Versions prior to JE Story submit 1.8 are vulnerable.
The JE Story submit component for Joomla! is prone to an unspecified local file-include vulnerability because it fails to properly sanitize user-supplied input.
An attacker can exploit this vulnerability to obtain potentially sensitive information and execute arbitrary local scripts in the context of the webserver process.
Versions prior to JE Story submit 1.8 are vulnerable.
Exploit / POC
JE Story submit Component for Joomla! Unspecified Local File Include Vulnerability
Attackers can exploit this issue through a browser.
Attackers can exploit this issue through a browser.
Solution / Fix
JE Story submit Component for Joomla! Unspecified Local File Include Vulnerability
Solution:
Vendor patch is available. Please see the reference for more details.
Solution:
Vendor patch is available. Please see the reference for more details.
References
JE Story submit Component for Joomla! Unspecified Local File Include Vulnerability
References:
References:
- Joomla Homepage (Joomla)
- JE Story submit (Joomla)