Joomla! JCE Component Multiple Directory Traversal Vulnerabilities
BID:49338
Info
Joomla! JCE Component Multiple Directory Traversal Vulnerabilities
| Bugtraq ID: | 49338 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 28 2011 12:00AM |
| Updated: | Mar 27 2013 08:06AM |
| Credit: | AmnPardaz Security Research Team |
| Vulnerable: |
Joomla JCE 2.0.10 |
| Not Vulnerable: | |
Discussion
Joomla! JCE Component Multiple Directory Traversal Vulnerabilities
The JCE component for Joomla! is prone to multiple directory-traversal vulnerabilities because it fails to sufficiently sanitize user-supplied input.
Remote attackers can use a specially crafted request with directory-traversal sequences ('../') to view directories or upload, rename, and delete arbitrary files within the context of the application. This may aid in further attacks.
JCE component 2.0.10 is vulnerable; other products may also be affected.
The JCE component for Joomla! is prone to multiple directory-traversal vulnerabilities because it fails to sufficiently sanitize user-supplied input.
Remote attackers can use a specially crafted request with directory-traversal sequences ('../') to view directories or upload, rename, and delete arbitrary files within the context of the application. This may aid in further attacks.
JCE component 2.0.10 is vulnerable; other products may also be affected.
Exploit / POC
Joomla! JCE Component Multiple Directory Traversal Vulnerabilities
Attackers can exploit these issues through a browser.
The following exploit codes are available:
Attackers can exploit these issues through a browser.
The following exploit codes are available:
Solution / Fix
Joomla! JCE Component Multiple Directory Traversal Vulnerabilities
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Joomla! JCE Component Multiple Directory Traversal Vulnerabilities
References:
References:
- JCE Joomla Extension <=2.0.10 Multiple Vulnerabilities (AmnPardaz Security Research Team)
- JCE Joomla Extension Homepage (Joomla)
- Joomla Homepage (Joomla)