Joomla! Simple File Lister module Directory Traversal Vulnerability
BID:49343
Info
Joomla! Simple File Lister module Directory Traversal Vulnerability
| Bugtraq ID: | 49343 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 28 2011 12:00AM |
| Updated: | Aug 28 2011 12:00AM |
| Credit: | evilsocket |
| Vulnerable: |
Joomla Simple File Lister 1.0 |
| Not Vulnerable: | |
Discussion
Joomla! Simple File Lister module Directory Traversal Vulnerability
The Simple File Lister module for Joomla! is prone to a directory-traversal vulnerability because it fails to sufficiently sanitize user-supplied input data.
Exploiting the issue may allow an attacker to obtain sensitive information that could aid in further attacks.
Simple File Lister versions 1.0 and prior are vulnerable.
The Simple File Lister module for Joomla! is prone to a directory-traversal vulnerability because it fails to sufficiently sanitize user-supplied input data.
Exploiting the issue may allow an attacker to obtain sensitive information that could aid in further attacks.
Simple File Lister versions 1.0 and prior are vulnerable.
Exploit / POC
Joomla! Simple File Lister module Directory Traversal Vulnerability
Attackers can exploit this issue via a browser.
The following example URI is available:
http://www.example.com/index.php?option=com_content&view=article&id=[A VALID ID]&Itemid=[A VALID ID]&sflaction=dir&sflDir=../../..
Attackers can exploit this issue via a browser.
The following example URI is available:
http://www.example.com/index.php?option=com_content&view=article&id=[A VALID ID]&Itemid=[A VALID ID]&sflaction=dir&sflDir=../../..
Solution / Fix
Joomla! Simple File Lister module Directory Traversal Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Joomla! Simple File Lister module Directory Traversal Vulnerability
References:
References: