Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-j52g-x5qp-5c66

Опубликовано: 02 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Directory traversal vulnerability in the JE Form Creator (com_jeformcr) component for Joomla!, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via directory traversal sequences in the view parameter to index.php. NOTE: the original researcher states that the affected product is JE Tooltip, not Form Creator; however, the exploit URL suggests that Form Creator is affected.

Directory traversal vulnerability in the JE Form Creator (com_jeformcr) component for Joomla!, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via directory traversal sequences in the view parameter to index.php. NOTE: the original researcher states that the affected product is JE Tooltip, not Form Creator; however, the exploit URL suggests that Form Creator is affected.

EPSS

Процентиль: 92%
0.07857
Низкий

Дефекты

CWE-22

Связанные уязвимости

nvd
почти 16 лет назад

Directory traversal vulnerability in the JE Form Creator (com_jeformcr) component for Joomla!, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via directory traversal sequences in the view parameter to index.php. NOTE: the original researcher states that the affected product is JE Tooltip, not Form Creator; however, the exploit URL suggests that Form Creator is affected.

EPSS

Процентиль: 92%
0.07857
Низкий

Дефекты

CWE-22