CVE-2009-0113

Directory traversal vulnerability in attachmentlibrary.php in the XStandard component for Joomla! 1.5.8 and earlier allows remote attackers to list arbitrary directories via a .. (dot dot) in the X_CMS_LIBRARY_PATH HTTP header.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:joomla:xstandard:*:*:*:*:*:*:*:*
OR cpe:2.3:a:joomla:joomla:*:*:*:*:*:*:*:*
cpe:2.3:a:joomla:joomla:1.0:*:*:*:*:*:*:*
cpe:2.3:a:joomla:joomla:1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:joomla:joomla:1.0.1:*:*:*:*:*:*:*
cpe:2.3:a:joomla:joomla:1.0.2:*:*:*:*:*:*:*
cpe:2.3:a:joomla:joomla:1.0.3:*:*:*:*:*:*:*
cpe:2.3:a:joomla:joomla:1.0.4:*:*:*:*:*:*:*
cpe:2.3:a:joomla:joomla:1.0.5:*:*:*:*:*:*:*
cpe:2.3:a:joomla:joomla:1.0.6:*:*:*:*:*:*:*
cpe:2.3:a:joomla:joomla:1.0.7:*:*:*:*:*:*:*
cpe:2.3:a:joomla:joomla:1.0.8:*:*:*:*:*:*:*
cpe:2.3:a:joomla:joomla:1.0.9:*:*:*:*:*:*:*
cpe:2.3:a:joomla:joomla:1.0.10:*:*:*:*:*:*:*
cpe:2.3:a:joomla:joomla:1.0.11:*:*:*:*:*:*:*
cpe:2.3:a:joomla:joomla:1.0.12:*:*:*:*:*:*:*
cpe:2.3:a:joomla:joomla:1.0.13:*:*:*:*:*:*:*
cpe:2.3:a:joomla:joomla:1.0.14:*:*:*:*:*:*:*
cpe:2.3:a:joomla:joomla:1.03:*:*:*:*:*:*:*
cpe:2.3:a:joomla:joomla:1.5:*:*:*:*:*:*:*
cpe:2.3:a:joomla:joomla:1.5.0:beta:*:*:*:*:*:*
cpe:2.3:a:joomla:joomla:1.5.0:beta1:*:*:*:*:*:*
cpe:2.3:a:joomla:joomla:1.5.0:beta2:*:*:*:*:*:*
cpe:2.3:a:joomla:joomla:1.5.0:rc1:*:*:*:*:*:*
cpe:2.3:a:joomla:joomla:1.5.1:*:*:*:*:*:*:*
cpe:2.3:a:joomla:joomla:1.5.2:*:*:*:*:*:*:*
cpe:2.3:a:joomla:joomla:1.5.3:*:*:*:*:*:*:*
cpe:2.3:a:joomla:joomla:1.5.4:*:*:*:*:*:*:*
cpe:2.3:a:joomla:joomla:1.5.5:*:*:*:*:*:*:*
cpe:2.3:a:joomla:joomla:1.5.6:*:*:*:*:*:*:*

History

21 Nov 2024, 00:59

Type Values Removed Values Added
References () http://secunia.com/advisories/33377 - Vendor Advisory () http://secunia.com/advisories/33377 - Vendor Advisory
References () http://securityreason.com/securityalert/4896 - () http://securityreason.com/securityalert/4896 -
References () http://www.securityfocus.com/bid/33143 - Exploit () http://www.securityfocus.com/bid/33143 - Exploit
References () https://www.exploit-db.com/exploits/7691 - () https://www.exploit-db.com/exploits/7691 -

Information

Published : 2009-01-09 18:30

Updated : 2024-11-21 00:59


NVD link : CVE-2009-0113

Mitre link : CVE-2009-0113

CVE.ORG link : CVE-2009-0113


JSON object : View

Products Affected

joomla

  • joomla
  • xstandard
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')