Arbitrary File Download exists in the Jtag Members Directory 5.3.7 component for Joomla! via the download_file parameter.
References
Link | Resource |
---|---|
https://packetstormsecurity.com/files/146137/Joomla-Jtag-Members-Directory-5.3.7-Arbitrary-File-Download.html | Exploit Third Party Advisory VDB Entry |
https://www.exploit-db.com/exploits/43913/ | Exploit Third Party Advisory VDB Entry |
Configurations
Information
Published : 2018-01-28 21:29
Updated : 2018-02-15 09:42
NVD link : CVE-2018-6008
Mitre link : CVE-2018-6008
JSON object : View
CWE
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor
Products Affected
joomlatag
- jtag_members_directory