CVE-2018-7482

CVE-2018-7482

The K2 component 2.8.0 for Joomla! has Incorrect Access Control with directory traversal, allowing an attacker to download arbitrary files, as demonstrated by a view=media&task=connector&cmd=file&target=l1_../configuration.php&download=1 request. The specific pathname ../configuration.php should be base64 encoded for a valid attack.

Source: CVE-2018-7482

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다