CVE-2010-4270 Information

Description

Directory traversal vulnerability in the nBill (com_netinvoice) component before 2.0.9 standard edition 2.0.10 lite edition and 1.2_10 for Joomla! allows remote attackers to read arbitrary files via directory traversal sequences in unspecified vectors related to (1) administrator/components/com_nbill/admin.nbill.php (2) components/com_nbill/nbill.php (3) administrator/components/com_netinvoice/admin.netinvoice.php or (4) components/com_netinvoice/netinvoice.php as exploited in the wild in November 2010.

Reference

http://osvdb.org/69066 http://secunia.com/advisories/42186 http://www.nbill.co.uk/forum-smf/index.php/topic2158.0.html http://www.nbill.co.uk/newsflash/security-patch-for-all-versions-of-nbill.html http://www.securityfocus.com/bid/44719

Share on: