CVE-2010-1217

Vulnérabilités

CVE-2010-1217

Directory traversal vulnerability in the JE Form Creator (com_jeformcr) component for Joomla!, when magic_quotes_gpc is disabled, allows remote attackers to re…

MEDIUM com_jeformcr Composant

Directory traversal vulnerability in the JE Form Creator (com_jeformcr) component for Joomla!, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via directory traversal sequences in the view parameter to index.php. NOTE: the original researcher states that the affected product is JE Tooltip, not Form Creator; however, the exploit URL suggests that Form Creator is affected.

4.3 Moyenne · CVSS 2.0

AV:N/AC:M/Au:N/C:P/I:N/A:N

Score retenu : NVD

SourceSévérité d'origineCVSS
NVDMEDIUM 4.3 (v2.0)
Produit
com_jeformcr
Type
Composant
Corrigée dans
Non précisée
Publiée
30/03/2010
Modifiée
16/06/2026
CWE
CWE-22

Versions non précisées par les sources.

Ces informations proviennent des sources ci-dessus ; CVE Oyer n'y ajoute aucune interprétation.

  1. Détectée via nvd26/09/2026 09:27 UTC