Medium severity5.8NVD Advisory· Published Feb 2, 2010· Updated Apr 29, 2026
CVE-2010-0467
CVE-2010-0467
Description
Directory traversal vulnerability in the ccNewsletter (com_ccnewsletter) component 1.0.5 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter in a ccnewsletter action to index.php.
Affected products
1- cpe:2.3:a:chillcreations:com_ccnewsletter:1.0.5:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
6- www.securityfocus.com/bid/37987nvdBroken LinkExploitThird Party AdvisoryVDB Entry
- secunia.com/advisories/38378nvdBroken LinkThird Party Advisory
- www.chillcreations.com/en/blog/ccnewsletter-joomla-newsletter/ccnewsletter-106-security-release.htmlnvdBroken LinkVendor Advisory
- www.exploit-db.com/exploits/11277nvdThird Party AdvisoryVDB Entry
- www.exploit-db.com/exploits/11282nvdThird Party AdvisoryVDB Entry
- exchange.xforce.ibmcloud.com/vulnerabilities/55953nvdThird Party AdvisoryVDB Entry
News mentions
0No linked articles in our index yet.