Unrated severityNVD Advisory· Published Nov 26, 2012· Updated Apr 29, 2026
CVE-2010-5280
CVE-2010-5280
Description
Directory traversal vulnerability in the Community Builder Enhanced (CBE) (com_cbe) component 1.4.8, 1.4.9, and 1.4.10 for Joomla! allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the tabname parameter in a userProfile action to index.php. NOTE: this can be leveraged to execute arbitrary code by using the file upload feature.
Affected products
3cpe:2.3:a:joomla-cbe:com_cbe:1.4.10:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:joomla-cbe:com_cbe:1.4.10:*:*:*:*:*:*:*
- cpe:2.3:a:joomla-cbe:com_cbe:1.4.8:*:*:*:*:*:*:*
- cpe:2.3:a:joomla-cbe:com_cbe:1.4.9:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
7- www.exploit-db.com/exploits/15222nvdExploit
- www.securityfocus.com/bid/43873nvdExploit
- secunia.com/advisories/41741nvdVendor Advisory
- packetstormsecurity.org/1010-exploits/joomlacbe-lfi.txtnvd
- www.securityfocus.com/archive/1/514183/100/0/threadednvd
- exchange.xforce.ibmcloud.com/vulnerabilities/62375nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/62376nvd
News mentions
0No linked articles in our index yet.