Joomla! <=2.0.0 RC2 - Local File Inclusion
Joomla! 2.0.0 RC2 and earlier are susceptible to local file inclusion in the eXtplorer module (com_extplorer) that allows remote attackers to read arbitrary files via a .. (dot dot) in the dir parameter in a show_error action.
PoC 已收录com_extplorer
CVSS5.0EPSS 16.5%