peter bassill · operator
$ cve CVE-2010-2680 JSON

CVE-2010-2680 EXPLOIT

6.8
MEDIUM · CVSS 2.0 · EPSS 4.8% (pctl 92)

Patch early

A public exploit exists.

Description

Directory traversal vulnerability in the JExtensions JE Section/Property Finder (jesectionfinder) component for Joomla! allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the view parameter to index.php.

Scoring

CVSS6.8 (MEDIUM, v2.0)
VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
EPSS4.85% — more likely to be exploited than 92% of all CVEs
WeaknessCWE-22
On CISA KEVno
Public exploityes
Published2010-07-12
Last modified2026-06-16

Affected (2)

VendorProduct
harmistechnologycom jesectionfinder
joomlajoomla\!

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD