VRDA Feed by JPCERT/CC
  Vulnerability Response Decision Assistance Feed : Information for vulnerability impact analysis
[ about VRDA Feed | JPCERT/CC



 
Vulnerability Analysis Result (Revision No : 1) [ Download XML
CVE-2010-4270
com_netinvoice: Directory traversal vulnerability in the nBill (com...
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2010-4270

Original

Directory traversal vulnerability in the nBill (com_netinvoice) component before 2.0.9 standard edition, 2.0.10 lite edition, and 1.2_10 for Joomla! allows remote attackers to read arbitrary files via directory traversal sequences in unspecified vectors related to (1) administrator/components/com_nbill/admin.nbill.php, (2) components/com_nbill/nbill.php, (3) administrator/components/com_netinvoice/admin.netinvoice.php, or (4) components/com_netinvoice/netinvoice.php, as exploited in the wild ...

Translation   (Show)





About This Analysis Information
Analysis Information Provider:
NIST NVD
First Published:
2010-11-17
Source Information Category:
Advisory, Alert
Last Updated:
2010-11-17




Affected Product Tags
cpe:/a:joomla:joomla%21
cpe:/a:netshinesoftware:com_netinvoice:1.2_10 and previous versions
cpe:/a:netshinesoftware:com_netinvoice:2.0.10::lite and previous versions
cpe:/a:netshinesoftware:com_netinvoice:2.0.9::std and previous versions
 


Vulnerability Analysis Results
[Access Vector]  [?]
Undefined [?]

Local [?]
Adjacent Network [?]
X Network [?]

[Access Complexit]  [?]
Undefined [?]

High [?]
Medium [?]
X Low [?]

[Authentication]  [?]
Undefined [?]

Multiple [?]
Single [?]
X None [?]

[Confidentiality Impact]  [?]
Undefined [?]

None [?]
X Partial [?]
Complete [?]

[Integrity Impact]  [?]
Undefined [?]

X None [?]
Partial [?]
Complete [?]

[Availability Impact]  [?]
Undefined [?]

X None [?]
Partial [?]
Complete [?]

Alternatives




References
BID 44719




CONFIRM http://www.nbill.co.uk/newsflash/security-patch-for-all-versions-of-nbill.html




CONFIRM http://www.nbill.co.uk/forum-smf/index.php/topic,2158.0.html




OSVDB 69066




SECUNIA 42186




Vulnerability Type Path Traversal (CWE-22)





Copyright © 2010 JPCERT/CC All Rights Reserved.