Joomla BF Survey Component "controller" Local File Inclusion Vulnerability

SECUNIA ADVISORY ID:
SA37866

VERIFY ADVISORY:
http://secunia.com/advisories/37866/

DESCRIPTION:
A vulnerability has been reported in the BF Survey component for
Joomla, which can be exploited by malicious people to disclose
sensitive information.

Input passed to the "controller" parameter in index.php (if "option"
is set to "com_bfsurvey") is not properly verified before being used
to include files. This can be exploited to include arbitrary files
from local resources via directory traversal attacks.

SOLUTION:
Upgrade to BF Survey Basic version 1.1 or later.

PROVIDED AND/OR DISCOVERED BY:
FL0RiX