Joomla nBill Component Directory Traversal Vulnerability

SECUNIA ADVISORY ID:
SA42186

VERIFY ADVISORY:
Secunia.com
http://secunia.com/advisories/42186/
Customer Area (Credentials Required)
https://ca.secunia.com/?page=viewadvisory&vuln_id=42186

RELEASE DATE:
2010-11-08
DESCRIPTION:
A vulnerability has been reported in the nBill component for Joomla!,
which can be exploited by malicious people to disclose sensitive
information.

Certain unspecified input in not properly sanitised before being
used, which can be exploited to disclose sensitive information via
directory traversal attacks.

The vulnerabilities are reported in 2.0.9 standard edition, 2.0.10
lite edition, and 1.2_10. Other versions may also be affected.

SOLUTION:
Update to 2.0.9 standard edition, 2.0.10 lite edition, or 1.2_10 and
apply the patch.

PROVIDED AND/OR DISCOVERED BY:
Discovered in the wild.

ORIGINAL ADVISORY:
http://www.nbill.co.uk/newsflash/security-patch-for-all-versions-of-nbill.html

RECENT ARTICLE

RECENT POST