Joomla! Component RSfiles 1.0.2 - 'path' File Download Vulnerability CVE-2007-4504 Scanner Detail
There is an arbitrary file download vulnerability in Joomla! Component RSfiles 1.0.2.
Directory traversal vulnerability in index.php in the RSfiles component (com_rsfiles) 1.0.2 and earlier for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the path parameter in a files.display action.
Some Advice for Common Problems
- You need to apply related fixes.
- Sanitize all parameters received as input from the user.