« Volver al listado

CVE-2010-4270

Estado: ModificadaMedia (5)—

Directory traversal vulnerability in the nBill (com_netinvoice) component before 2.0.9 standard edition, 2.0.10 lite edition, and 1.2_10 for Joomla! allows remote attackers to read arbitrary files via directory traversal sequences in unspecified vectors related to (1) administrator/components/com_nbill/admin.nbill.php, (2) components/com_nbill/nbill.php, (3) administrator/components/com_netinvoice/admin.netinvoice.php, or (4) components/com_netinvoice/netinvoice.php, as exploited in the wild in November 2010.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2010-4270",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2010-11-17T01:00:05.403",
  "references": [
    {
      "url": "http://osvdb.org/69066",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://secunia.com/advisories/42186",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.nbill.co.uk/forum-smf/index.php/topic%2C2158.0.html",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.nbill.co.uk/newsflash/security-patch-for-all-versions-of-nbill.html",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/44719",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://osvdb.org/69066",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/42186",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.nbill.co.uk/forum-smf/index.php/topic%2C2158.0.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.nbill.co.uk/newsflash/security-patch-for-all-versions-of-nbill.html",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/44719",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-22"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Directory traversal vulnerability in the nBill (com_netinvoice) component before 2.0.9 standard edition, 2.0.10 lite edition, and 1.2_10 for Joomla! allows remote attackers to read arbitrary files via directory traversal sequences in unspecified vectors related to (1) administrator/components/com_nbill/admin.nbill.php, (2) components/com_nbill/nbill.php, (3) administrator/components/com_netinvoice/admin.netinvoice.php, or (4) components/com_netinvoice/netinvoice.php, as exploited in the wild in November 2010."
    },
    {
      "lang": "es",
      "value": "Vulnerabilidad de salto de directorio en el componente nBill (com_netinvoice) anterior a v2.0.9 standard edition, v2.0.10 lite edition, y v1.2_10 para Joomla! permite a atacantes remotos leer archivos arbitrarios a través de secuencias de salto de directorio mediante vectores no especificados relacionados con (1) administrator/components/com_nbill/admin.nbill.php, (2) components/com_nbill/nbill.php, (3) administrator/components/com_netinvoice/admin.netinvoice.php, o (4) components/com_netinvoice/netinvoice.php, tal y como se pudo comprobar en Noviembre de 2010."
    }
  ],
  "lastModified": "2026-06-16T23:24:28.900",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:netshinesoftware:com_netinvoice:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F4B45661-A646-4F2A-A5E0-564C89F017FA",
              "versionEndIncluding": "1.2_10"
            },
            {
              "criteria": "cpe:2.3:a:netshinesoftware:com_netinvoice:*:*:std:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "486CE9D7-6B30-4623-A59A-EF010707B7FC",
              "versionEndIncluding": "2.0.9"
            },
            {
              "criteria": "cpe:2.3:a:netshinesoftware:com_netinvoice:*:*:lite:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0F60EA83-CA38-4D04-89DF-9611A50D70D8",
              "versionEndIncluding": "2.0.10"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:joomla:joomla\\!:*:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "2AC7400C-F6AF-4B5E-A34B-0222F94DCC46"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "evaluatorImpact": "Per: http://www.nbill.co.uk/newsflash/security-patch-for-all-versions-of-nbill.html\r\n\r\n'A security vulnerability has been discovered affecting ALL VERSIONS of nBill that were downloaded on or prior to 5th November 2010.'",
  "sourceIdentifier": "cve@mitre.org"
}