Gadget Factory Component for Joomla! contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered by insufficient validation of the 'controller' parameter by index.php, which will disclose the contents of arbitrary files to a remote attacker.
Classification
Location:
Remote / Network Access
Attack Type:
Information Disclosure,
Input Manipulation
Impact:
Loss of Confidentiality
Solution:
Solution Unknown
Exploit:
Exploit Public
Disclosure:
Vendor Verified,
Uncoordinated Disclosure
OSVDB:
Web Related
Solution
OSVDB is not aware of a solution for this vulnerability.