|
nBill Component for Joomla! contains a flaw that allows a remote attacker to traverse outside of a restricted path. The issue is due to the administrator/components/com_nbill/admin.nbill.php, components/com_nbill/nbill.php, administrator/components/com_netinvoice/admin.netinvoice.php and components/com_netinvoice/netinvoice.php scripts not properly sanitizing user input, specifically directory traversal style attacks (e.g., ../../) supplied via an unspecified parameter. This directory traversal attack would allow the attacker to read arbitrary files.
|