CVE-2008-6172
43Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendepss 12%
exploitation probability
12%top 4% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
Directory traversal vulnerability in captcha/captcha_image.php in the RWCards (com_rwcards) 3.0.11 component for Joomla!, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the img parameter.
Affected products
n/a · n/apublic PoCs found — 1✓ VexDay Proof
cve_reference✓ VexDay Proofwww.exploit-db.com/exploits/6817⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.