S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Dec 16, 2023

CVE-2010-1954 Scanner

CVE-2010-1954 scanner - Directory Traversal vulnerability in iNetLanka Multiple root component for Joomla!

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.6k
Times Used
continuous scan runs
3.4k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2010-1954
7.5
CVSS

Directory traversal vulnerability in the iNetLanka Multiple root (com_multiroot) component 1.0 and 1.1 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php. NOTE: some of these details are obtained from third party information.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

The iNetLanka Multiple root component for Joomla! is designed to provide users with the ability to maintain multiple website roots within a single Joomla! installation. This component allows users to easily and efficiently manage multiple websites without the need to install separate Joomla! instances for each. This product is used by website developers and administrators to reduce overheads and streamline website management tasks.

The CVE-2010-1954 vulnerability in the iNetLanka Multiple root component for Joomla! allows remote attackers to read arbitrary files by exploiting a directory traversal vulnerability in the com_multiroot component. This vulnerability can be exploited by attackers by inserting a ".." in the controller parameter to index.php. Upon exploitation, attackers can gain access to files that they should not normally have access to, such as sensitive data or configuration files. 

When exploited, the CVE-2010-1954 vulnerability can lead to significant data breaches and privacy violations. Attackers can gain access to sensitive data and personally identifiable information from databases, configuration files, or other sensitive files. This vulnerability can also allow attackers to compromise web application servers, potentially leading to the installation of malware or other malicious software that can further compromise the security of digital assets.

Thanks to the pro features of s4e.io, website owners and administrators can easily and quickly learn about vulnerabilities in their digital assets. With features such as automated scanning and real-time monitoring, s4e.io provides users with unparalleled insight into their website's security posture. Plus, with expert support and guidance available around the clock, users can take proactive steps to prevent attacks and secure their digital assets effectively. So, act now and sign up for s4e.io today to take your website security to the next level!

 

REFERENCES

Solution Advice

To protect against the CVE-2010-1954 vulnerability, website owners and administrators must:

  • Update the iNetLanka Multiple root component to version 1.2 or later
  • Install security patches or hotfixes related to this vulnerability
  • Restrict directory access on web servers to prevent undue access to sensitive files
  • Implement strong access controls on web servers, including authentication and authorization protocols
  • Monitor and analyze web server activity for suspicious behavior, such as unusual file access patterns or access from unknown IP addresses

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2010-1954 scanner - Directory Traversal vulnerability in iNetLanka Multiple root component for Joomla! | S4E