S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Dec 16, 2023

CVE-2010-1474 Scanner

Detects 'Directory Traversal' vulnerability in Sweety Keeper component of Joomla affects v. 1.5.x.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
3.2k
Times Used
continuous scan runs
3.4k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2010-1474
6.8
CVSS

Directory traversal vulnerability in the Sweety Keeper (com_sweetykeeper) component 1.5.x for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the controller parameter to index.php.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

The Sweety Keeper component is a software extension for Joomla content management system designed to manage user data, including login credentials and account details. It is a popular tool that allows website administrators to create secure and personalized areas for their users. The Sweety Keeper component is primarily used by websites that require user registration and provide restricted content areas. It helps administrators create a more user-friendly and efficient system for managing user data.

CVE-2010-1474 is a directory traversal vulnerability in the Sweety Keeper component 1.5.x for Joomla. This vulnerability allows remote attackers to read arbitrary files and potentially execute other malicious actions via a ".." (dot dot) in the controller parameter to index.php. The flaw could potentially allow an attacker to gain unauthorized access to sensitive information or perform actions that could harm the website or its users.

Exploiting the CVE-2010-1474 vulnerability on Sweety Keeper component in Joomla can lead to severe consequences. Attackers can gain access to sensitive information such as user passwords, confidential business data, and financial information. They could also manipulate the application to execute arbitrary code on the system, leading to system crashes, data corruption, or complete system compromise. Such actions can have serious implications on both the website and the organization that owns the website.

In conclusion, the Sweety Keeper component is a valuable extension for Joomla websites that require user management. However, this component can be vulnerable to exploits such as CVE-2010-1474, which can have serious ramifications for the website and organization. As such, it is crucial to ensure that suitable precautions are taken to mitigate these vulnerabilities. With the s4e.io platform, website administrators can stay ahead of vulnerabilities and protect their digital assets effectively. By using this platform, readers of this article can gain access to a comprehensive suite of security features that can help them secure their websites proactively.

 

REFERENCES

Solution Advice

There are several precautions that can be taken to protect against this vulnerability. These include:

  • Keeping the Joomla and the Sweety Keeper component updated with the latest security patches and fixes
  • Regularly scanning the website for vulnerabilities using security tools and applications
  • Implementing access controls such as user authentication, login credentials, and authorization policies
  • Restricting the use of certain file types that may be prone to exploitation
  • Enabling PHP's 'open_basedir' directive in the website's configuration settings to restrict access to directories outside the website's root directory.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2010-1474 scanner - Directory Traversal vulnerability in Sweety Keeper component of Joomla | S4E