S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Dec 16, 2023

CVE-2010-1535 Scanner

Detects 'Directory Traversal' vulnerability in TRAVELbook component of Joomla affects v. 1.0.1.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.8k
Times Used
continuous scan runs
5.9k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
7.5
CVSS
Description

Directory traversal vulnerability in the TRAVELbook (com_travelbook) component 1.0.1 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the controller parameter to index.php.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Sep 18, 2026View on NVD →
Detail

TRAVELbook is a component of Joomla! software that is primarily used for planning and organizing travel itineraries. This component provides a platform for users to create personalized travel plans, by integrating various travel vendors and services. This functionality makes it a popular tool amongst travel enthusiasts who are looking to create custom and detailed travel arrangements. 

The TRAVELbook component, unfortunately, has a vulnerability that was detected and designated as CVE-2010-1535. This vulnerability arises when remote attackers use the ".." symbol to traverse directories. This vulnerability then permits the attacker to read any arbitrary file and potentially impact several aspects of the system. 

When this vulnerability is exploited, it can cause multiple issues, including an attacker compromising sensitive information, manipulating content, or initiating different infections on the system. In some cases, it can even allow remote attackers to take full control of a website. This can have a grave impact on the organization’s reputation, and may cause significant financial losses in the long-term. 

Having a tool to quickly and efficiently identify vulnerabilities in digital assets is critical to ensuring that your website stays secure. This is why we highly recommend the use of s4e.io’s pro features. With this platform, you can easily and quickly identify vulnerabilities in your asset, and get real-time updates on any security threats. This tool is exceptionally user-friendly and cost-effective; making it an invaluable addition to any security program.

 

REFERENCES

Solution Advice

To protect against this vulnerability, it is best to follow a few precautions. The following are precautions that can be taken to avoid the CVE-2010-1535 vulnerability: 

  • Regularly update the Joomla! software to the latest version, which includes security fixes.
  • Filter input out of directories traversal characters such as ".." symbols
  • Review access permissions of directories to ensure that directories do not permit unauthorized access.
  • Monitor site/file changes and logs to identify and report any suspicious activity. 
  • Implement a Web Application Firewall (WAF) to prevent any malicious activity that could have negative consequences. 

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.