S4E just found a high-severity finding from top 38 parameters xss vulnerability scanner
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2010-2918 Scanner

CVE-2010-2918 scanner - Remote File Inclusion (RFI) vulnerability in Visites component for Joomla!

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
3.4k
Times Used
continuous scan runs
3.4k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2010-2918
7.5
CVSS

PHP remote file inclusion vulnerability in core/include/myMailer.class.php in the Visites (com_joomla-visites) component 1.1 RC2 for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

The Visites (com_joomla-visites) component for Joomla! is a popular plugin used to provide website admins with visitor tracking statistics. It enables admins to monitor website traffic, analyze user behavior on the site, and track important metrics, such as visitor count and page views. With powerful reporting capabilities, the Visites plugin is an essential tool for optimizing website performance and driving conversions.

However, a vulnerability coded as CVE-2010-2918 has been detected in the Visites plugin, which can result in a PHP remote file inclusion attack. This attack enables remote attackers to execute arbitrary PHP code through the mosConfig_absolute_path parameter, which can lead to serious consequences for your website's security and performance.

Exploiting the vulnerability can give attackers access to website content and data, which can result in data theft, website defacement, or even complete shutdown. This can lead to loss of customer trust, negative brand reputation, and revenue loss. The realization of such devastating consequences highlights the critical need for proactive security measures to protect digital assets against cyber threats.

Thanks to the pro features of the s4e.io platform, you can easily and quickly learn about vulnerabilities in your digital assets. The platform offers comprehensive security features, such as malware scanners, vulnerability assessments, and penetration testing, to identify and mitigate security risks proactively. With s4e.io, you can ensure that your website, applications, and digital assets are safe and secure from any form of cyber attack.

 

REFERENCES

Solution Advice

To prevent this vulnerability and secure your website from possible attacks, it is essential to take specific precautions. These measures include:

  • Keeping the Visites plugin updated with the latest security patches
  • Ensuring proper file and folder permissions
  • Implementing server-side Web Application Firewalls (WAFs)
  • Configuring web servers to limit access to files and directories
  • Regularly scanning your website for vulnerabilities.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.