Description
An issue was discovered in Joomla! 2.5.0 through 3.9.22. The folder parameter of mod_random_image lacked input validation, leading to a path traversal vulnerability.
Remediation
References
Related Vulnerabilities
WordPress Plugin bbPress Members Only Cross-Site Request Forgery (1.2.1)
WordPress Plugin Pay Per Media Player Multiple Cross-Site Scripting Vulnerabilities (1.24)
Apache HTTP Server CVE-2013-1862 Vulnerability (CVE-2013-1862)
WordPress Plugin Restaurant Reservations Privilege Escalation (1.3)
Joomla! Core 1.0.x Multiple Unspecified Vulnerabilities (1.0.0 - 1.0.5)