A directory traversal vulnerability in the Music Manager component for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impacts via a .. (dot dot) in the cid parameter to album.html.
id: CVE-2010-2857
info:
name: Joomla! Component Music Manager - Local File Inclusion
author: da
...