CVE-2011-4804: Foobla Com Obsuggest

Medium severity, CVSS 5.0. EPSS: 21% chance of exploitation in the next 30 days.

Directory traversal vulnerability in the obSuggest (com_obsuggest) component before 1.8 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.

Affected products

  • Foobla Com Obsuggest: up to and including 1.6.4; version 1.5.0.1 only; version 1.5.1.1.20090922 only; version 1.5.1.2 only; version 1.5.1.4 only; version 1.5.1.5 only; …

Published 2011-12-14. Last modified 2026-06-16.