Vulnerabilities > CVE-2011-5148 - Remote Code Execution vulnerability in Wasen MOD Simplefileupload 1.0/1.1/1.3

047910
CVSS 6.8 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
wasen
joomla
exploit available

Summary

Multiple incomplete blacklist vulnerabilities in the Simple File Upload (mod_simplefileuploadv1.3) module before 1.3.5 for Joomla! allow remote attackers to execute arbitrary code by uploading a file with a (1) php5, (2) php6, or (3) double (e.g. .php.jpg) extension, then accessing it via a direct request to the file in images/, as exploited in the wild in January 2012. Per: http://cwe.mitre.org/data/definitions/184.html 'CWE-184: Incomplete Blacklist'

Vulnerable Configurations

Part Description Count
Application
Wasen
3
Application
Joomla
1

Exploit-Db

descriptionJoomla Module Simple File Upload 1.3 - Remote Code Execution. CVE-2011-5148. Webapps exploit for php platform
fileexploits/php/webapps/18287.php
idEDB-ID:18287
last seen2016-02-02
modified2011-12-28
platformphp
port
published2011-12-28
reportergmda
sourcehttps://www.exploit-db.com/download/18287/
titleJoomla Module Simple File Upload 1.3 - Remote Code Execution
typewebapps