PT-2012-2112 · Joomla · Jce
Publicado
2012-08-30
·
Atualizado
2012-09-13
·
CVE-2011-5134
CVSS v2.0
6.0
Média
| Vetor | AV:N/AC:M/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
JCE component versions prior to 2.0.18 for Joomla!
Description
The issue allows remote authenticated users with author privileges to execute arbitrary PHP code by uploading a file with a double extension. This can be achieved by uploading a file such as
.php.gif.Recommendations
For JCE component versions prior to 2.0.18, update to version 2.0.18 or later to resolve the issue. As a temporary workaround, consider restricting file uploads or disabling the
file.php extension in the JCE component to minimize the risk of exploitation.Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Jce