CVE-2011-5148
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
31/08/2012
Last modified:
11/04/2025
Description
Multiple incomplete blacklist vulnerabilities in the Simple File Upload (mod_simplefileuploadv1.3) module before 1.3.5 for Joomla! allow remote attackers to execute arbitrary code by uploading a file with a (1) php5, (2) php6, or (3) double (e.g. .php.jpg) extension, then accessing it via a direct request to the file in images/, as exploited in the wild in January 2012.
Impact
Base Score 2.0
6.80
Severity 2.0
MEDIUM
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:wasen:mod_simplefileupload:*:*:*:*:*:*:*:* | 1.3 (including) | |
cpe:2.3:a:wasen:mod_simplefileupload:1.0:*:*:*:*:*:*:* | ||
cpe:2.3:a:wasen:mod_simplefileupload:1.1:*:*:*:*:*:*:* | ||
cpe:2.3:a:joomla:joomla\!:*:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://docs.joomla.org/Vulnerable_Extensions_List#Simple_File_Upload_1.3
- http://secunia.com/advisories/47370
- http://wasen.net/index.php?option=com_content&view=article&id=87&Itemid=59
- http://www.exploit-db.com/exploits/18287
- http://www.osvdb.org/78122
- http://www.securityfocus.com/bid/51214
- http://www.securityfocus.com/bid/51234
- https://exchange.xforce.ibmcloud.com/vulnerabilities/72023
- http://docs.joomla.org/Vulnerable_Extensions_List#Simple_File_Upload_1.3
- http://secunia.com/advisories/47370
- http://wasen.net/index.php?option=com_content&view=article&id=87&Itemid=59
- http://www.exploit-db.com/exploits/18287
- http://www.osvdb.org/78122
- http://www.securityfocus.com/bid/51214
- http://www.securityfocus.com/bid/51234
- https://exchange.xforce.ibmcloud.com/vulnerabilities/72023