CVE-2011-5134

Unrestricted file upload vulnerability in editor/extensions/browser/file.php in the JCE component before 2.0.18 for Joomla! allows remote authenticated users with the author privileges to execute arbitrary PHP code by uploading a file with a double extension, as demonstrated by .php.gif. NOTE: some of these details are obtained from third party information.
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:a:widgetfactorylimited:com_jce:*:*:*:*:*:*:*:*
cpe:2.3:a:widgetfactorylimited:com_jce:2.0.0:*:*:*:*:*:*:*
cpe:2.3:a:widgetfactorylimited:com_jce:2.0.1:*:*:*:*:*:*:*
cpe:2.3:a:widgetfactorylimited:com_jce:2.0.2:*:*:*:*:*:*:*
cpe:2.3:a:widgetfactorylimited:com_jce:2.0.3:*:*:*:*:*:*:*
cpe:2.3:a:widgetfactorylimited:com_jce:2.0.4:*:*:*:*:*:*:*
cpe:2.3:a:widgetfactorylimited:com_jce:2.0.5:*:*:*:*:*:*:*
cpe:2.3:a:widgetfactorylimited:com_jce:2.0.6:*:*:*:*:*:*:*
cpe:2.3:a:widgetfactorylimited:com_jce:2.0.7:*:*:*:*:*:*:*
cpe:2.3:a:widgetfactorylimited:com_jce:2.0.8:*:*:*:*:*:*:*
cpe:2.3:a:widgetfactorylimited:com_jce:2.0.9:*:*:*:*:*:*:*
cpe:2.3:a:widgetfactorylimited:com_jce:2.0.10:*:*:*:*:*:*:*
cpe:2.3:a:widgetfactorylimited:com_jce:2.0.11:*:*:*:*:*:*:*
cpe:2.3:a:widgetfactorylimited:com_jce:2.0.12:*:*:*:*:*:*:*
cpe:2.3:a:widgetfactorylimited:com_jce:2.0.13:*:*:*:*:*:*:*
cpe:2.3:a:widgetfactorylimited:com_jce:2.0.14:*:*:*:*:*:*:*
cpe:2.3:a:widgetfactorylimited:com_jce:2.0.15:*:*:*:*:*:*:*
cpe:2.3:a:widgetfactorylimited:com_jce:2.0.16:*:*:*:*:*:*:*
cpe:2.3:a:joomla:joomla\!:*:*:*:*:*:*:*:*

History

21 Nov 2024, 01:33

Type Values Removed Values Added
References () http://secunia.com/advisories/47190 - Vendor Advisory () http://secunia.com/advisories/47190 - Vendor Advisory
References () http://www.joomlacontenteditor.net/news/item/jce-2018-released?category_id=32 - () http://www.joomlacontenteditor.net/news/item/jce-2018-released?category_id=32 -
References () http://www.osvdb.org/77579 - () http://www.osvdb.org/77579 -

Information

Published : 2012-08-30 22:55

Updated : 2024-11-21 01:33


NVD link : CVE-2011-5134

Mitre link : CVE-2011-5134

CVE.ORG link : CVE-2011-5134


JSON object : View

Products Affected

widgetfactorylimited

  • com_jce

joomla

  • joomla\!