CVE-2013-5576
Summary
| CVE | CVE-2013-5576 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2013-10-09 14:54:26 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | administrator/components/com_media/helpers/media.php in the media manager in Joomla! 2.5.x before 2.5.14 and 3.x before 3.1.5 allows remote authenticated users or remote attackers to bypass intended access restrictions and upload files with dangerous extensions via a filename with a trailing . (dot), as exploited in the wild in August 2013. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:M/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Joomla | Joomla! | 2.5.0 | All | All | All |
| Application | Joomla | Joomla! | 2.5.1 | All | All | All |
| Application | Joomla | Joomla! | 2.5.10 | All | All | All |
| Application | Joomla | Joomla! | 2.5.11 | All | All | All |
| Application | Joomla | Joomla! | 2.5.12 | All | All | All |
| Application | Joomla | Joomla! | 2.5.13 | All | All | All |
| Application | Joomla | Joomla! | 2.5.2 | All | All | All |
| Application | Joomla | Joomla! | 2.5.3 | All | All | All |
| Application | Joomla | Joomla! | 2.5.4 | All | All | All |
| Application | Joomla | Joomla! | 2.5.5 | All | All | All |
| Application | Joomla | Joomla! | 2.5.6 | All | All | All |
| Application | Joomla | Joomla! | 2.5.7 | All | All | All |
| Application | Joomla | Joomla! | 2.5.8 | All | All | All |
| Application | Joomla | Joomla! | 2.5.9 | All | All | All |
| Application | Joomla | Joomla! | 3.0.0 | All | All | All |
| Application | Joomla | Joomla! | 3.0.1 | All | All | All |
| Application | Joomla | Joomla! | 3.0.2 | All | All | All |
| Application | Joomla | Joomla! | 3.0.3 | All | All | All |
| Application | Joomla | Joomla! | 3.0.4 | All | All | All |
| Application | Joomla | Joomla! | 3.1.0 | All | All | All |
| Application | Joomla | Joomla! | 3.1.1 | All | All | All |
| Application | Joomla | Joomla! | 3.1.2 | All | All | All |
| Application | Joomla | Joomla! | 3.1.3 | All | All | All |
| Application | Joomla | Joomla! | 3.1.4 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| [20130801] - Core - Unauthorised Uploads | af854a3a-2127-422b-91ae-364da2661108 | developer.joomla.org | |
| oss-sec: CVE request: Joomla unauthorised uploads before 2.5.14 / 3.1.5 | af854a3a-2127-422b-91ae-364da2661108 | seclists.org | |
| Joomla patches file manager vulnerability responsible for hijacked websites - patches, CMS security, applications, security, Fort Disco, joomla, botnet, software, data protection, Versafe - CSO | The Resource for Data Security Executives | af854a3a-2127-422b-91ae-364da2661108 | www.cso.com.au | |
| Vulnerability Note VU#639620 - Joomla! Media Manager allows arbitrary file upload and execution | af854a3a-2127-422b-91ae-364da2661108 | www.kb.cert.org | US Government Resource |
| oss-sec: Re: CVE request: Joomla unauthorised uploads before 2.5.14 / 3.1.5 | af854a3a-2127-422b-91ae-364da2661108 | seclists.org | |
| Joomla Media Manager File Upload Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.exploit-db.com | Exploit |
| Prepare 2.5.14 release · joomla/joomla-cms@fa56452 · GitHub | af854a3a-2127-422b-91ae-364da2661108 | github.com | Exploit, Patch |
| JoomlaCode > Projects > Joomla! > Tracker > NO LONGER SUPPORTED: Joomla! 1.5.x Bug Tracker > Edit Tracker Item | af854a3a-2127-422b-91ae-364da2661108 | joomlacode.org | |
| Prepare 3.1.5 release · joomla/joomla-cms@1ed07e2 · GitHub | af854a3a-2127-422b-91ae-364da2661108 | github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.