Joomla! Remote File Upload Vulnerability And Information Disclosure Weakness
BID:35780
Info
Joomla! Remote File Upload Vulnerability And Information Disclosure Weakness
| Bugtraq ID: | 35780 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 22 2009 12:00AM |
| Updated: | Nov 03 2009 05:27PM |
| Credit: | Patrice Lazareff, Juan Galiana Lara |
| Vulnerable: |
Joomla Joomla 1.5.12 Joomla Joomla 1.5.11 Joomla Joomla 1.5.10 Joomla Joomla 1.5.9 Joomla Joomla 1.5.8 Joomla Joomla 1.5.7 Joomla Joomla 1.5.6 Joomla Joomla 1.5.5 Joomla Joomla 1.5.4 Joomla Joomla 1.5.3 Joomla Joomla 1.5.2 Joomla Joomla 1.5.1 |
| Not Vulnerable: |
Joomla Joomla 1.5.13 |
Discussion
Joomla! Remote File Upload Vulnerability And Information Disclosure Weakness
Joomla! is prone to a remote file-upload vulnerability and an information-disclosure weakness.
Attackers can exploit these issues to obtain sensitive information or to upload arbitrary code and execute it in the context of the webserver process. This may facilitate unauthorized access or privilege escalation; other attacks are also possible.
These issues affect Joomla! 1.5.x (prior to 1.5.13).
Joomla! is prone to a remote file-upload vulnerability and an information-disclosure weakness.
Attackers can exploit these issues to obtain sensitive information or to upload arbitrary code and execute it in the context of the webserver process. This may facilitate unauthorized access or privilege escalation; other attacks are also possible.
These issues affect Joomla! 1.5.x (prior to 1.5.13).
Exploit / POC
Joomla! Remote File Upload Vulnerability And Information Disclosure Weakness
Attackers can use a browser to exploit these issues.
The following example URIs are available:
http://www.example.com/joomla-1.5.12/libraries/joomla/utilities/compat/php50x.php
http://www.example.com/joomla-1.5.12/libraries/joomla/client/ldap.php
http://www.example.com/joomla-1.5.12/libraries/joomla/html/html/content.php
The following exploit is available for the file-upload issue:
Attackers can use a browser to exploit these issues.
The following example URIs are available:
http://www.example.com/joomla-1.5.12/libraries/joomla/utilities/compat/php50x.php
http://www.example.com/joomla-1.5.12/libraries/joomla/client/ldap.php
http://www.example.com/joomla-1.5.12/libraries/joomla/html/html/content.php
The following exploit is available for the file-upload issue:
Solution / Fix
Joomla! Remote File Upload Vulnerability And Information Disclosure Weakness
Solution:
The vendor has released updates. Please see the references for details.
Joomla Joomla 1.5.1
Joomla Joomla 1.5.10
Joomla Joomla 1.5.11
Joomla Joomla 1.5.12
Joomla Joomla 1.5.2
Joomla Joomla 1.5.3
Joomla Joomla 1.5.4
Joomla Joomla 1.5.5
Joomla Joomla 1.5.6
Joomla Joomla 1.5.7
Joomla Joomla 1.5.8
Joomla Joomla 1.5.9
Solution:
The vendor has released updates. Please see the references for details.
Joomla Joomla 1.5.1
-
Joomla Joomla_1.5.13-Stable-Full_Package.zip
http://joomlacode.org/gf/download/frsrelease/10697/42195/Joomla_1.5.13 -Stable-Full_Package.zip
Joomla Joomla 1.5.10
-
Joomla Joomla_1.5.13-Stable-Full_Package.zip
http://joomlacode.org/gf/download/frsrelease/10697/42195/Joomla_1.5.13 -Stable-Full_Package.zip
Joomla Joomla 1.5.11
-
Joomla Joomla_1.5.13-Stable-Full_Package.zip
http://joomlacode.org/gf/download/frsrelease/10697/42195/Joomla_1.5.13 -Stable-Full_Package.zip
Joomla Joomla 1.5.12
-
Joomla Joomla_1.5.13-Stable-Full_Package.zip
http://joomlacode.org/gf/download/frsrelease/10697/42195/Joomla_1.5.13 -Stable-Full_Package.zip
Joomla Joomla 1.5.2
-
Joomla Joomla_1.5.13-Stable-Full_Package.zip
http://joomlacode.org/gf/download/frsrelease/10697/42195/Joomla_1.5.13 -Stable-Full_Package.zip
Joomla Joomla 1.5.3
-
Joomla Joomla_1.5.13-Stable-Full_Package.zip
http://joomlacode.org/gf/download/frsrelease/10697/42195/Joomla_1.5.13 -Stable-Full_Package.zip
Joomla Joomla 1.5.4
-
Joomla Joomla_1.5.13-Stable-Full_Package.zip
http://joomlacode.org/gf/download/frsrelease/10697/42195/Joomla_1.5.13 -Stable-Full_Package.zip
Joomla Joomla 1.5.5
-
Joomla Joomla_1.5.13-Stable-Full_Package.zip
http://joomlacode.org/gf/download/frsrelease/10697/42195/Joomla_1.5.13 -Stable-Full_Package.zip
Joomla Joomla 1.5.6
-
Joomla Joomla_1.5.13-Stable-Full_Package.zip
http://joomlacode.org/gf/download/frsrelease/10697/42195/Joomla_1.5.13 -Stable-Full_Package.zip
Joomla Joomla 1.5.7
-
Joomla Joomla_1.5.13-Stable-Full_Package.zip
http://joomlacode.org/gf/download/frsrelease/10697/42195/Joomla_1.5.13 -Stable-Full_Package.zip
Joomla Joomla 1.5.8
-
Joomla Joomla_1.5.13-Stable-Full_Package.zip
http://joomlacode.org/gf/download/frsrelease/10697/42195/Joomla_1.5.13 -Stable-Full_Package.zip
Joomla Joomla 1.5.9
-
Joomla Joomla_1.5.13-Stable-Full_Package.zip
http://joomlacode.org/gf/download/frsrelease/10697/42195/Joomla_1.5.13 -Stable-Full_Package.zip
References
Joomla! Remote File Upload Vulnerability And Information Disclosure Weakness
References:
References:
- [20090722] - Core - File Upload (Joomla!)
- [20090722] - Core - Missing JEXEC Check (Joomla!)
- Joomla! Homepage (Joomla!)
- [ISecAuditors Security Advisories] Joomla! < 1.5.12 Multiple Full Path Disclosu (ISecAuditors Security Advisories
)