Joomla! Easy Flash Uploader Component 'helper.php' Arbitrary File Upload Vulnerability
BID:53977
Info
Joomla! Easy Flash Uploader Component 'helper.php' Arbitrary File Upload Vulnerability
| Bugtraq ID: | 53977 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 12 2012 12:00AM |
| Updated: | Jun 12 2012 12:00AM |
| Credit: | Sammy FORGIT |
| Vulnerable: |
ValorApps Easy Flash Uploader 2.0 |
| Not Vulnerable: | |
Discussion
Joomla! Easy Flash Uploader Component 'helper.php' Arbitrary File Upload Vulnerability
The Easy Flash Uploader component for Joomla! is prone to a vulnerability that lets attackers upload arbitrary files because the application fails to adequately sanitize user-supplied input.
An attacker can exploit this vulnerability to upload arbitrary code and run it in the context of the web server process.
Easy Flash Uploader 2.0 is vulnerable; other versions may also be affected.
The Easy Flash Uploader component for Joomla! is prone to a vulnerability that lets attackers upload arbitrary files because the application fails to adequately sanitize user-supplied input.
An attacker can exploit this vulnerability to upload arbitrary code and run it in the context of the web server process.
Easy Flash Uploader 2.0 is vulnerable; other versions may also be affected.
Exploit / POC
Joomla! Easy Flash Uploader Component 'helper.php' Arbitrary File Upload Vulnerability
Attackers can exploit this issue with a browser.
The following exploit data is available:
Attackers can exploit this issue with a browser.
The following exploit data is available:
Solution / Fix
Joomla! Easy Flash Uploader Component 'helper.php' Arbitrary File Upload Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
References
Joomla! Easy Flash Uploader Component 'helper.php' Arbitrary File Upload Vulnerability
References:
References:
- Easy Flash Uploader Homepage (Valor Apps)
- Joomla! Homepage (Joomla )