Joomla! CiviCRM Component Multiple Arbitrary File Upload Vulnerabilities
BID:55166
Info
Joomla! CiviCRM Component Multiple Arbitrary File Upload Vulnerabilities
| Bugtraq ID: | 55166 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 22 2012 12:00AM |
| Updated: | Aug 22 2012 12:00AM |
| Credit: | Crim3R |
| Vulnerable: |
CiviCRM CiviCRM 0 |
| Not Vulnerable: | |
Discussion
Joomla! CiviCRM Component Multiple Arbitrary File Upload Vulnerabilities
The CiviCRM component for Joomla! is prone to multiple arbitrary file-upload vulnerabilities that allows attackers to upload arbitrary files because the application fails to adequately sanitize user-supplied input.
An attacker can exploit these vulnerabilities to upload arbitrary code and run it in the context of the web server process. This may facilitate unauthorized access or privilege escalation; other attacks are also possible.
The CiviCRM component for Joomla! is prone to multiple arbitrary file-upload vulnerabilities that allows attackers to upload arbitrary files because the application fails to adequately sanitize user-supplied input.
An attacker can exploit these vulnerabilities to upload arbitrary code and run it in the context of the web server process. This may facilitate unauthorized access or privilege escalation; other attacks are also possible.
Exploit / POC
Joomla! CiviCRM Component Multiple Arbitrary File Upload Vulnerabilities
Attackers can exploit this issue with a browser.
The following example URIs are available:
http://www.example.com/lynda/administrator/components/com_civicrm/civicrm/packages/fckeditor/editor/filemanager/connectors/uploadtest.html
http://www.example.com/administrator/components/com_civicrm/civicrm/packages/fckeditor/editor/filemanager/connectors/test.html
http://www.example.com/mada/administrator/components/com_civicrm/civicrm/packages/fckeditor/editor/filemanager/connectors/test.html
Attackers can exploit this issue with a browser.
The following example URIs are available:
http://www.example.com/lynda/administrator/components/com_civicrm/civicrm/packages/fckeditor/editor/filemanager/connectors/uploadtest.html
http://www.example.com/administrator/components/com_civicrm/civicrm/packages/fckeditor/editor/filemanager/connectors/test.html
http://www.example.com/mada/administrator/components/com_civicrm/civicrm/packages/fckeditor/editor/filemanager/connectors/test.html
Solution / Fix
Joomla! CiviCRM Component Multiple Arbitrary File Upload Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
References
Joomla! CiviCRM Component Multiple Arbitrary File Upload Vulnerabilities
References:
References:
- CiviCRM (CiviCRM LLC)
- Joomla! Homepage (Joomla )