Joomla! 'media.php' Arbitrary File Upload Vulnerability
BID:61582
Info
Joomla! 'media.php' Arbitrary File Upload Vulnerability
| Bugtraq ID: | 61582 |
| Class: | Input Validation Error |
| CVE: |
CVE-2013-5576 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 01 2013 12:00AM |
| Updated: | Nov 01 2013 12:51AM |
| Credit: | Jens Hinrichsen |
| Vulnerable: |
Joomla Joomla! 2.5.4 Joomla Joomla! 2.5.3 Joomla Joomla! 2.5.2 Joomla Joomla! 2.5.1 Joomla Joomla! 2.5 |
| Not Vulnerable: | |
Discussion
Joomla! 'media.php' Arbitrary File Upload Vulnerability
Joomla! is prone to a vulnerability that lets attackers upload arbitrary files. The issue occurs because the application fails to adequately sanitize user-supplied input.
An attacker may leverage this issue to upload arbitrary files to the affected computer; this can result in arbitrary code execution within the context of the vulnerable application.
Joomla! versions prior to 2.5.14 and 3.1.5 are vulnerable.
Joomla! is prone to a vulnerability that lets attackers upload arbitrary files. The issue occurs because the application fails to adequately sanitize user-supplied input.
An attacker may leverage this issue to upload arbitrary files to the affected computer; this can result in arbitrary code execution within the context of the vulnerable application.
Joomla! versions prior to 2.5.14 and 3.1.5 are vulnerable.
Exploit / POC
Joomla! 'media.php' Arbitrary File Upload Vulnerability
An attacker can exploit this issue using a web browser.
The following metasploit module is available:
An attacker can exploit this issue using a web browser.
The following metasploit module is available:
Solution / Fix
Joomla! 'media.php' Arbitrary File Upload Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.