Joomla! JomSocial Component Arbitrary PHP Code Execution Vulnerability
BID:65261
Info
Joomla! JomSocial Component Arbitrary PHP Code Execution Vulnerability
| Bugtraq ID: | 65261 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 30 2014 12:00AM |
| Updated: | Jan 30 2014 12:00AM |
| Credit: | Matias Fontanini and Gaston Traberg |
| Vulnerable: |
JomSocial JomSocial 2.6 |
| Not Vulnerable: |
JomSocial JomSocial 3.1.0.1 |
Discussion
Joomla! JomSocial Component Arbitrary PHP Code Execution Vulnerability
The JomSocial component for Joomla is prone to an arbitrary PHP code-execution vulnerability.
Successfully exploiting this issue will allow attackers to execute arbitrary code within the context of the application.
JomSocial prior to 3.1.0.1 are vulnerable.
The JomSocial component for Joomla is prone to an arbitrary PHP code-execution vulnerability.
Successfully exploiting this issue will allow attackers to execute arbitrary code within the context of the application.
JomSocial prior to 3.1.0.1 are vulnerable.
References
Joomla! JomSocial Component Arbitrary PHP Code Execution Vulnerability
References:
References:
- JomSocial Homepage (JomSocial)
- Joomla! JomSocial component < 3.1.0.1 - Remote code execution (Seclists)