Joomla! Yeendeen YEEditor File Upload Security Bypass Vulnerability
BID:67484
Info
Joomla! Yeendeen YEEditor File Upload Security Bypass Vulnerability
| Bugtraq ID: | 67484 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 19 2014 12:00AM |
| Updated: | May 19 2014 12:00AM |
| Credit: | The vendor reported this issue. |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Joomla! Yeendeen YEEditor File Upload Security Bypass Vulnerability
Joomla! Yeendeen YEEditor is prone to a security-bypass vulnerability.
Attackers can exploit this issue to bypass security restrictions and upload arbitrary files to the application. This may lead to further attacks.
Yeendeen YEEditor 1.07 and prior are vulnerable.
Joomla! Yeendeen YEEditor is prone to a security-bypass vulnerability.
Attackers can exploit this issue to bypass security restrictions and upload arbitrary files to the application. This may lead to further attacks.
Yeendeen YEEditor 1.07 and prior are vulnerable.
Exploit / POC
Joomla! Yeendeen YEEditor File Upload Security Bypass Vulnerability
An attacker can exploit this issue through readily available tools.
An attacker can exploit this issue through readily available tools.
Solution / Fix
Joomla! Yeendeen YEEditor File Upload Security Bypass Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information
Solution:
Updates are available. Please see the references or vendor advisory for more information
References
Joomla! Yeendeen YEEditor File Upload Security Bypass Vulnerability
References:
References: