CVE-2011-5134

Unrestricted file upload vulnerability in editor/extensions/browser/file.php in the JCE component before 2.0.18 for Joomla! allows remote authenticated users with the author privileges to execute arbitrary PHP code by uploading a file with a double extension, as demonstrated by .php.gif. NOTE: some of these details are obtained from third party information.
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:a:widgetfactorylimited:com_jce:*:*:*:*:*:*:*:*
cpe:2.3:a:widgetfactorylimited:com_jce:2.0.0:*:*:*:*:*:*:*
cpe:2.3:a:widgetfactorylimited:com_jce:2.0.1:*:*:*:*:*:*:*
cpe:2.3:a:widgetfactorylimited:com_jce:2.0.2:*:*:*:*:*:*:*
cpe:2.3:a:widgetfactorylimited:com_jce:2.0.3:*:*:*:*:*:*:*
cpe:2.3:a:widgetfactorylimited:com_jce:2.0.4:*:*:*:*:*:*:*
cpe:2.3:a:widgetfactorylimited:com_jce:2.0.5:*:*:*:*:*:*:*
cpe:2.3:a:widgetfactorylimited:com_jce:2.0.6:*:*:*:*:*:*:*
cpe:2.3:a:widgetfactorylimited:com_jce:2.0.7:*:*:*:*:*:*:*
cpe:2.3:a:widgetfactorylimited:com_jce:2.0.8:*:*:*:*:*:*:*
cpe:2.3:a:widgetfactorylimited:com_jce:2.0.9:*:*:*:*:*:*:*
cpe:2.3:a:widgetfactorylimited:com_jce:2.0.10:*:*:*:*:*:*:*
cpe:2.3:a:widgetfactorylimited:com_jce:2.0.11:*:*:*:*:*:*:*
cpe:2.3:a:widgetfactorylimited:com_jce:2.0.12:*:*:*:*:*:*:*
cpe:2.3:a:widgetfactorylimited:com_jce:2.0.13:*:*:*:*:*:*:*
cpe:2.3:a:widgetfactorylimited:com_jce:2.0.14:*:*:*:*:*:*:*
cpe:2.3:a:widgetfactorylimited:com_jce:2.0.15:*:*:*:*:*:*:*
cpe:2.3:a:widgetfactorylimited:com_jce:2.0.16:*:*:*:*:*:*:*
cpe:2.3:a:joomla:joomla\!:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2012-08-30 22:55

Updated : 2023-12-10 11:16


NVD link : CVE-2011-5134

Mitre link : CVE-2011-5134

CVE.ORG link : CVE-2011-5134


JSON object : View

Products Affected

widgetfactorylimited

  • com_jce

joomla

  • joomla\!