Secunia Logo
 
CVE Reference: CVE-2007-4817
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2007-4817

Description:
Unrestricted file upload vulnerability in the Restaurante (com_restaurante) component for Joomla! allows remote attackers to upload and execute arbitrary PHP code via an upload action specifying a filename with a double extension such as .php.jpg, which creates an accessible file under img_original/.

CVE Status:
Candidate

References:

XF
  http://xforce.iss.net/xforce/xfdb/36538

SAID
  Secunia Advisory: SA26756

MLIST
  http://www.attrition.org/pipermail/vim/2007-September/001779.html

MILW0RM
  http://www.milw0rm.com/exploits/4383

BID
  25612


Return to the previous page.