header-logo
Suggest Exploit
vendor:
com_jfuploader
by:
Setr0nix
8,8
CVSS
HIGH
Remote File Upload
434
CWE
Product Name: com_jfuploader
Affected Version From: 2.12 and below
Affected Version To: N/A
Patch Exists: Yes
Related CWE: N/A
CPE: N/A
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
N/A

Joomla Component com_jfuploader < 2.12 Remote File Upload

A vulnerability in Joomla Component com_jfuploader version 2.12 and below allows an attacker to upload a malicious file to the server. The attacker can register on the website, download a gif image, open it in Notepad++, copy and paste a PHP code after the last line, save it, rename it to logo.php.gif and upload it from com_jfuploader. The attacker can then access the uploaded file by going to http://127.0.0.1/files/YourUsername/logo.php.gif.

Mitigation:

Upgrade to version 2.12 or later, or apply the patch provided by the vendor.
Source

Exploit-DB raw data:

=========================================================================================================
[#]    Type    : Joomla Component com_jfuploader < 2.12 Remote File Upload
[#]    Author  : Setr0nix
[#]    Home    : www.Setr0nix.com
[#]    Contact : Admin@Setr0nix.com
=========================================================================================================

[#]    Exploit :
       1. Register 
	   2. http://127.0.0.1/index.php?option=com_jfuploader&Itemid=[Itemid]
	   3. Download One gif Image ( Example : http://www.google.com/images/logo.gif )
	   4. Open logo.gif In Notepad++ And Got to Last Line
	   5. Copy And Past You PHP Code After The Last Line ( Don't Delete Any Thing Of Image Code )
	   6. Save It , Ctrl + S
	   7. Rename logo.gif To logo.php.gif And Upload It From com_jfuploader
	   8. To Run Your Uploaded File Go To This Link : http://127.0.0.1/files/YourUsername/logo.php.gif
	   
=========================================================================================================
[#]    S T T   :
       All Iranian Hackers , Offensive Security , Inj3ct0r , SecurityReason
=========================================================================================================