header-logo
Suggest Exploit
vendor:
Joomla
by:
Luca "daath" De Fulgentis
N/A
CVSS
HIGH
Remote Code Execution
CWE
Product Name: Joomla
Affected Version From: Joomla 1.5.12
Affected Version To: Joomla 1.5.12
Patch Exists: NO
Related CWE:
CPE:
Metasploit:
Other Scripts:
Platforms Tested: Ubuntu 8.10 / Apache 2.2.9, Windows XP SP2 / Apache 2.2.12
2009

Joomla 1.5.12 Remote Code Execution via TinyMCE upload vulnerability

This exploit allows an attacker to upload a PHP shell through the TinyMCE plugin in Joomla 1.5.12, leading to remote code execution. The attacker can then execute arbitrary commands on the target system.

Mitigation:

Update Joomla to a patched version. Disable or remove the TinyMCE plugin if not required.
Source

Exploit-DB raw data: