vendor:
CBE
by:
Not provided
7,5
CVSS
HIGH
Local File Inclusion
22
CWE
Product Name: CBE
Affected Version From: CBE v1.4.8
Affected Version To: CBE v1.4.10
Patch Exists: YES
Related CWE: Not provided
CPE: Not provided
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows, Linux, Mac
Not provided
Joomla CBE Local File Inclusion Vulnerability
Joomla CBE suffers from a local file inclusion vulnerability. As CBE also offers file uploading functionality that allows to upload files that contain php-code, this can be used to execute arbitary system-commands on the host with the webservers privileges.
Mitigation:
Check if the contents of an uploaded file contains a php open-tag ('<?php') (requires that the php-short-open-tag option is disabled) and upgrade to Joomla CBE v1.4.11