vendor:
E-portfolio
by:
Sid3^effects aKa HaRi
7,5
CVSS
HIGH
Upload Vulnerability
N/A
CWE
Product Name: E-portfolio
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: N/A
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2010
Joomla com_eportfolio Upload Vulnerability
Advanced access control will let a user decide who will be able to read and comment his joomla portfolio. There are many configuration features like the ability to upload files to portfolio, calendar and events by users and others. Attackers can upload their shells in the options Achievements • Plans • Events • Pages. After uploading the shell, attackers can check their shell and root the server.
Mitigation:
Ensure that the access control is properly configured and users are not allowed to upload malicious files.