vendor:
MySMS
by:
Sid3^effects aKa HaRi
7,5
CVSS
HIGH
Upload Vulnerability
N/A
CWE
Product Name: MySMS
Affected Version From: Joomla 1.0.x
Affected Version To: Joomla 1.5.x
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2010
Joomla com_mysms Upload Vulnerability
MySMS is standing for 'Simple sms component' for Joomla. The MySMS component is now available for Joomla 1.0.x ( com_mysms-0.9.4.zip ) and for Joomla 1.5.x series ( use com_mysms-1.5.10.zip ). This component supports following sms gateway provider today: w2sms, teleword, smskaufen, smscreator, sms77, sms4credits, mobilant, mesmo, clickatell, aspsms, nohnoh, mexado, innosend, suresms,compaya and hardwired, mobilenl, sloono, smsat and wannfind, agiletelecom, smsviainternet, infobip, at&t, smscom, coolsms, smsglobal, aruhat, massenversand, smstrade. The attacker can upload shell in the 'Import phonebook' option and it doesnt validate any file format so upload your shell.
Mitigation:
N/A