vendor:
Civicrm
by:
iskorpitx
7,5
CVSS
HIGH
Remote Code Injection
78
CWE
Product Name: Civicrm
Affected Version From: civicrm 4.2.2
Affected Version To: civicrm 4.2.2
Patch Exists: YES
Related CWE: N/A
CPE: a:civicrm:civicrm
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Win8 Pro x64
2013
joomla component com_civicrm remode code injection exploit
This exploit is used to inject malicious code into the Joomla component com_civicrm OpenFlashCart ofc_upload_image.php. The exploit is done by submitting a request to the URL with the malicious code in the post fields. The malicious code is then executed and a shell is uploaded to the target server.
Mitigation:
Ensure that all components are up to date and that all security patches are applied.