vendor:
Joomla joomgalaxy
by:
Daniel Barragan "D4NB4R"
9.8
CVSS
CRITICAL
Unrestricted File Upload
434
CWE
Product Name: Joomla joomgalaxy
Affected Version From: 1.2.0.4
Affected Version To: 1.2.0.4
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Linux, Windows
2012
Joomla joomgalaxy 1.2.0.4 Multiple Vulnerabilities
The vulnerability allows attackers to upload arbitrary files by exploiting the file upload functionality in the Joomla joomgalaxy component. By uploading a specially crafted file, an attacker can execute arbitrary code on the target system.
Mitigation:
Apply the latest patch or upgrade to a newer version of the component. Disable file upload functionality if not required.