vendor:
Joomla! CMS
by:
Johannes Greil / SEC Consult
9
CVSS
CRITICAL
Remote Command Execution
78
CWE
Product Name: Joomla! CMS
Affected Version From: 1.5 beta 2
Affected Version To: 1.5 beta 2
Patch Exists: NO
Related CWE:
CPE: a:joomla:joomla:1.5_beta_2
Platforms Tested:
2007
Remote command execution in Joomla! CMS
The search component of Joomla! allows an attacker to execute arbitrary PHP commands. It is possible to execute OS commands via system() calls. An attacker does not need to be authenticated to perform this attack.
Mitigation:
Upgrade to a non-vulnerable version of Joomla!