CVE-2011-5148

High PUBLISHED

Multiple incomplete blacklist vulnerabilities in the Simple File Upload (mod_simplefileuploadv1.3) module before 1.3.5 for Joomla! allow remote...

Joomla! · Simple File Upload

Not yet in CISA KEV

Exploited in the wild

Recommended Action

Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.

Confidence
High
Exploitation Status
Exploited in the wild
Observed in Sensors
No
Attempts (30d)
Unique Attacker IPs
CISA KEV
Not yet in CISA KEV
CVSS / EPSS
6.8 Medium

At a Glance

Multiple incomplete blacklist vulnerabilities in the Simple File Upload (mod_simplefileuploadv1.3) module before 1.3.5 for Joomla! allow remote attackers to execute arbitrary code by uploading a file with a (1) php5, (2) php6, or (3) double (e.g. .php.jpg) extension, then accessing it via a direct request to the file in images/, as exploited in the wild in January 2012.

joomla php
CVE Published
Aug 31, 2012
Exploitation Reported
Aug 31, 2012
CVSS
6.8 Medium
EPSS
Remote Unauthenticated

Affected Versions

Vendor Product Version Status
n/a
n/a

n/a

Affected

CVE References

  • 47370 secunia.com · Third-Party Advisory http://secunia.com/advisories/47370
  • 18287 exploit-db.com · Exploit http://www.exploit-db.com/exploits/18287
  • simplefileupload-index-code-exec(72023) exchange.xforce.ibmcloud.com · VDB Entry https://exchange.xforce.ibmcloud.com/vulnerabilities/72023
  • 51214 securityfocus.com · VDB Entry http://www.securityfocus.com/bid/51214
  • 51234 securityfocus.com · VDB Entry http://www.securityfocus.com/bid/51234
Show 3 more references

Recommended Actions

  • Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
  • Use the Pro API to automate enrichment, telemetry, and workflow delivery for VM, SOC, and CTI pipelines.