1 results (0.002 seconds)
CVSS: 9.8EPSS: 6%CPEs: 1EXPL: 1

CVE-2007-4817 – Joomla! Component Restaurante - Arbitrary File Upload
https://notcve.org/view.php?id=CVE-2007-4817
11 Sep 2007 — Unrestricted file upload vulnerability in the Restaurante (com_restaurante) component for Joomla! allows remote attackers to upload and execute arbitrary PHP code via an upload action specifying a filename with a double extension such as .php.jpg, which creates an accessible file under img_original/. Vulnerabilidad de envío de archivo no restringido en el componente REstaurante (com_restaurante) para Joomla! permite a atacantes remotos enviar y ejecutar código PHP de su elección mediante una acción upload e... • https://www.exploit-db.com/exploits/4383 • CWE-94: Improper Control of Generation of Code ('Code Injection') •