CVE-2013-5576
Joomla! Component Media Manager - Arbitrary File Upload
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
3Exploited in Wild
-Decision
Descriptions
administrator/components/com_media/helpers/media.php in the media manager in Joomla! 2.5.x before 2.5.14 and 3.x before 3.1.5 allows remote authenticated users or remote attackers to bypass intended access restrictions and upload files with dangerous extensions via a filename with a trailing . (dot), as exploited in the wild in August 2013.
administrator/components/com_media/helpers/media.php en el gestor de medios de Joomla! 2.5.x anterior a la versión 2.5.14 y 3.x anterior a 3.1.5 permite a usuarios remotos autenticados o a atacantes remotos evadir restricciones de acceso intencionadas y subir archivos con extensiones peligrosas a través de un nombre de archivo con un . (punto), tal y como se explotó activamente en agosto de 2013.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2013-08-15 First Exploit
- 2013-08-23 CVE Reserved
- 2013-10-09 CVE Published
- 2024-08-06 CVE Updated
- 2024-11-02 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-20: Improper Input Validation
CAPEC
References (10)
URL | Tag | Source |
---|---|---|
http://developer.joomla.org/security/563-20130801-core-unauthorised-uploads.html | X_refsource_confirm | |
http://joomlacode.org/gf/project/joomla/tracker/?action=TrackerItemEdit&tracker_item_id=31626 | X_refsource_misc | |
http://seclists.org/oss-sec/2013/q3/484 | Mailing List | |
http://seclists.org/oss-sec/2013/q3/486 | Mailing List | |
http://www.cso.com.au/article/523528/joomla_patches_file_manager_vulnerability_responsible_hijacked_websites | X_refsource_misc | |
http://www.kb.cert.org/vuls/id/639620 | Third Party Advisory | |
https://github.com/joomla/joomla-cms/commit/1ed07e257a2c0794ba19e864f7c5101e7e8c41d2 | X_refsource_confirm |
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/27610 | 2013-08-15 | |
http://www.exploit-db.com/exploits/27610 | 2024-08-06 | |
https://github.com/joomla/joomla-cms/commit/fa5645208eefd70f521cd2e4d53d5378622133d8 | 2024-08-06 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Joomla Search vendor "Joomla" | Joomla\! Search vendor "Joomla" for product "Joomla\!" | 2.5.0 Search vendor "Joomla" for product "Joomla\!" and version "2.5.0" | - |
Affected
| ||||||
Joomla Search vendor "Joomla" | Joomla\! Search vendor "Joomla" for product "Joomla\!" | 2.5.1 Search vendor "Joomla" for product "Joomla\!" and version "2.5.1" | - |
Affected
| ||||||
Joomla Search vendor "Joomla" | Joomla\! Search vendor "Joomla" for product "Joomla\!" | 2.5.2 Search vendor "Joomla" for product "Joomla\!" and version "2.5.2" | - |
Affected
| ||||||
Joomla Search vendor "Joomla" | Joomla\! Search vendor "Joomla" for product "Joomla\!" | 2.5.3 Search vendor "Joomla" for product "Joomla\!" and version "2.5.3" | - |
Affected
| ||||||
Joomla Search vendor "Joomla" | Joomla\! Search vendor "Joomla" for product "Joomla\!" | 2.5.4 Search vendor "Joomla" for product "Joomla\!" and version "2.5.4" | - |
Affected
| ||||||
Joomla Search vendor "Joomla" | Joomla\! Search vendor "Joomla" for product "Joomla\!" | 2.5.5 Search vendor "Joomla" for product "Joomla\!" and version "2.5.5" | - |
Affected
| ||||||
Joomla Search vendor "Joomla" | Joomla\! Search vendor "Joomla" for product "Joomla\!" | 2.5.6 Search vendor "Joomla" for product "Joomla\!" and version "2.5.6" | - |
Affected
| ||||||
Joomla Search vendor "Joomla" | Joomla\! Search vendor "Joomla" for product "Joomla\!" | 2.5.7 Search vendor "Joomla" for product "Joomla\!" and version "2.5.7" | - |
Affected
| ||||||
Joomla Search vendor "Joomla" | Joomla\! Search vendor "Joomla" for product "Joomla\!" | 2.5.8 Search vendor "Joomla" for product "Joomla\!" and version "2.5.8" | - |
Affected
| ||||||
Joomla Search vendor "Joomla" | Joomla\! Search vendor "Joomla" for product "Joomla\!" | 2.5.9 Search vendor "Joomla" for product "Joomla\!" and version "2.5.9" | - |
Affected
| ||||||
Joomla Search vendor "Joomla" | Joomla\! Search vendor "Joomla" for product "Joomla\!" | 2.5.10 Search vendor "Joomla" for product "Joomla\!" and version "2.5.10" | - |
Affected
| ||||||
Joomla Search vendor "Joomla" | Joomla\! Search vendor "Joomla" for product "Joomla\!" | 2.5.11 Search vendor "Joomla" for product "Joomla\!" and version "2.5.11" | - |
Affected
| ||||||
Joomla Search vendor "Joomla" | Joomla\! Search vendor "Joomla" for product "Joomla\!" | 2.5.12 Search vendor "Joomla" for product "Joomla\!" and version "2.5.12" | - |
Affected
| ||||||
Joomla Search vendor "Joomla" | Joomla\! Search vendor "Joomla" for product "Joomla\!" | 2.5.13 Search vendor "Joomla" for product "Joomla\!" and version "2.5.13" | - |
Affected
| ||||||
Joomla Search vendor "Joomla" | Joomla\! Search vendor "Joomla" for product "Joomla\!" | 3.0.0 Search vendor "Joomla" for product "Joomla\!" and version "3.0.0" | - |
Affected
| ||||||
Joomla Search vendor "Joomla" | Joomla\! Search vendor "Joomla" for product "Joomla\!" | 3.0.1 Search vendor "Joomla" for product "Joomla\!" and version "3.0.1" | - |
Affected
| ||||||
Joomla Search vendor "Joomla" | Joomla\! Search vendor "Joomla" for product "Joomla\!" | 3.0.2 Search vendor "Joomla" for product "Joomla\!" and version "3.0.2" | - |
Affected
| ||||||
Joomla Search vendor "Joomla" | Joomla\! Search vendor "Joomla" for product "Joomla\!" | 3.0.3 Search vendor "Joomla" for product "Joomla\!" and version "3.0.3" | - |
Affected
| ||||||
Joomla Search vendor "Joomla" | Joomla\! Search vendor "Joomla" for product "Joomla\!" | 3.0.4 Search vendor "Joomla" for product "Joomla\!" and version "3.0.4" | - |
Affected
| ||||||
Joomla Search vendor "Joomla" | Joomla\! Search vendor "Joomla" for product "Joomla\!" | 3.1.0 Search vendor "Joomla" for product "Joomla\!" and version "3.1.0" | - |
Affected
| ||||||
Joomla Search vendor "Joomla" | Joomla\! Search vendor "Joomla" for product "Joomla\!" | 3.1.1 Search vendor "Joomla" for product "Joomla\!" and version "3.1.1" | - |
Affected
| ||||||
Joomla Search vendor "Joomla" | Joomla\! Search vendor "Joomla" for product "Joomla\!" | 3.1.2 Search vendor "Joomla" for product "Joomla\!" and version "3.1.2" | - |
Affected
| ||||||
Joomla Search vendor "Joomla" | Joomla\! Search vendor "Joomla" for product "Joomla\!" | 3.1.3 Search vendor "Joomla" for product "Joomla\!" and version "3.1.3" | - |
Affected
| ||||||
Joomla Search vendor "Joomla" | Joomla\! Search vendor "Joomla" for product "Joomla\!" | 3.1.4 Search vendor "Joomla" for product "Joomla\!" and version "3.1.4" | - |
Affected
|