7.5
CVSSv2

CVE-2007-3932

Published: 21/07/2007 Updated: 29/09/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

uploadimg.php in the Expose RC35 and previous versions (com_expose) component for Joomla! sends an error message but does not exit when it detects an attempt to upload a non-JPEG file, which allows remote malicious users to upload and execute arbitrary PHP code in the img/ folder.

Vulnerable Product Search on Vulmon Subscribe to Product

joomla expose

Exploits

HHHHHHH HHHHHH HH HHHHHHHH HHHHHH HHHHHHHH IHHI HH HH HHHHHHHH HH HH HH HH HH HHHHHHHH HH IHHI HH HHH HH HHHHHHHH HH HH HH HH HH HH HH HH HH HHHH HH HH HHHHHHH HHHHHH HH HHHHHHH HHHHHH HH HH HH HH HH HHHHHHHH HH HH ...