7.5
CVSSv2

CVE-2011-4906

Published: 12/02/2020 Updated: 25/02/2020
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Tiny browser in TinyMCE 3.0 editor in Joomla! prior to 1.5.13 allows file upload and arbitrary PHP code execution.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

tiny tinybrowser

Exploits

<?php /** ** Joomla 1512 Remote Code Execution via TinyMCE upload vulnerability ** ** Tested against : ** - Joomla 1512 / Ubuntu 810 / Apache 229 ** - Joomla 1512 / Windows XP SP2 / Apache 2212 ** ** Luca "daath" De Fulgentis - daath [at] nibblesecorg ** blognibblesecorg ** **/ /* daath@shaytan:~$ php pwnoomla ...