6.5
CVSSv2

CVE-2014-1214

Published: 13/11/2019 Updated: 18/11/2019
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 655
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

views/upload.php in the ProJoom Smart Flash Header (NovaSFH) component 3.0.2 and previous versions for Joomla! allows remote malicious users to upload and execute arbitrary files via a crafted (1) dest parameter and (2) arbitrary extension in the Filename parameter.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

projoom smart flash header

Exploits

source: wwwsecurityfocuscom/bid/65438/info Projoom NovaSFH plugin for Joomla! is prone to an arbitrary-file-upload vulnerability because it fails to adequately sanitize user-supplied input An attacker may leverage this issue to upload arbitrary files; this can result in arbitrary code execution within the context of the vulnerable appli ...