7.5
CVSSv2

CVE-2018-6580

Published: 02/02/2018 Updated: 14/02/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Arbitrary file upload exists in the Jimtawl 2.1.6 and 2.2.5 component for Joomla! via a view=upload&task=upload&pop=true&tmpl=component request.

Vulnerable Product Search on Vulmon Subscribe to Product

janguo jimtawl 2.1.6

janguo jimtawl 2.2.5

Exploits

# # # # # # Exploit Title: Joomla! Component Jimtawl 225 - Arbitrary File Upload # Dork: N/A # Date: 01022018 # Vendor Homepage: janguode/ # Software Link: extensionsjoomlaorg/extensions/extension/multimedia/streaming-a-broadcasting/jimtawl/ # Software Download: janguode/lang-en/joomla-25-higher/jimtawl/pkg_jimtawl-2-2 ...