HTTP: Joomla JCE Editor File Upload
This signature detects attempts to exploit a known vulnerability in the Joomla JCE Editor. By supplying a maliciously crafted file upload request to a php script, attackers can cause files to be uploaded to an arbitrary location, possibly leading to script execution.
Extended Description
The JCE component for Joomla! is prone to a vulnerability that lets attackers upload arbitrary files because the application fails to adequately sanitize user-supplied input. An attacker can exploit this vulnerability to upload arbitrary code and run it in the context of the webserver process. This may facilitate unauthorized access or privilege escalation; other attacks are also possible. Versions prior to JCE component 2.1.0 are vulnerable.
Affected Products
Joomla jce,Joomla jce
References
BugTraq: 51002
CVE: CVE-2012-2902
URL: http://www.joomlacontenteditor.net/ http://secunia.com/secunia_research/2012-15/
srx-branch-12.3
srx-19.3
srx-branch-19.3
vsrx3bsd-19.2
srx-branch-19.4
vsrx-19.4
mx-12.3
mx-19.4
vmx-19.4
mx-19.3
vsrx3bsd-19.4
srx-19.4
vsrx-12.3
vmx-19.3
vsrx-19.2
srx-12.3
Joomla
6.0