{ "schema_version": "1.4.0", "id": "GHSA-x22x-5jv5-w996", "modified": "2022-05-17T01:50:51Z", "published": "2022-05-17T01:50:51Z", "aliases": [ "CVE-2011-5148" ], "details": "Multiple incomplete blacklist vulnerabilities in the Simple File Upload (mod_simplefileuploadv1.3) module before 1.3.5 for Joomla! allow remote attackers to execute arbitrary code by uploading a file with a (1) php5, (2) php6, or (3) double (e.g. .php.jpg) extension, then accessing it via a direct request to the file in images/, as exploited in the wild in January 2012.", "severity": [], "affected": [], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2011-5148" }, { "type": "WEB", "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/72023" }, { "type": "WEB", "url": "http://docs.joomla.org/Vulnerable_Extensions_List#Simple_File_Upload_1.3" }, { "type": "WEB", "url": "http://secunia.com/advisories/47370" }, { "type": "WEB", "url": "http://wasen.net/index.php?option=com_content&view=article&id=87&Itemid=59" }, { "type": "WEB", "url": "http://www.exploit-db.com/exploits/18287" }, { "type": "WEB", "url": "http://www.osvdb.org/78122" }, { "type": "WEB", "url": "http://www.securityfocus.com/bid/51214" }, { "type": "WEB", "url": "http://www.securityfocus.com/bid/51234" } ], "database_specific": { "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2012-08-31T21:55:00Z" } }