CVE-2006-4471Unrestricted File Upload in Joomla !

Severity
6.5MEDIUMNVD
EPSS
0.1%
top 73.38%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedAug 31
Latest updateMay 1

Description

The Admin Upload Image functionality in Joomla! before 1.0.11 allows remote authenticated users to upload files outside of the /images/stories/ directory via unspecified vectors.

CVSS vector

AV:N/AC:L/C:P/I:P/A:PExploitability: 8.0 | Impact: 6.4

Affected Packages1 packages

NVDjoomla/joomla_!< 1.0.11

🔴Vulnerability Details

1
GHSA
GHSA-77r3-596x-p2g8: The Admin Upload Image functionality in Joomla! before 12022-05-01