CVE-2007-4781: Input Validation
administrator/index.php in the installer component (cominstaller) in Joomla! 1.5 Beta1, Beta2, and RC1 allows remote authenticated administrators to upload arbitrary files to tmp/ via the "Upload Package File" functionality, which is accessible when cominstaller is the value of the option parameter.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2007-4781?
CVE-2007-4781 is considered to be of medium severity due to the potential for unauthorized file uploads.
How do I fix CVE-2007-4781?
To fix CVE-2007-4781, upgrade to Joomla! versions later than 1.5.0_rc1 that address this vulnerability.
Who is affected by CVE-2007-4781?
CVE-2007-4781 affects remote authenticated administrators using Joomla! versions 1.5 Beta1, Beta2, and RC1.
What versions of Joomla! are vulnerable to CVE-2007-4781?
Versions 1.5.0 Beta1, Beta2, and 1.5.0 RC1 of Joomla! are vulnerable to CVE-2007-4781.
Can CVE-2007-4781 be exploited without authentication?
No, CVE-2007-4781 requires an authenticated administrator to exploit the vulnerability.