CVE-2011-5134: Medium severity widgetfactorylimited jce vulnerability
Unrestricted file upload vulnerability in editor/extensions/browser/file.php in the JCE component before 2.0.18 for Joomla! allows remote authenticated users with the author privileges to execute arbitrary PHP code by uploading a file with a double extension, as demonstrated by .php.gif. NOTE: some of these details are obtained from third party information.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-5134?
CVE-2011-5134 has a high severity level due to its potential to allow remote code execution by unauthorized users.
How do I fix CVE-2011-5134?
To fix CVE-2011-5134, you should upgrade the JCE component to version 2.0.18 or later without using vulnerable versions.
Who is affected by CVE-2011-5134?
CVE-2011-5134 affects remote authenticated users with author privileges in the JCE component on Joomla! installations prior to version 2.0.18.
What is the exploit method for CVE-2011-5134?
CVE-2011-5134 can be exploited by uploading files with double extensions, such as .php.gif, to execute arbitrary PHP code.
Is there a workaround for CVE-2011-5134?
The most effective workaround for CVE-2011-5134 is to restrict file upload capabilities and implement proper file validation before upgrading the component.