Collector Component for Joomla! File Upload RCE
High Nessus Plugin ID 64470
SynopsisThe remote web server contains a PHP application that is affected by a remote code execution vulnerability.
DescriptionThe Collector Component for Joomla! running on the remote web server is affected by a remote code execution vulnerability in the com_collector component due to improper sanitization or verification of uploaded files before placing them in a user-accessible path. An unauthenticated, remote attacker can exploit this issue, by uploading and then making a direct request to a crafted file, to execute arbitrary PHP script on the remote host, subject to the privileges of the web server user ID.
SolutionUnknown at this time.