CVE-2007-4817
Restaurante Component for Joomla! - Unauthenticated Arbitrary PHP File Upload via Double Extension Bypass
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2007-4817. PoCs published by Cold Zero.
AI-analyzed exploit summary This is a writeup describing a remote file upload vulnerability in the Joomla Component Restaurante. The vulnerability allows an attacker to upload arbitrary files by exploiting the 'upload' task in the 'com_restaurante' component, with the uploaded file accessible via a specific path.
Description
Unrestricted file upload vulnerability in the Restaurante (com_restaurante) component for Joomla! allows remote attackers to upload and execute arbitrary PHP code via an upload action specifying a filename with a double extension such as .php.jpg, which creates an accessible file under img_original/.
Exploits (1)
This is a writeup describing a remote file upload vulnerability in the Joomla Component Restaurante. The vulnerability allows an attacker to upload arbitrary files by exploiting the 'upload' task in the 'com_restaurante' component, with the uploaded file accessible via a specific path.