CVE-2011-5148
EXPLOITED IN THE WILDJoomla! mod_simplefileuploadv1.3 <1.3.5 - RCE
Title source: llmDescription
Multiple incomplete blacklist vulnerabilities in the Simple File Upload (mod_simplefileuploadv1.3) module before 1.3.5 for Joomla! allow remote attackers to execute arbitrary code by uploading a file with a (1) php5, (2) php6, or (3) double (e.g. .php.jpg) extension, then accessing it via a direct request to the file in images/, as exploited in the wild in January 2012.
Exploits (1)
References (8)
Scores
EPSS
0.1893
EPSS Percentile
95.3%
Details
VulnCheck KEV
2012-08-31
InTheWild.io
2017-08-29
Status
published
Products (3)
wasen/mod_simplefileupload
1.0
wasen/mod_simplefileupload
1.1
wasen/mod_simplefileupload
< 1.3
Published
Aug 31, 2012
Tracked Since
Feb 18, 2026