CVE-2012-2902
Unrestricted file upload vulnerability in editor/extensions/browser/file.php in the Joomla Content Editor (JCE) component before 2.1 for Joomla!, when chunking…
MEDIUM
Extension Joomla (identification incertaine)
Pertinence : probable
Description
Unrestricted file upload vulnerability in editor/extensions/browser/file.php in the Joomla Content Editor (JCE) component before 2.1 for Joomla!, when chunking is set to greater than zero, allows remote authors to execute arbitrary PHP code by uploading a PHP file with a double extension as demonstrated by .jpg.pht.
Sévérité
6.0
Moyenne · CVSS 2.0
AV:N/AC:M/Au:S/C:P/I:P/A:P
Score retenu : NVD
| Source | Sévérité d'origine | CVSS |
|---|---|---|
| NVD | MEDIUM | 6.0 (v2.0) |
Produit et versions
- Produit
- Extension Joomla (identification incertaine)
- Corrigée dans
- Non précisée
- Publiée
- 21/05/2012
- Modifiée
- 16/06/2026
Versions concernées
- joomla_content_editor — jusqu'à 2.0.21
- joomla_content_editor — 2.0 – 2.0
Sources
- NVD CVE-2012-2902 vu
Ces informations proviennent des sources ci-dessus ; CVE Oyer n'y ajoute aucune interprétation.
Historique
- Détectée via nvd26/09/2026 09:34 UTC