visit http(s)://site/index.php?option=com_media&view=images&asset=com_content&tmpl=component to upload files onto target victim host's Joomla "images" folder
Permission denied, I suppose?
Success
NA
tutorial documented @ https://cxsecurity.com/issue/WLB-2017020171
Labels |
Added:
?
|
Category | ⇒ | ACL com_media |
Status | New | ⇒ | Discussion |
Closed
Status | Discussion | ⇒ | Closed |
Closed_Date | 0000-00-00 00:00:00 | ⇒ | 2017-08-29 09:43:28 |
Closed_By | ⇒ | brianteeman |
Only exploitable if your site's ACL is massively misconfigured (as in you allow public write access to something)
We really just need to rip out the ACL support in com_media because there are far too many false reports about this