Joomla Com Sexycontactform Plugin File Upload

Strike ID:
E18-wn9b1
CVSS:
7.5 (AV:N/AC:L/Au:N/C:P/I:P/A:P)
False Positive:
f
Variants:
1
Year:
2017

Description

This strike exploits a file upload vulnerability present in Joomla com_sexycontactform plugin. By exploiting this vulnerability, an unauthenticated attacker can run arbitrary code by uploading files on the server and execute them. Note: This vulnerability was disclosed by the XAttacker Tool.

References