views/upload.php in the ProJoom Smart Flash Header (NovaSFH) component 3.0.2 and earlier for Joomla! allows remote attackers to upload and execute arbitrary files via a crafted (1) dest parameter and (2) arbitrary extension in the Filename parameter.
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
Link | Tags |
---|---|
https://www.portcullis-security.com/security-research-and-downloads/security-advisories/cve-2014-1214/ | third party advisory exploit |
https://exchange.xforce.ibmcloud.com/vulnerabilities/91020 | vdb entry third party advisory |