CVE-2007-4781 describes an arbitrary file upload vulnerability in the installer component of Joomla! 1.5 Beta1, Beta2, and RC1. Authenticated administrators can exploit this flaw by uploading malicious files to the tmp/ directory via the "Upload Package File" functionality. With a CVSS score of 6.6, this vulnerability has a network attack vector and high attack complexity, potentially leading to complete compromise of integrity and availability. While no active exploitation or Metasploit/Nuclei modules are reported, an ExploitDB entry for SQL Injection in similar versions exists, though not directly for this specific vulnerability. Community and media attention for this CVE are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.5.0_beta1CPE matchmatch criteria | cpe:2.3:a:joomla:joomla:1.5.0_beta1:*:*:*:*:*:*:* | ||
1.5.0_beta2CPE matchmatch criteria | cpe:2.3:a:joomla:joomla:1.5.0_beta2:*:*:*:*:*:*:* | ||
1.5.0_rc1CPE matchmatch criteria | cpe:2.3:a:joomla:joomla:1.5.0_rc1:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:H/Au:S/C:N/I:C/A:C
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.