CVE-2011-5004

EUVD-2011-4909
Unrestricted file upload vulnerability in models/importcsv.php in the Fabrik (com_fabrik) component before 2.1.1 for Joomla! allows remote authenticated users with Manager privileges to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in an unspecified directory.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:S/C:P/I:P/A:P
Base Score
CVSS 3.x
EPSS Score
Percentile: 80%
Affected Products (NVD)
VendorProductVersion
fabrikarcom_fabrikar
𝑥
≤ 2.1
fabrikarcom_fabrikar
1.0.1
fabrikarcom_fabrikar
1.0.6
fabrikarcom_fabrikar
2.0.2
fabrikarcom_fabrikar
2.0.4
fabrikarcom_fabrikar
2.0.5
𝑥
= Vulnerable software versions