In Joomla! 3.2.0 through 3.6.5 (fixed in 3.7.0), inadequate MIME type checks allowed low-privilege users to upload swf files even if they were explicitly forbidden.
The product allows the attacker to upload or transfer files of dangerous types that can be automatically processed within the product’s environment.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Joomla! | Joomla | 3.2.0 (including) | 3.2.0 (including) |
Joomla! | Joomla | 3.2.1 (including) | 3.2.1 (including) |
Joomla! | Joomla | 3.2.2 (including) | 3.2.2 (including) |
Joomla! | Joomla | 3.2.3 (including) | 3.2.3 (including) |
Joomla! | Joomla | 3.2.4 (including) | 3.2.4 (including) |
Joomla! | Joomla | 3.3.0 (including) | 3.3.0 (including) |
Joomla! | Joomla | 3.3.1 (including) | 3.3.1 (including) |
Joomla! | Joomla | 3.3.2 (including) | 3.3.2 (including) |
Joomla! | Joomla | 3.3.3 (including) | 3.3.3 (including) |
Joomla! | Joomla | 3.3.4 (including) | 3.3.4 (including) |
Joomla! | Joomla | 3.3.5 (including) | 3.3.5 (including) |
Joomla! | Joomla | 3.4.0 (including) | 3.4.0 (including) |
Joomla! | Joomla | 3.4.0-alpha (including) | 3.4.0-alpha (including) |
Joomla! | Joomla | 3.4.0-beta1 (including) | 3.4.0-beta1 (including) |
Joomla! | Joomla | 3.4.0-beta2 (including) | 3.4.0-beta2 (including) |
Joomla! | Joomla | 3.4.0-beta3 (including) | 3.4.0-beta3 (including) |
Joomla! | Joomla | 3.4.0-rc1 (including) | 3.4.0-rc1 (including) |
Joomla! | Joomla | 3.4.1 (including) | 3.4.1 (including) |
Joomla! | Joomla | 3.4.1-rc1 (including) | 3.4.1-rc1 (including) |
Joomla! | Joomla | 3.4.1-rc2 (including) | 3.4.1-rc2 (including) |
Joomla! | Joomla | 3.4.2 (including) | 3.4.2 (including) |
Joomla! | Joomla | 3.4.2-rc1 (including) | 3.4.2-rc1 (including) |
Joomla! | Joomla | 3.4.3 (including) | 3.4.3 (including) |
Joomla! | Joomla | 3.4.4 (including) | 3.4.4 (including) |
Joomla! | Joomla | 3.4.5 (including) | 3.4.5 (including) |
Joomla! | Joomla | 3.4.6 (including) | 3.4.6 (including) |
Joomla! | Joomla | 3.4.7 (including) | 3.4.7 (including) |
Joomla! | Joomla | 3.4.8 (including) | 3.4.8 (including) |
Joomla! | Joomla | 3.4.8-rc (including) | 3.4.8-rc (including) |
Joomla! | Joomla | 3.5.0 (including) | 3.5.0 (including) |
Joomla! | Joomla | 3.5.0-beta (including) | 3.5.0-beta (including) |
Joomla! | Joomla | 3.5.0-beta2 (including) | 3.5.0-beta2 (including) |
Joomla! | Joomla | 3.5.0-beta3 (including) | 3.5.0-beta3 (including) |
Joomla! | Joomla | 3.5.0-beta4 (including) | 3.5.0-beta4 (including) |
Joomla! | Joomla | 3.5.0-beta5 (including) | 3.5.0-beta5 (including) |
Joomla! | Joomla | 3.5.0-rc (including) | 3.5.0-rc (including) |
Joomla! | Joomla | 3.5.0-rc2 (including) | 3.5.0-rc2 (including) |
Joomla! | Joomla | 3.5.0-rc3 (including) | 3.5.0-rc3 (including) |
Joomla! | Joomla | 3.5.0-rc4 (including) | 3.5.0-rc4 (including) |
Joomla! | Joomla | 3.5.1 (including) | 3.5.1 (including) |
Joomla! | Joomla | 3.5.1-rc (including) | 3.5.1-rc (including) |
Joomla! | Joomla | 3.6.0 (including) | 3.6.0 (including) |
Joomla! | Joomla | 3.6.0-alpha (including) | 3.6.0-alpha (including) |
Joomla! | Joomla | 3.6.0-beta1 (including) | 3.6.0-beta1 (including) |
Joomla! | Joomla | 3.6.0-beta2 (including) | 3.6.0-beta2 (including) |
Joomla! | Joomla | 3.6.0-rc (including) | 3.6.0-rc (including) |
Joomla! | Joomla | 3.6.0-rc2 (including) | 3.6.0-rc2 (including) |
Joomla! | Joomla | 3.6.1 (including) | 3.6.1 (including) |
Joomla! | Joomla | 3.6.1-rc1 (including) | 3.6.1-rc1 (including) |
Joomla! | Joomla | 3.6.1-rc2 (including) | 3.6.1-rc2 (including) |
Joomla! | Joomla | 3.6.2 (including) | 3.6.2 (including) |
Joomla! | Joomla | 3.6.3 (including) | 3.6.3 (including) |
Joomla! | Joomla | 3.6.3-rc1 (including) | 3.6.3-rc1 (including) |
Joomla! | Joomla | 3.6.3-rc2 (including) | 3.6.3-rc2 (including) |
Joomla! | Joomla | 3.6.3-rc3 (including) | 3.6.3-rc3 (including) |
Joomla! | Joomla | 3.6.4 (including) | 3.6.4 (including) |
Joomla! | Joomla | 3.6.5 (including) | 3.6.5 (including) |