CVE-2011-5148: Wasen Mod Simplefileupload
Medium severity, CVSS 6.8. EPSS: 4.8% chance of exploitation in the next 30 days.
Multiple incomplete blacklist vulnerabilities in the Simple File Upload (mod_simplefileuploadv1.3) module before 1.3.5 for Joomla! allow remote attackers to execute arbitrary code by uploading a file with a (1) php5, (2) php6, or (3) double (e.g. .php.jpg) extension, then accessing it via a direct request to the file in images/, as exploited in the wild in January 2012.
Affected products
- Wasen Mod Simplefileupload: up to and including 1.3; version 1.0 only; version 1.1 only
Published 2012-08-31. Last modified 2026-06-16.