albertynos Posted March 27, 2013 Report Posted March 27, 2013 Joomla Component JCE File Upload Remote Code ExecutionThis Metasploit module exploits a vulnerability in the JCE component for Joomla!, which could allow an unauthenticated remote attacker to upload arbitrary files, caused by the fails to sufficiently sanitize user-supplied input. Sending specially-crafted HTTP request, a remote attacker could exploit this vulnerability to upload a malicious PHP script, which could allow the attacker to execute arbitrary PHP code on the vulnerable system. This Metasploit module has been tested successfully on the JCE Editor 1.5.71 and Joomla 1.5.26.Source + Download : Joomla Component JCE File Upload Remote Code Execution ? Packet Storm Quote