Description
An issue was discovered in Joomla! 3.0.0 through 3.9.24. Extracting an specifilcy crafted zip package could write files outside of the intended path.
Remediation
References
Related Vulnerabilities
e107 Other Vulnerability (CVE-2005-1949)
WordPress Plugin Automattic Stats Referer Field HTML Injection (1.0)
WebLogic CVE-2017-10148 Vulnerability (CVE-2017-10148)
WordPress Plugin Spreadsheet (wpSS) 'ss_id' Parameter SQL Injection (0.61)
WordPress Plugin ActiveCampaign-Forms, Site Tracking, Live Chat Unspecified Vulnerability (5.7)