SECUNIA ADVISORY ID: SA41680 VERIFY ADVISORY: Secunia.com http://secunia.com/advisories/41680/ Customer Area (Credentials Required) https://ca.secunia.com/?page=viewadvisory&vuln_id=41680 RELEASE DATE: 2010-10-05DESCRIPTION: A vulnerability has been reported in the JomSocial component for Joomla!, which can be exploited by malicious users to compromise a vulnerable system. The vulnerability is caused due to the application allowing the upload of files with arbitrary extensions to a folder inside the webroot. This can be exploited to execute arbitrary PHP code by uploading a PHP file. Successful exploitation of this vulnerability requires that direct video uploads are enabled and may require that directory listings are enabled to access the uploaded file. The vulnerability is reported in version 1.8.8. Prior versions may also be affected. SOLUTION: Reportedly, an update to version 1.8.9 fixes the vulnerability. PROVIDED AND/OR DISCOVERED BY: Jeff Channell ORIGINAL ADVISORY: JomSocial: http://www.jomsocial.com/docs/Change_Log#Version_1.8.9