Vulnerability Description
Akeeba Restore (restore.php), as used in Joomla! 2.5.4 through 2.5.25, 3.x through 3.2.5, and 3.3.0 through 3.3.4; Akeeba Backup for Joomla! Professional 3.0.0 through 4.0.2; Backup Professional for WordPress 1.0.b1 through 1.1.3; Solo 1.0.b1 through 1.1.2; Admin Tools Core and Professional 2.0.0 through 2.4.4; and CMS Update 1.0.a1 through 1.0.1, when performing a backup or update for an archive, does not delete parameters from $_GET and $_POST when it is cleansing $_REQUEST, but later accesses $_GET and $_POST using the getQueryParam function, which allows remote attackers to bypass encryption and execute arbitrary code via a command message that extracts a crafted archive.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Joomla | Joomla\! | 2.5.4 |
Related Weaknesses (CWE)
References
- http://developer.joomla.org/security/595-20140903-core-remote-file-inclusion.htmVendor Advisory
- http://websec.wordpress.com/2014/10/05/joomla-3-3-4-akeeba-kickstart-remote-codeExploit
- https://www.akeebabackup.com/home/news/1605-security-update-sep-2014.htmlVendor Advisory
- http://developer.joomla.org/security/595-20140903-core-remote-file-inclusion.htmVendor Advisory
- http://websec.wordpress.com/2014/10/05/joomla-3-3-4-akeeba-kickstart-remote-codeExploit
- https://www.akeebabackup.com/home/news/1605-security-update-sep-2014.htmlVendor Advisory
FAQ
What is CVE-2014-7228?
CVE-2014-7228 is a vulnerability with a CVSS score of 7.5 (HIGH). Akeeba Restore (restore.php), as used in Joomla! 2.5.4 through 2.5.25, 3.x through 3.2.5, and 3.3.0 through 3.3.4; Akeeba Backup for Joomla! Professional 3.0.0 through 4.0.2; Backup Professional for W...
How severe is CVE-2014-7228?
CVE-2014-7228 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2014-7228?
Check the references section above for vendor advisories and patch information. Affected products include: Joomla Joomla\!.