Vulnerability record · CVE-2011-4908 · published 12 February 2020
CVE-2011-4908: TinyBrowser Joomla plugin unrestricted file upload
Tiny · Tinybrowser
The TinyBrowser plugin for Joomla! before 1.5.13 exposes upload.php without restricting uploaded file types, allowing arbitrary file uploads. Because the endpoint is reachable over the network with no authentication or user interaction, an attacker can place executable content on the server. This is a critical-severity flaw in an end-of-life Joomla component.
Description
TinyBrowser plugin for Joomla! before 1.5.13 allows arbitrary file upload via upload.php.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated remote arbitrary file upload with a CVSS of 9.8 and public exploit code makes full server compromise likely.
What it is
The TinyBrowser plugin for Joomla! before 1.5.13 exposes upload.php without restricting uploaded file types, allowing arbitrary file uploads. Because the endpoint is reachable over the network with no authentication or user interaction, an attacker can place executable content on the server. This is a critical-severity flaw in an end-of-life Joomla component.
Impact
An attacker can upload arbitrary files, including web shells, and execute them on the host, leading to full compromise of the Joomla site and potentially the underlying server.
Attack surface
Reached remotely over HTTP through the plugin's upload.php endpoint. The CVSS vector shows no privileges required and no user interaction, so the upload path is directly accessible to unauthenticated attackers.
Exploitation
Not listed in CISA KEV, but EPSS is 0.55769 (99th percentile) and public Exploit-DB and mailing-list references exist, indicating known exploit code and active interest.
What to do
- Upgrade or remove the TinyBrowser plugin; Joomla! 1.5.13 or later is required per the advisory.
- If the plugin cannot be removed, block or restrict access to upload.php at the web server or WAF.
- Disable file uploads in the plugin and audit the upload directory for unexpected files.
- Run the Joomla site with least privilege and keep the web root non-executable for uploaded content.
- Monitor for and remove any web shells or unexpected executable files already present.
Detection
- Review web server logs for POST requests to TinyBrowser upload.php, especially from unauthenticated clients.
- Alert on new executable files (php, phtml, jsp, etc.) appearing in upload or media directories.
- Scan the filesystem for web shells and compare against known-good file hashes.
- Monitor outbound connections from the web server that may indicate post-exploitation activity.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://vulmon.com/vulnerabilitydetails?qid=CVE-2011-4908 | Third Party Advisory |
| https://www.exploit-db.com/exploits/9926 | ExploitThird Party AdvisoryVDB Entry |
| https://www.openwall.com/lists/oss-security/2011/12/25/7 | Mailing ListThird Party Advisory |
| https://vulmon.com/vulnerabilitydetails?qid=CVE-2011-4908 | Third Party Advisory |
| https://www.exploit-db.com/exploits/9926 | ExploitThird Party AdvisoryVDB Entry |
| https://www.openwall.com/lists/oss-security/2011/12/25/7 | Mailing ListThird Party Advisory |
Track CVE-2011-4908 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2011-4908), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.