Vulnerability record · CVE-2013-5576 · published 9 October 2013
CVE-2013-5576: Joomla media manager file upload restriction bypass via trailing dot filename
Joomla · Joomla\!
The media manager in Joomla! 2.5.x before 2.5.14 and 3.x before 3.1.5 fails to properly validate uploaded filenames, allowing a filename with a trailing dot to bypass the dangerous-extension blocklist. This lets an attacker upload executable files to the web server, which can lead to remote code execution and full site compromise.
Description
administrator/components/com_media/helpers/media.php in the media manager in Joomla! 2.5.x before 2.5.14 and 3.x before 3.1.5 allows remote authenticated users or remote attackers to bypass intended access restrictions and upload files with dangerous extensions via a filename with a trailing . (dot), as exploited in the wild in August 2013.
AV:N/AC:M/Au:N/C:P/I:P/A:P
Automated analysis
high priorityThe flaw allows unauthenticated remote file upload leading to code execution, was exploited in the wild, and has a high EPSS score despite a medium CVSS base score.
What it is
The media manager in Joomla! 2.5.x before 2.5.14 and 3.x before 3.1.5 fails to properly validate uploaded filenames, allowing a filename with a trailing dot to bypass the dangerous-extension blocklist. This lets an attacker upload executable files to the web server, which can lead to remote code execution and full site compromise.
Impact
An attacker can upload and execute arbitrary files on the Joomla server, gaining the ability to run code with the web server's privileges and take over the site.
Attack surface
Reached remotely over the network through the media manager upload functionality; the CVSS vector indicates no authentication is required, though the description also notes remote authenticated users can exploit it. No user interaction is needed.
Exploitation
Exploited in the wild in August 2013, with a public Exploit-DB entry and patch commits available; not listed in CISA KEV, but EPSS probability is 0.48191 (98.8th percentile).
What to do
- Upgrade Joomla! to 2.5.14 or 3.1.5 (or later) immediately.
- If immediate upgrade is not possible, restrict or disable the media manager upload feature for untrusted users.
- Enforce server-side file extension allowlisting and reject filenames with trailing dots or other malformed extensions.
- Review and remove any unexpected executable files in Joomla upload directories.
- Apply the referenced Joomla patch commits if maintaining a custom build.
Detection
- Monitor web server logs for upload requests to com_media with filenames ending in a dot or containing suspicious extensions.
- Scan Joomla upload directories for newly created executable files (e.g., .php, .phtml, .php5) or files with trailing dots.
- Alert on outbound connections or process creation from the web server user that may indicate uploaded shell execution.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2013-5576 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2013-5576), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.