Joomla! before version 3.9.5 contains a directory traversal vulnerability in the Media Manager component. The folder parameter is not properly sanitized, which allows attackers to manipulate the path and access files or directories outside the intended media manager root directory.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
3 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository is a small collection of two standalone Python web exploit scripts plus a minimal README and MIT license. It is not a framework-based repository. The code files are Drupalgeddon.py and Joomla_DirTrav.py, both intended to be run directly from the command line. Drupalgeddon.py targets Drupal 7.x SA-CORE-2014-005 ('Drupalgeddon'). The script includes an embedded DrupalHash implementation to generate a valid Drupal password hash for an attacker-supplied password. It accepts target URL, username, and password arguments, normalizes the target URL, and sends a crafted POST request to the Drupal login form. The exploit abuses the vulnerable array-style name parameter to inject SQL statements that insert a new user into the users table and then grant that user administrator privileges by inserting into users_roles with rid=3. Success is inferred from a response string containing 'mb_strlen() expects parameter 1'. Main capability: unauthenticated remote admin account creation on vulnerable Drupal. Joomla_DirTrav.py targets Joomla Core 1.5.0 through 3.9.4 and explicitly references CVE-2019-10945. It uses click for CLI parsing, requests for HTTP, and lxml for HTML parsing. The script first authenticates to the Joomla administrator interface using supplied manager credentials, extracts a CSRF field from the login page, and caches the resulting session cookies in a temp file serialized with pickle. It then abuses the com_media media manager endpoint with folder=/.. traversal to enumerate files in arbitrary directories. A second function rewrites a discovered folder.delete link into file.delete and appends rm[]=<file> to delete a chosen file. Main capabilities: authenticated directory traversal for file listing and authenticated arbitrary file deletion. Notable fingerprintable artifacts include Joomla administrator paths, com_media query strings, com_login/task=login parameters, the Drupal user_login_block form identifier, and the local .Jcookie temp file naming convention. Overall, the repository's purpose is offensive proof-of-concept exploitation of two unrelated CMS vulnerabilities: one for Drupal privilege creation and one for Joomla file system abuse.
This repository contains a Python 3 exploit for CVE-2019-10945, targeting Joomla Core versions 1.5.0 through 3.9.4. The exploit leverages directory traversal and authenticated arbitrary file deletion vulnerabilities in the Joomla com_media component. The main script, 'exp.py', requires valid Joomla administrator credentials and a target URL. It can list files in arbitrary directories or delete specified files on the server by abusing crafted HTTP requests to the Joomla administrator interface. The script uses the 'click' library for command-line argument parsing and 'requests' for HTTP communication. The repository also includes a 'requirements.txt' file listing dependencies and a brief README. The exploit is operational, requiring authentication but providing real file system impact on vulnerable Joomla installations.
This repository contains a Python 3 exploit script (CVE-2019-10945.py) targeting Joomla Core versions 1.5.0 through 3.9.4, specifically exploiting CVE-2019-10945. The exploit requires valid Joomla administrator credentials and interacts with the Joomla administrator web interface. It leverages a directory traversal vulnerability in the media component to list files in arbitrary directories and, optionally, to delete arbitrary files on the server. The script uses the 'requests', 'lxml', and 'click' Python libraries for HTTP requests, HTML parsing, and command-line interface, respectively. The README documents the conversion from Python 2 to Python 3 and provides usage instructions. The LICENSE is MIT. The main entry point is CVE-2019-10945.py, which provides both file listing and deletion capabilities via command-line options. The exploit is operational and can be used to demonstrate or test the vulnerability on affected Joomla installations.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.