The file scanning mechanism of JFilterInput::isFileSafe() in Joomla! CMS before 3.6.5 does not consider alternative PHP file extensions when checking uploaded files for PHP content, which enables a user to upload and execute files with the `.php6`, `.php7`, `.phtml`, and `.phpt` extensions. Additionally, JHelperMedia::canUpload() did not blacklist these file extensions as uploadable file types.
We have discovered 273,630 live websites that are affected by CVE-2016-9836.
Product | |
Category | Content Management System |
Vulnerable Domains | 273,630 live websites (98.51% of Joomla install base) |
Vulnerable Versions |
|
Vulnerable Versions Count | 62 versions ( 36.90% of all versions) |
![]() | 16,292 websites |
![]() | 66,613 websites |
![]() | 24,828 websites |
![]() | 16,750 websites |
![]() | 14,450 websites |
![]() | 14,418 websites |
![]() | 12,826 websites |
![]() | 11,568 websites |
![]() | 9,246 websites |
![]() | 8,925 websites |
.com | 66,701 websites |
.it | 43,763 websites |
.com.au | 17,070 websites |
.ru | 12,316 websites |
.pl | 9,189 websites |
.co.uk | 9,022 websites |
.org | 7,529 websites |
.de | 6,956 websites |
.nl | 6,893 websites |
.net | 5,906 websites |
Domain | Country | Rank | Contacts |
---|---|---|---|
*****************.de | ![]() | *,*** | |
*******.**.ca | ![]() | *,*** | |
**************.********.com | ![]() | **,*** | |
***********.com | ![]() | **,*** | |
***********.**.za | ![]() | **,*** | |
********.com | ![]() | **,*** | |
***************.com | ![]() | **,*** | |
********.com | ![]() | **,*** | |
*********.com | ![]() | **,*** | |
*****.**.uk | ![]() | **,*** |
FAQ