High severity8.8NVD Advisory· Published Nov 13, 2019· Updated Jun 17, 2026
CVE-2014-1214
CVE-2014-1214
Description
views/upload.php in the ProJoom Smart Flash Header (NovaSFH) component 3.0.2 and earlier for Joomla! allows remote attackers to upload and execute arbitrary files via a crafted (1) dest parameter and (2) arbitrary extension in the Filename parameter.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:projoom:smart_flash_header:*:*:*:*:*:joomla\!:*:*+ 1 more
- cpe:2.3:a:projoom:smart_flash_header:*:*:*:*:*:joomla\!:*:*range: <=3.0.2
- (no CPE)range: <=3.0.2
- Joomla!/Smart Flash Header (NovaSFH) componentdescription
Patches
Vulnerability mechanics
References
2- www.portcullis-security.com/security-research-and-downloads/security-advisories/cve-2014-1214/nvdExploitThird Party Advisory
- exchange.xforce.ibmcloud.com/vulnerabilities/91020nvdThird Party AdvisoryVDB Entry
News mentions
0No linked articles in our index yet.