Tiny browser in TinyMCE 3.0 editor in Joomla! before 1.5.13 allows file upload and arbitrary PHP code execution.
Joomla
Exploit
CVE-2011-4906
NVD
Refer to CVE-2011-4906 NVD advisory