TinyBrowser plugin for Joomla! before 1.5.13 allows arbitrary file upload via upload.php.
Joomla
Exploit
CVE-2011-4908
NVD
Refer to CVE-2011-4908 NVD advisory