Show filters
21 Total Results
Displaying 1-10 of 21
Sort by:
Attacker Value
Unknown
CVE-2017-11364
Disclosure Date: August 02, 2017 (last updated November 26, 2024)
The CMS installer in Joomla! before 3.7.4 does not verify a user's ownership of a webspace, which allows remote authenticated users to gain control of the target application by leveraging Certificate Transparency logs.
0
Attacker Value
Unknown
CVE-2008-6299
Disclosure Date: February 26, 2009 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in Joomla! 1.5.7 and earlier allow remote authenticated users with certain privileges to inject arbitrary web script or HTML via (1) the title and description parameters to the com_weblinks module and (2) unspecified vectors in the com_content module related to "article submission."
0
Attacker Value
Unknown
CVE-2008-3227
Disclosure Date: July 18, 2008 (last updated October 04, 2023)
Unspecified vulnerability in Joomla! before 1.5.4 has unknown impact and attack vectors related to a "User Redirect Spam fix," possibly an open redirect vulnerability.
0
Attacker Value
Unknown
CVE-2008-3225
Disclosure Date: July 18, 2008 (last updated October 04, 2023)
Joomla! before 1.5.4 allows attackers to access administration functionality, which has unknown impact and attack vectors related to a missing "LDAP security fix."
0
Attacker Value
Unknown
CVE-2008-3228
Disclosure Date: July 18, 2008 (last updated October 04, 2023)
Joomla! before 1.5.4 does not configure .htaccess to apply certain security checks that "block common exploits" to SEF URLs, which has unknown impact and remote attack vectors.
0
Attacker Value
Unknown
CVE-2008-3226
Disclosure Date: July 18, 2008 (last updated October 04, 2023)
The file caching implementation in Joomla! before 1.5.4 allows attackers to access cached pages via unknown attack vectors.
0
Attacker Value
Unknown
CVE-2008-1935
Disclosure Date: April 25, 2008 (last updated October 04, 2023)
SQL injection vulnerability in the Filiale 1.0.4 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the idFiliale parameter.
0
Attacker Value
Unknown
CVE-2006-7009
Disclosure Date: February 12, 2007 (last updated October 04, 2023)
Joomla! before 1.0.10 allows remote attackers to spoof the frontend submission forms, which has unknown impact and attack vectors.
0
Attacker Value
Unknown
CVE-2006-7010
Disclosure Date: February 12, 2007 (last updated October 04, 2023)
The mosgetparam implementation in Joomla! before 1.0.10, does not set a variable's data type to integer when the variable's default value is numeric, which has unspecified impact and attack vectors, which may permit SQL injection attacks.
0
Attacker Value
Unknown
CVE-2006-7008
Disclosure Date: February 12, 2007 (last updated October 04, 2023)
Unspecified vulnerability in Joomla! before 1.0.10 has unknown impact and attack vectors, related to "securing mosmsg from misuse." NOTE: it is possible that this issue overlaps CVE-2006-1029.
0