Show filters
391 Total Results
Displaying 231-240 of 391
Sort by:
Attacker Value
Unknown
CVE-2013-1453
Disclosure Date: February 13, 2013 (last updated October 05, 2023)
plugins/system/highlight/highlight.php in Joomla! 3.0.x through 3.0.2 and 2.5.x through 2.5.8 allows attackers to unserialize arbitrary PHP objects to obtain sensitive information, delete arbitrary directories, conduct SQL injection attacks, and possibly have other impacts via the highlight parameter. Note: it was originally reported that this issue only allowed attackers to obtain sensitive information, but later analysis demonstrated that other attacks exist.
0
Attacker Value
Unknown
CVE-2013-1454
Disclosure Date: February 13, 2013 (last updated October 05, 2023)
Joomla! 3.0.x through 3.0.2 allows attackers to obtain sensitive information via unspecified vectors related to "Coding errors."
0
Attacker Value
Unknown
CVE-2012-1599
Disclosure Date: December 03, 2012 (last updated October 05, 2023)
Joomla! 1.5.x before 1.5.26 does not properly check permissions, which allows attackers to obtain sensitive "administrative back end information" via unknown vectors. NOTE: this might be a duplicate of CVE-2012-1611.
0
Attacker Value
Unknown
CVE-2012-1598
Disclosure Date: December 03, 2012 (last updated October 05, 2023)
Joomla! 1.5.x before 1.5.26 has unspecified impact and attack vectors related to "insufficient randomness" and a "password reset vulnerability."
0
Attacker Value
Unknown
CVE-2012-5827
Disclosure Date: November 11, 2012 (last updated October 05, 2023)
Joomla! 2.5.x before 2.5.8 and 3.0.x before 3.0.2 allows remote attackers to conduct clickjacking attacks via unspecified vectors involving "Inadequate protection."
0
Attacker Value
Unknown
CVE-2012-4532
Disclosure Date: October 31, 2012 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in modules/mod_languages/tmpl/default.php in the Language Switcher module for Joomla! 2.5.x before 2.5.7 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to index.php. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown
CVE-2012-4531
Disclosure Date: October 31, 2012 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in Joomla! 2.5.x before 2.5.7 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown
CVE-2012-5455
Disclosure Date: October 22, 2012 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in the language search component in Joomla! before 3.0.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, related to a "typographical error."
0
Attacker Value
Unknown
CVE-2011-4909
Disclosure Date: October 07, 2012 (last updated October 05, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in Joomla! before 1.5.12 allow remote attackers to inject arbitrary web script or HTML via the HTTP_REFERER header to (1) components/com_content/views/article/tmpl/form.php, (2) components/com_user/controller.php, (3) plugins/system/legacy/html.php, or (4) templates/beez/html/com_content/article/form.php.
0
Attacker Value
Unknown
CVE-2011-4911
Disclosure Date: October 07, 2012 (last updated October 05, 2023)
Joomla! before 1.5.12 does not perform a JEXEC check in unspecified files, which allows remote attackers to obtain the installation path via unspecified vectors.
0