Show filters
391 Total Results
Displaying 271-280 of 391
Sort by:
Attacker Value
Unknown
CVE-2010-3712
Disclosure Date: October 28, 2010 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in Joomla! 1.5.x before 1.5.21 and 1.6.x before 1.6.1 allows remote attackers to inject arbitrary web script or HTML via vectors involving "multiple encoded entities," as demonstrated by the query string to index.php in the com_weblinks or com_content component.
0
Attacker Value
Unknown
CVE-2010-2535
Disclosure Date: October 05, 2010 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in the Back End in Joomla! 1.5.x before 1.5.20 allow remote authenticated users to inject arbitrary web script or HTML via administrator screens.
0
Attacker Value
Unknown
CVE-2010-2918
Disclosure Date: July 30, 2010 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in core/include/myMailer.class.php in the Visites (com_joomla-visites) component 1.1 RC2 for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.
0
Attacker Value
Unknown
CVE-2010-2679
Disclosure Date: July 08, 2010 (last updated October 04, 2023)
SQL injection vulnerability in the Weblinks (com_weblinks) component in Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a view action to index.php.
0
Attacker Value
Unknown
CVE-2010-1649
Disclosure Date: June 08, 2010 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in the back end in Joomla! 1.5 through 1.5.17 allow remote attackers to inject arbitrary web script or HTML via unknown vectors related to "various administrator screens," possibly the search parameter in administrator/index.php.
0
Attacker Value
Unknown
CVE-2010-1980
Disclosure Date: May 19, 2010 (last updated October 04, 2023)
Directory traversal vulnerability in joomlaflickr.php in the Joomla Flickr (com_joomlaflickr) component 1.0.3 for Joomla! allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the controller parameter to index.php.
0
Attacker Value
Unknown
CVE-2010-1307
Disclosure Date: April 08, 2010 (last updated October 04, 2023)
Directory traversal vulnerability in the Magic Updater (com_joomlaupdater) component for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.
0
Attacker Value
Unknown
CVE-2010-1306
Disclosure Date: April 08, 2010 (last updated October 04, 2023)
Directory traversal vulnerability in the Picasa (com_joomlapicasa2) component 2.0 and 2.0.5 for Joomla! allows remote attackers to read arbitrary local files via a .. (dot dot) in the controller parameter to index.php. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown
CVE-2009-3945
Disclosure Date: November 16, 2009 (last updated October 04, 2023)
Unspecified vulnerability in the Front-End Editor in the com_content component in Joomla! before 1.5.15 allows remote authenticated users, with Author privileges, to replace the articles of an arbitrary user via unknown vectors.
0
Attacker Value
Unknown
CVE-2009-3946
Disclosure Date: November 16, 2009 (last updated October 04, 2023)
Joomla! before 1.5.15 allows remote attackers to read an extension's XML file, and thereby obtain the extension's version number, via a direct request.
0