Show filters
391 Total Results
Displaying 271-280 of 391
Sort by:
Attacker Value
Unknown

CVE-2010-3712

Disclosure Date: October 28, 2010 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in Joomla! 1.5.x before 1.5.21 and 1.6.x before 1.6.1 allows remote attackers to inject arbitrary web script or HTML via vectors involving "multiple encoded entities," as demonstrated by the query string to index.php in the com_weblinks or com_content component.
0
Attacker Value
Unknown

CVE-2010-2535

Disclosure Date: October 05, 2010 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in the Back End in Joomla! 1.5.x before 1.5.20 allow remote authenticated users to inject arbitrary web script or HTML via administrator screens.
0
Attacker Value
Unknown

CVE-2010-2918

Disclosure Date: July 30, 2010 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in core/include/myMailer.class.php in the Visites (com_joomla-visites) component 1.1 RC2 for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.
0
Attacker Value
Unknown

CVE-2010-2679

Disclosure Date: July 08, 2010 (last updated October 04, 2023)
SQL injection vulnerability in the Weblinks (com_weblinks) component in Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a view action to index.php.
0
Attacker Value
Unknown

CVE-2010-1649

Disclosure Date: June 08, 2010 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in the back end in Joomla! 1.5 through 1.5.17 allow remote attackers to inject arbitrary web script or HTML via unknown vectors related to "various administrator screens," possibly the search parameter in administrator/index.php.
0
Attacker Value
Unknown

CVE-2010-1980

Disclosure Date: May 19, 2010 (last updated October 04, 2023)
Directory traversal vulnerability in joomlaflickr.php in the Joomla Flickr (com_joomlaflickr) component 1.0.3 for Joomla! allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the controller parameter to index.php.
0
Attacker Value
Unknown

CVE-2010-1307

Disclosure Date: April 08, 2010 (last updated October 04, 2023)
Directory traversal vulnerability in the Magic Updater (com_joomlaupdater) component for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.
0
Attacker Value
Unknown

CVE-2010-1306

Disclosure Date: April 08, 2010 (last updated October 04, 2023)
Directory traversal vulnerability in the Picasa (com_joomlapicasa2) component 2.0 and 2.0.5 for Joomla! allows remote attackers to read arbitrary local files via a .. (dot dot) in the controller parameter to index.php. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown

CVE-2009-3945

Disclosure Date: November 16, 2009 (last updated October 04, 2023)
Unspecified vulnerability in the Front-End Editor in the com_content component in Joomla! before 1.5.15 allows remote authenticated users, with Author privileges, to replace the articles of an arbitrary user via unknown vectors.
0
Attacker Value
Unknown

CVE-2009-3946

Disclosure Date: November 16, 2009 (last updated October 04, 2023)
Joomla! before 1.5.15 allows remote attackers to read an extension's XML file, and thereby obtain the extension's version number, via a direct request.
0