Show filters
391 Total Results
Displaying 291-300 of 391
Sort by:
Attacker Value
Unknown
CVE-2008-6068
Disclosure Date: February 10, 2009 (last updated October 04, 2023)
SQL injection vulnerability in the JoomlaDate (com_joomladate) component 1.2 for Joomla! allows remote attackers to execute arbitrary SQL commands via the user parameter in a viewProfile action to index.php.
0
Attacker Value
Unknown
CVE-2008-4122
Disclosure Date: December 19, 2008 (last updated January 26, 2024)
Joomla! 1.5.8 does not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.
0
Attacker Value
Unknown
CVE-2008-5671
Disclosure Date: December 19, 2008 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in index.php in Joomla! 1.0.11 through 1.0.14, when RG_EMULATION is enabled in configuration.php, allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.
0
Attacker Value
Unknown
CVE-2008-4105
Disclosure Date: September 18, 2008 (last updated October 04, 2023)
JRequest in Joomla! 1.5 before 1.5.7 does not sanitize variables that were set with JRequest::setVar, which allows remote attackers to conduct "variable injection" attacks and have unspecified other impact.
0
Attacker Value
Unknown
CVE-2008-4104
Disclosure Date: September 18, 2008 (last updated October 04, 2023)
Multiple open redirect vulnerabilities in Joomla! 1.5 before 1.5.7 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a "passed in" URL.
0
Attacker Value
Unknown
CVE-2008-4102
Disclosure Date: September 18, 2008 (last updated October 04, 2023)
Joomla! 1.5 before 1.5.7 initializes PHP's PRNG with a weak seed, which makes it easier for attackers to guess the pseudo-random values produced by PHP's mt_rand function, as demonstrated by guessing password reset tokens, a different vulnerability than CVE-2008-3681.
0
Attacker Value
Unknown
CVE-2008-3227
Disclosure Date: July 18, 2008 (last updated October 04, 2023)
Unspecified vulnerability in Joomla! before 1.5.4 has unknown impact and attack vectors related to a "User Redirect Spam fix," possibly an open redirect vulnerability.
0
Attacker Value
Unknown
CVE-2008-3225
Disclosure Date: July 18, 2008 (last updated October 04, 2023)
Joomla! before 1.5.4 allows attackers to access administration functionality, which has unknown impact and attack vectors related to a missing "LDAP security fix."
0
Attacker Value
Unknown
CVE-2008-3228
Disclosure Date: July 18, 2008 (last updated October 04, 2023)
Joomla! before 1.5.4 does not configure .htaccess to apply certain security checks that "block common exploits" to SEF URLs, which has unknown impact and remote attack vectors.
0
Attacker Value
Unknown
CVE-2008-3226
Disclosure Date: July 18, 2008 (last updated October 04, 2023)
The file caching implementation in Joomla! before 1.5.4 allows attackers to access cached pages via unknown attack vectors.
0