Show filters
34 Total Results
Displaying 31-34 of 34
Sort by:
Attacker Value
Unknown

CVE-2008-6299

Disclosure Date: February 26, 2009 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in Joomla! 1.5.7 and earlier allow remote authenticated users with certain privileges to inject arbitrary web script or HTML via (1) the title and description parameters to the com_weblinks module and (2) unspecified vectors in the com_content module related to "article submission."
0
Attacker Value
Unknown

CVE-2008-4105

Disclosure Date: September 18, 2008 (last updated October 04, 2023)
JRequest in Joomla! 1.5 before 1.5.7 does not sanitize variables that were set with JRequest::setVar, which allows remote attackers to conduct "variable injection" attacks and have unspecified other impact.
0
Attacker Value
Unknown

CVE-2008-4104

Disclosure Date: September 18, 2008 (last updated October 04, 2023)
Multiple open redirect vulnerabilities in Joomla! 1.5 before 1.5.7 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a "passed in" URL.
0
Attacker Value
Unknown

CVE-2008-4102

Disclosure Date: September 18, 2008 (last updated October 04, 2023)
Joomla! 1.5 before 1.5.7 initializes PHP's PRNG with a weak seed, which makes it easier for attackers to guess the pseudo-random values produced by PHP's mt_rand function, as demonstrated by guessing password reset tokens, a different vulnerability than CVE-2008-3681.
0