Show filters
33 Total Results
Displaying 31-33 of 33
Sort by:
Attacker Value
Unknown
CVE-2008-4105
Disclosure Date: September 18, 2008 (last updated October 04, 2023)
JRequest in Joomla! 1.5 before 1.5.7 does not sanitize variables that were set with JRequest::setVar, which allows remote attackers to conduct "variable injection" attacks and have unspecified other impact.
0
Attacker Value
Unknown
CVE-2008-4104
Disclosure Date: September 18, 2008 (last updated October 04, 2023)
Multiple open redirect vulnerabilities in Joomla! 1.5 before 1.5.7 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a "passed in" URL.
0
Attacker Value
Unknown
CVE-2008-4102
Disclosure Date: September 18, 2008 (last updated October 04, 2023)
Joomla! 1.5 before 1.5.7 initializes PHP's PRNG with a weak seed, which makes it easier for attackers to guess the pseudo-random values produced by PHP's mt_rand function, as demonstrated by guessing password reset tokens, a different vulnerability than CVE-2008-3681.
0