Show filters
55 Total Results
Displaying 41-50 of 55
Sort by:
Attacker Value
Unknown
CVE-2007-6645
Disclosure Date: January 04, 2008 (last updated October 04, 2023)
Unspecified vulnerability in Joomla! before 1.5 RC4 allows remote authenticated users to gain privileges via unspecified vectors, aka "registered user privilege escalation vulnerability."
0
Attacker Value
Unknown
CVE-2007-6644
Disclosure Date: January 04, 2008 (last updated October 04, 2023)
Joomla! before 1.5 RC4 allows remote authenticated administrators to promote arbitrary users to the administrator group, in violation of the intended security model.
0
Attacker Value
Unknown
CVE-2007-6643
Disclosure Date: January 04, 2008 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in the com_poll component in Joomla! before 1.5 RC4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown
CVE-2007-6642
Disclosure Date: January 04, 2008 (last updated October 04, 2023)
Multiple cross-site request forgery (CSRF) vulnerabilities in Joomla! before 1.5 RC4 allow remote attackers to (1) add a Super Admin, (2) upload an extension containing arbitrary PHP code, and (3) modify the configuration as administrators via unspecified vectors.
0
Attacker Value
Unknown
CVE-2007-6272
Disclosure Date: December 07, 2007 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in index.php in Joomla! 1.5 RC3 allow remote attackers to execute arbitrary SQL commands via (1) the view parameter to the com_content component, (2) the task parameter to the com_search component, or (3) the option parameter in a search action to the com_search component.
0
Attacker Value
Unknown
CVE-2007-4777
Disclosure Date: September 10, 2007 (last updated October 04, 2023)
SQL injection vulnerability in Joomla! 1.5 before RC2 (aka Endeleo) allows remote attackers to execute arbitrary SQL commands via unspecified vectors, probably related to the archive section. NOTE: this may be the same as CVE-2007-4778.
0
Attacker Value
Unknown
CVE-2007-4778
Disclosure Date: September 10, 2007 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in the content component (com_content) in Joomla! 1.5 Beta1, Beta2, and RC1 allow remote attackers to execute arbitrary SQL commands via the filter parameter in an archive action to (1) archive.php, (2) category.php, or (3) section.php in models/. NOTE: this may be the same as CVE-2007-4777.
0
Attacker Value
Unknown
CVE-2007-4780
Disclosure Date: September 10, 2007 (last updated October 04, 2023)
Joomla! 1.5 before RC2 (aka Endeleo) allows remote attackers to obtain sensitive information (the full path) via unspecified vectors, probably involving direct requests to certain PHP scripts in tmpl/ directories.
0
Attacker Value
Unknown
CVE-2007-4779
Disclosure Date: September 10, 2007 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in Joomla! 1.5 before RC2 (aka Endeleo) allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, probably related to the archive section.
0
Attacker Value
Unknown
CVE-2007-4781
Disclosure Date: September 10, 2007 (last updated October 04, 2023)
administrator/index.php in the installer component (com_installer) in Joomla! 1.5 Beta1, Beta2, and RC1 allows remote authenticated administrators to upload arbitrary files to tmp/ via the "Upload Package File" functionality, which is accessible when com_installer is the value of the option parameter.
0