Show filters
27 Total Results
Displaying 1-10 of 27
Sort by:
Attacker Value
Unknown

CVE-2017-11364

Disclosure Date: August 02, 2017 (last updated November 26, 2024)
The CMS installer in Joomla! before 3.7.4 does not verify a user's ownership of a webspace, which allows remote authenticated users to gain control of the target application by leveraging Certificate Transparency logs.
0
Attacker Value
Unknown

CVE-2008-6299

Disclosure Date: February 26, 2009 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in Joomla! 1.5.7 and earlier allow remote authenticated users with certain privileges to inject arbitrary web script or HTML via (1) the title and description parameters to the com_weblinks module and (2) unspecified vectors in the com_content module related to "article submission."
0
Attacker Value
Unknown

CVE-2008-5671

Disclosure Date: December 19, 2008 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in index.php in Joomla! 1.0.11 through 1.0.14, when RG_EMULATION is enabled in configuration.php, allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.
0
Attacker Value
Unknown

CVE-2008-3227

Disclosure Date: July 18, 2008 (last updated October 04, 2023)
Unspecified vulnerability in Joomla! before 1.5.4 has unknown impact and attack vectors related to a "User Redirect Spam fix," possibly an open redirect vulnerability.
0
Attacker Value
Unknown

CVE-2008-3225

Disclosure Date: July 18, 2008 (last updated October 04, 2023)
Joomla! before 1.5.4 allows attackers to access administration functionality, which has unknown impact and attack vectors related to a missing "LDAP security fix."
0
Attacker Value
Unknown

CVE-2008-3228

Disclosure Date: July 18, 2008 (last updated October 04, 2023)
Joomla! before 1.5.4 does not configure .htaccess to apply certain security checks that "block common exploits" to SEF URLs, which has unknown impact and remote attack vectors.
0
Attacker Value
Unknown

CVE-2008-3226

Disclosure Date: July 18, 2008 (last updated October 04, 2023)
The file caching implementation in Joomla! before 1.5.4 allows attackers to access cached pages via unknown attack vectors.
0
Attacker Value
Unknown

CVE-2008-2564

Disclosure Date: June 06, 2008 (last updated October 04, 2023)
SQL injection vulnerability in the JotLoader (com_jotloader) component 1.2.1.a and earlier for Joomla! allows remote attackers to execute arbitrary SQL commands via the cid parameter to index.php.
0
Attacker Value
Unknown

CVE-2008-0517

Disclosure Date: January 31, 2008 (last updated October 04, 2023)
SQL injection vulnerability in index.php in the Darko Selesi EstateAgent (com_estateagent) 0.1 component for Mambo 4.5.x and Joomla! allows remote attackers to execute arbitrary SQL commands via the objid parameter in a contact showObject action.
0
Attacker Value
Unknown

CVE-2007-4185

Disclosure Date: August 08, 2007 (last updated October 04, 2023)
Joomla! 1.0.12 allows remote attackers to obtain sensitive information via a direct request for (1) Stat.php (2) OutputFilter.php, (3) OutputCache.php, (4) Modifier.php, (5) Reader.php, and (6) TemplateCache.php in includes/patTemplate/patTemplate/; (7) includes/Cache/Lite/Output.php; and other unspecified components, which reveal the path in various error messages.
0