Show filters
15 Total Results
Displaying 1-10 of 15
Sort by:
Attacker Value
Unknown

CVE-2009-1939

Disclosure Date: June 05, 2009 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in the JA_Purity template for Joomla! 1.5.x through 1.5.10 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown

CVE-2008-6299

Disclosure Date: February 26, 2009 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in Joomla! 1.5.7 and earlier allow remote authenticated users with certain privileges to inject arbitrary web script or HTML via (1) the title and description parameters to the com_weblinks module and (2) unspecified vectors in the com_content module related to "article submission."
0
Attacker Value
Unknown

CVE-2008-3227

Disclosure Date: July 18, 2008 (last updated October 04, 2023)
Unspecified vulnerability in Joomla! before 1.5.4 has unknown impact and attack vectors related to a "User Redirect Spam fix," possibly an open redirect vulnerability.
0
Attacker Value
Unknown

CVE-2008-3225

Disclosure Date: July 18, 2008 (last updated October 04, 2023)
Joomla! before 1.5.4 allows attackers to access administration functionality, which has unknown impact and attack vectors related to a missing "LDAP security fix."
0
Attacker Value
Unknown

CVE-2008-3228

Disclosure Date: July 18, 2008 (last updated October 04, 2023)
Joomla! before 1.5.4 does not configure .htaccess to apply certain security checks that "block common exploits" to SEF URLs, which has unknown impact and remote attack vectors.
0
Attacker Value
Unknown

CVE-2008-3226

Disclosure Date: July 18, 2008 (last updated October 04, 2023)
The file caching implementation in Joomla! before 1.5.4 allows attackers to access cached pages via unknown attack vectors.
0
Attacker Value
Unknown

CVE-2007-4777

Disclosure Date: September 10, 2007 (last updated October 04, 2023)
SQL injection vulnerability in Joomla! 1.5 before RC2 (aka Endeleo) allows remote attackers to execute arbitrary SQL commands via unspecified vectors, probably related to the archive section. NOTE: this may be the same as CVE-2007-4778.
0
Attacker Value
Unknown

CVE-2007-4778

Disclosure Date: September 10, 2007 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in the content component (com_content) in Joomla! 1.5 Beta1, Beta2, and RC1 allow remote attackers to execute arbitrary SQL commands via the filter parameter in an archive action to (1) archive.php, (2) category.php, or (3) section.php in models/. NOTE: this may be the same as CVE-2007-4777.
0
Attacker Value
Unknown

CVE-2007-4780

Disclosure Date: September 10, 2007 (last updated October 04, 2023)
Joomla! 1.5 before RC2 (aka Endeleo) allows remote attackers to obtain sensitive information (the full path) via unspecified vectors, probably involving direct requests to certain PHP scripts in tmpl/ directories.
0
Attacker Value
Unknown

CVE-2007-4779

Disclosure Date: September 10, 2007 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in Joomla! 1.5 before RC2 (aka Endeleo) allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, probably related to the archive section.
0