Show filters
8 Total Results
Displaying 1-8 of 8
Sort by:
Attacker Value
Unknown

CVE-2009-1939

Disclosure Date: June 05, 2009 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in the JA_Purity template for Joomla! 1.5.x through 1.5.10 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown

CVE-2008-6299

Disclosure Date: February 26, 2009 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in Joomla! 1.5.7 and earlier allow remote authenticated users with certain privileges to inject arbitrary web script or HTML via (1) the title and description parameters to the com_weblinks module and (2) unspecified vectors in the com_content module related to "article submission."
0
Attacker Value
Unknown

CVE-2008-3227

Disclosure Date: July 18, 2008 (last updated October 04, 2023)
Unspecified vulnerability in Joomla! before 1.5.4 has unknown impact and attack vectors related to a "User Redirect Spam fix," possibly an open redirect vulnerability.
0
Attacker Value
Unknown

CVE-2008-3225

Disclosure Date: July 18, 2008 (last updated October 04, 2023)
Joomla! before 1.5.4 allows attackers to access administration functionality, which has unknown impact and attack vectors related to a missing "LDAP security fix."
0
Attacker Value
Unknown

CVE-2008-3228

Disclosure Date: July 18, 2008 (last updated October 04, 2023)
Joomla! before 1.5.4 does not configure .htaccess to apply certain security checks that "block common exploits" to SEF URLs, which has unknown impact and remote attack vectors.
0
Attacker Value
Unknown

CVE-2008-3226

Disclosure Date: July 18, 2008 (last updated October 04, 2023)
The file caching implementation in Joomla! before 1.5.4 allows attackers to access cached pages via unknown attack vectors.
0
Attacker Value
Unknown

CVE-2007-4778

Disclosure Date: September 10, 2007 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in the content component (com_content) in Joomla! 1.5 Beta1, Beta2, and RC1 allow remote attackers to execute arbitrary SQL commands via the filter parameter in an archive action to (1) archive.php, (2) category.php, or (3) section.php in models/. NOTE: this may be the same as CVE-2007-4777.
0
Attacker Value
Unknown

CVE-2007-4781

Disclosure Date: September 10, 2007 (last updated October 04, 2023)
administrator/index.php in the installer component (com_installer) in Joomla! 1.5 Beta1, Beta2, and RC1 allows remote authenticated administrators to upload arbitrary files to tmp/ via the "Upload Package File" functionality, which is accessible when com_installer is the value of the option parameter.
0