Show filters
30 Total Results
Displaying 1-10 of 30
Sort by:
Attacker Value
Unknown

CVE-2017-14596

Disclosure Date: September 20, 2017 (last updated November 26, 2024)
In Joomla! before 3.8.0, inadequate escaping in the LDAP authentication plugin can result in a disclosure of a username and password.
0
Attacker Value
Unknown

CVE-2017-11364

Disclosure Date: August 02, 2017 (last updated November 26, 2024)
The CMS installer in Joomla! before 3.7.4 does not verify a user's ownership of a webspace, which allows remote authenticated users to gain control of the target application by leveraging Certificate Transparency logs.
0
Attacker Value
Unknown

CVE-2017-11612

Disclosure Date: July 26, 2017 (last updated November 26, 2024)
In Joomla! before 3.7.4, inadequate filtering of potentially malicious HTML tags leads to XSS vulnerabilities in various components.
0
Attacker Value
Unknown

CVE-2017-7983

Disclosure Date: April 25, 2017 (last updated November 26, 2024)
In Joomla! 1.5.0 through 3.6.5 (fixed in 3.7.0), mail sent using the JMail API leaked the used PHPMailer version in the mail headers.
0
Attacker Value
Unknown

CVE-2017-7986

Disclosure Date: April 25, 2017 (last updated November 26, 2024)
In Joomla! 1.5.0 through 3.6.5 (fixed in 3.7.0), inadequate filtering of specific HTML attributes leads to XSS vulnerabilities in various components.
0
Attacker Value
Unknown

CVE-2015-8562

Disclosure Date: December 16, 2015 (last updated October 05, 2023)
Joomla! 1.5.x, 2.x, and 3.x before 3.4.6 allow remote attackers to conduct PHP object injection attacks and execute arbitrary PHP code via the HTTP User-Agent header, as exploited in the wild in December 2015.
0
Attacker Value
Unknown

CVE-2012-2413

Disclosure Date: October 20, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in the ja_purity template for Joomla! 1.5.26 and earlier allows remote attackers to inject arbitrary web script or HTML via the Mod* cookie parameter to html/modules.php.
0
Attacker Value
Unknown

CVE-2012-1599

Disclosure Date: December 03, 2012 (last updated October 05, 2023)
Joomla! 1.5.x before 1.5.26 does not properly check permissions, which allows attackers to obtain sensitive "administrative back end information" via unknown vectors. NOTE: this might be a duplicate of CVE-2012-1611.
0
Attacker Value
Unknown

CVE-2012-1598

Disclosure Date: December 03, 2012 (last updated October 05, 2023)
Joomla! 1.5.x before 1.5.26 has unspecified impact and attack vectors related to "insufficient randomness" and a "password reset vulnerability."
0
Attacker Value
Unknown

CVE-2011-4909

Disclosure Date: October 07, 2012 (last updated October 05, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in Joomla! before 1.5.12 allow remote attackers to inject arbitrary web script or HTML via the HTTP_REFERER header to (1) components/com_content/views/article/tmpl/form.php, (2) components/com_user/controller.php, (3) plugins/system/legacy/html.php, or (4) templates/beez/html/com_content/article/form.php.
0