VYPR
Unrated severityNVD Advisory· Published Jan 9, 2006· Updated Jun 16, 2026

CVE-2006-0114

CVE-2006-0114

Description

The vCard functions in Joomla! 1.0.5 use predictable sequential IDs for vcards and do not restrict access to them, which allows remote attackers to obtain valid e-mail addresses to conduct spam attacks by modifying the contact_id parameter to index2.php.

Affected products

2
  • Joomla/Joomla!2 versions
    cpe:2.3:a:joomla:joomla:1.0.5:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:joomla:joomla:1.0.5:*:*:*:*:*:*:*
    • (no CPE)range: = 1.0.5

Patches

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

7

News mentions

0

No linked articles in our index yet.