Joomla!
by Joomla
Source repositories
CVEs (418)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2007-4185 | 0.00 | — | 0.02 | Aug 8, 2007 | Joomla! 1.0.12 allows remote attackers to obtain sensitive information via a direct request for (1) Stat.php (2) OutputFilter.php, (3) OutputCache.php, (4) Modifier.php, (5) Reader.php, and (6) TemplateCache.php in includes/patTemplate/patTemplate/; (7)… | |||
| CVE-2007-4188 | 0.00 | — | 0.04 | Aug 8, 2007 | Session fixation vulnerability in Joomla! before 1.0.13 (aka Sunglow) allows remote attackers to hijack administrative web sessions via unspecified vectors. | |||
| CVE-2006-7010 | 0.00 | — | 0.01 | Feb 12, 2007 | The mosgetparam implementation in Joomla! before 1.0.10, does not set a variable's data type to integer when the variable's default value is numeric, which has unspecified impact and attack vectors, which may permit SQL injection attacks. | |||
| CVE-2006-7008 | 0.00 | — | 0.01 | Feb 12, 2007 | Unspecified vulnerability in Joomla! before 1.0.10 has unknown impact and attack vectors, related to "securing mosmsg from misuse." NOTE: it is possible that this issue overlaps CVE-2006-1029. | |||
| CVE-2006-7009 | 0.00 | — | 0.01 | Feb 12, 2007 | Joomla! before 1.0.10 allows remote attackers to spoof the frontend submission forms, which has unknown impact and attack vectors. | |||
| CVE-2007-0375 | 0.00 | — | 0.02 | Jan 19, 2007 | Joomla! 1.5.0 Beta allows remote attackers to obtain sensitive information via a direct request for (1) plugins/user/example.php; (2) gmail.php, (3) example.php, or (4) ldap.php in plugins/authentication/; (5) modules/mod_mainmenu/menu.php; or other unspecified PHP scripts,… | |||
| CVE-2007-0387 | 0.00 | — | 0.01 | Jan 19, 2007 | SQL injection vulnerability in models/category.php in the Weblinks component for Joomla! SVN 20070118 (com_weblinks) allows remote attackers to execute arbitrary SQL commands via the catid parameter. | |||
| CVE-2007-0374 | 0.00 | — | 0.01 | Jan 19, 2007 | SQL injection vulnerability in (1) Joomla! 1.0.11 and 1.5 Beta, and (2) Mambo 4.6.1, allows remote attackers to execute arbitrary SQL commands via the id parameter when cancelling content editing. | |||
| CVE-2006-6832 | 0.00 | — | 0.01 | Dec 31, 2006 | Cross-site scripting (XSS) vulnerability in Joomla! before 1.0.12 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, possibly related to poll.php or the module title. | |||
| CVE-2006-6833 | 0.00 | — | 0.01 | Dec 31, 2006 | com_categories in Joomla! before 1.0.12 does not validate input, which has unknown impact and remote attack vectors. | |||
| CVE-2006-6834 | 0.00 | — | 0.01 | Dec 31, 2006 | Multiple unspecified vulnerabilities in Joomla! before 1.0.12 have unknown impact and attack vectors related to (1) "unneeded legacy functions" and (2) "Several low level security fixes." | |||
| CVE-2006-4470 | 0.00 | — | 0.03 | Aug 31, 2006 | Joomla! before 1.0.11 omits some checks for whether _VALID_MOS is defined, which allows attackers to have an unknown impact, possibly resulting in PHP remote file inclusion. | |||
| CVE-2006-4472 | 0.00 | — | 0.03 | Aug 31, 2006 | Multiple unspecified vulnerabilities in Joomla! before 1.0.11 allow attackers to bypass user authentication via unknown vectors involving the (1) do_pdf command and the (2) emailform com_content task. | |||
| CVE-2006-4468 | 0.00 | — | 0.02 | Aug 31, 2006 | Multiple unspecified vulnerabilities in Joomla! before 1.0.11, related to unvalidated input, allow attackers to have an unknown impact via unspecified vectors involving the (1) mosMail, (2) JosIsValidEmail, and (3) josSpoofValue functions; (4) the lack of inclusion of… | |||
| CVE-2006-4469 | 0.00 | — | 0.04 | Aug 31, 2006 | Unspecified vulnerability in PEAR.php in Joomla! before 1.0.11 allows remote attackers to perform "remote execution," related to "Injection Flaws." | |||
| CVE-2006-4475 | 0.00 | — | 0.01 | Aug 31, 2006 | Joomla! before 1.0.11 does not limit access to the Admin Popups functionality, which has unknown impact and attack vectors. | |||
| CVE-2006-4466 | 0.00 | — | 0.01 | Aug 31, 2006 | Joomla! before 1.0.11 does not properly unset variables when the input data includes a numeric parameter with a value matching an alphanumeric parameter's hash value, which allows remote attackers to have an unspecified impact. NOTE: it could be argued that this vulnerability… | |||
| CVE-2006-4473 | 0.00 | — | 0.01 | Aug 31, 2006 | Unspecified vulnerability in com_content in Joomla! before 1.0.11, when $mosConfig_hideEmail is set, allows attackers to perform the emailform and emailsend tasks. | |||
| CVE-2006-4471 | 0.00 | — | 0.02 | Aug 31, 2006 | The Admin Upload Image functionality in Joomla! before 1.0.11 allows remote authenticated users to upload files outside of the /images/stories/ directory via unspecified vectors. | |||
| CVE-2006-4474 | 0.00 | — | 0.01 | Aug 31, 2006 | Multiple cross-site scripting (XSS) vulnerabilities in Joomla! before 1.0.11 allow remote attackers to inject arbitrary web script or HTML via unspecified parameters in (1) Admin Module Manager, (2) Admin Help, and (3) Search. |
- CVE-2007-4185Aug 8, 2007risk 0.00cvss —epss 0.02
Joomla! 1.0.12 allows remote attackers to obtain sensitive information via a direct request for (1) Stat.php (2) OutputFilter.php, (3) OutputCache.php, (4) Modifier.php, (5) Reader.php, and (6) TemplateCache.php in includes/patTemplate/patTemplate/; (7)…
- CVE-2007-4188Aug 8, 2007risk 0.00cvss —epss 0.04
Session fixation vulnerability in Joomla! before 1.0.13 (aka Sunglow) allows remote attackers to hijack administrative web sessions via unspecified vectors.
- CVE-2006-7010Feb 12, 2007risk 0.00cvss —epss 0.01
The mosgetparam implementation in Joomla! before 1.0.10, does not set a variable's data type to integer when the variable's default value is numeric, which has unspecified impact and attack vectors, which may permit SQL injection attacks.
- CVE-2006-7008Feb 12, 2007risk 0.00cvss —epss 0.01
Unspecified vulnerability in Joomla! before 1.0.10 has unknown impact and attack vectors, related to "securing mosmsg from misuse." NOTE: it is possible that this issue overlaps CVE-2006-1029.
- CVE-2006-7009Feb 12, 2007risk 0.00cvss —epss 0.01
Joomla! before 1.0.10 allows remote attackers to spoof the frontend submission forms, which has unknown impact and attack vectors.
- CVE-2007-0375Jan 19, 2007risk 0.00cvss —epss 0.02
Joomla! 1.5.0 Beta allows remote attackers to obtain sensitive information via a direct request for (1) plugins/user/example.php; (2) gmail.php, (3) example.php, or (4) ldap.php in plugins/authentication/; (5) modules/mod_mainmenu/menu.php; or other unspecified PHP scripts,…
- CVE-2007-0387Jan 19, 2007risk 0.00cvss —epss 0.01
SQL injection vulnerability in models/category.php in the Weblinks component for Joomla! SVN 20070118 (com_weblinks) allows remote attackers to execute arbitrary SQL commands via the catid parameter.
- CVE-2007-0374Jan 19, 2007risk 0.00cvss —epss 0.01
SQL injection vulnerability in (1) Joomla! 1.0.11 and 1.5 Beta, and (2) Mambo 4.6.1, allows remote attackers to execute arbitrary SQL commands via the id parameter when cancelling content editing.
- CVE-2006-6832Dec 31, 2006risk 0.00cvss —epss 0.01
Cross-site scripting (XSS) vulnerability in Joomla! before 1.0.12 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, possibly related to poll.php or the module title.
- CVE-2006-6833Dec 31, 2006risk 0.00cvss —epss 0.01
com_categories in Joomla! before 1.0.12 does not validate input, which has unknown impact and remote attack vectors.
- CVE-2006-6834Dec 31, 2006risk 0.00cvss —epss 0.01
Multiple unspecified vulnerabilities in Joomla! before 1.0.12 have unknown impact and attack vectors related to (1) "unneeded legacy functions" and (2) "Several low level security fixes."
- CVE-2006-4470Aug 31, 2006risk 0.00cvss —epss 0.03
Joomla! before 1.0.11 omits some checks for whether _VALID_MOS is defined, which allows attackers to have an unknown impact, possibly resulting in PHP remote file inclusion.
- CVE-2006-4472Aug 31, 2006risk 0.00cvss —epss 0.03
Multiple unspecified vulnerabilities in Joomla! before 1.0.11 allow attackers to bypass user authentication via unknown vectors involving the (1) do_pdf command and the (2) emailform com_content task.
- CVE-2006-4468Aug 31, 2006risk 0.00cvss —epss 0.02
Multiple unspecified vulnerabilities in Joomla! before 1.0.11, related to unvalidated input, allow attackers to have an unknown impact via unspecified vectors involving the (1) mosMail, (2) JosIsValidEmail, and (3) josSpoofValue functions; (4) the lack of inclusion of…
- CVE-2006-4469Aug 31, 2006risk 0.00cvss —epss 0.04
Unspecified vulnerability in PEAR.php in Joomla! before 1.0.11 allows remote attackers to perform "remote execution," related to "Injection Flaws."
- CVE-2006-4475Aug 31, 2006risk 0.00cvss —epss 0.01
Joomla! before 1.0.11 does not limit access to the Admin Popups functionality, which has unknown impact and attack vectors.
- CVE-2006-4466Aug 31, 2006risk 0.00cvss —epss 0.01
Joomla! before 1.0.11 does not properly unset variables when the input data includes a numeric parameter with a value matching an alphanumeric parameter's hash value, which allows remote attackers to have an unspecified impact. NOTE: it could be argued that this vulnerability…
- CVE-2006-4473Aug 31, 2006risk 0.00cvss —epss 0.01
Unspecified vulnerability in com_content in Joomla! before 1.0.11, when $mosConfig_hideEmail is set, allows attackers to perform the emailform and emailsend tasks.
- CVE-2006-4471Aug 31, 2006risk 0.00cvss —epss 0.02
The Admin Upload Image functionality in Joomla! before 1.0.11 allows remote authenticated users to upload files outside of the /images/stories/ directory via unspecified vectors.
- CVE-2006-4474Aug 31, 2006risk 0.00cvss —epss 0.01
Multiple cross-site scripting (XSS) vulnerabilities in Joomla! before 1.0.11 allow remote attackers to inject arbitrary web script or HTML via unspecified parameters in (1) Admin Module Manager, (2) Admin Help, and (3) Search.
Page 20 of 21