CVE-2011-2509
Published Jul 27, 2011
Last updated a year ago
Overview
- Description
- Multiple cross-site scripting (XSS) vulnerabilities in Joomla! before 1.6.4 allow remote attackers to inject arbitrary web script or HTML via (1) the query string to the com_contact component, as demonstrated by the Itemid parameter to index.php; (2) the query string to the com_content component, as demonstrated by the filter_order parameter to index.php; (3) the query string to the com_newsfeeds component, as demonstrated by an arbitrary parameter to index.php; or (4) the option parameter in a reset.request action to index.php; and, when Internet Explorer or Konqueror is used, (5) allow remote attackers to inject arbitrary web script or HTML via the searchword parameter in a search action to index.php in the com_search component.
- Source
- secalert@redhat.com
- NVD status
- Modified
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 4.3
- Impact score
- 2.9
- Exploitability score
- 8.6
- Vector string
- AV:N/AC:M/Au:N/C:N/I:P/A:N
Weaknesses
- nvd@nist.gov
- CWE-79
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:joomla:joomla\\!:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "04C7A143-6E44-40FE-9339-DA4346A99E5A", "versionEndIncluding": "1.6.3" }, { "criteria": "cpe:2.3:a:joomla:joomla\\!:1.5.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "65184BFE-A070-4099-B672-3A238E9F83EF" }, { "criteria": "cpe:2.3:a:joomla:joomla\\!:1.5.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "920129E4-F979-49B5-9B96-62BCBC3954D5" }, { "criteria": "cpe:2.3:a:joomla:joomla\\!:1.5.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "1313BEAD-C0C0-4D8C-A3AA-F514BA6A1C92" }, { "criteria": "cpe:2.3:a:joomla:joomla\\!:1.5.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A90A8900-E441-46C4-A725-BA312358760E" }, { "criteria": "cpe:2.3:a:joomla:joomla\\!:1.5.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E74E276C-C62D-4828-89CB-80F526FEAEA5" }, { "criteria": "cpe:2.3:a:joomla:joomla\\!:1.5.5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F370EA7F-3719-4D35-A7FD-C7AD1BD709D5" }, { "criteria": "cpe:2.3:a:joomla:joomla\\!:1.5.6:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E4E48636-9EDB-49BB-ABC8-D79864BFCB38" }, { "criteria": "cpe:2.3:a:joomla:joomla\\!:1.5.7:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "580712F4-E97C-4E3F-BF9D-3445BEB4C3FE" }, { "criteria": "cpe:2.3:a:joomla:joomla\\!:1.5.8:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "466E5E84-4C69-49F2-83DA-FC86202DB7F4" }, { "criteria": "cpe:2.3:a:joomla:joomla\\!:1.5.9:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "CB968DF7-4A0B-474C-8639-06976837E03D" }, { "criteria": "cpe:2.3:a:joomla:joomla\\!:1.5.10:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "1B6BE010-649F-4E48-97DC-DDF7511406D5" }, { "criteria": "cpe:2.3:a:joomla:joomla\\!:1.5.11:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2B8C4094-D028-4A55-B523-C90F5A4C9D82" }, { "criteria": "cpe:2.3:a:joomla:joomla\\!:1.5.12:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "69FA6550-2135-4D41-B592-433FFFDEE180" }, { "criteria": "cpe:2.3:a:joomla:joomla\\!:1.5.13:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C73D78E0-BF24-433B-9F1B-03FD956C5779" }, { "criteria": "cpe:2.3:a:joomla:joomla\\!:1.5.14:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B9BAC75B-DAC1-47E1-B9C9-48CF19489143" }, { "criteria": "cpe:2.3:a:joomla:joomla\\!:1.5.15:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "9BA97C8A-809D-44FC-95D2-5F269B6BF77D" }, { "criteria": "cpe:2.3:a:joomla:joomla\\!:1.5.15:rc:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A9F607CF-AC49-4B13-96E5-B44191108CDA" }, { "criteria": "cpe:2.3:a:joomla:joomla\\!:1.5.16:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "883B3DC0-6D6C-4C21-BC2A-EE53C140D817" }, { "criteria": "cpe:2.3:a:joomla:joomla\\!:1.5.17:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B7CFCF0F-BCD9-4215-817A-1409EA00CCBA" }, { "criteria": "cpe:2.3:a:joomla:joomla\\!:1.5.18:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "0D5CB72A-9B5F-42B2-BEE1-3F92C04FB335" }, { "criteria": "cpe:2.3:a:joomla:joomla\\!:1.5.19:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "3FDBBD33-63E0-4377-95ED-45FAA1EED3E7" }, { "criteria": "cpe:2.3:a:joomla:joomla\\!:1.5.20:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "34B39FD1-44E2-43EC-B393-99E6208622B5" }, { "criteria": "cpe:2.3:a:joomla:joomla\\!:1.5.21:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "0F77BABA-7768-4F92-84C7-D247E4772749" }, { "criteria": "cpe:2.3:a:joomla:joomla\\!:1.5.22:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "487204D9-7A9F-4A44-B625-FDBE2807444A" }, { "criteria": "cpe:2.3:a:joomla:joomla\\!:1.5.23:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "1A5C8747-BF6A-4436-BC3A-A4B808AFF889" }, { "criteria": "cpe:2.3:a:joomla:joomla\\!:1.6:alpha:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C15380EB-6543-4C95-9B7F-35DDD99D1C37" }, { "criteria": "cpe:2.3:a:joomla:joomla\\!:1.6:alpha2:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C95EE9E1-CB59-4E8B-B57B-991295790328" }, { "criteria": "cpe:2.3:a:joomla:joomla\\!:1.6:beta1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "605F893A-2612-4524-B24B-0468F5EE2019" }, { "criteria": "cpe:2.3:a:joomla:joomla\\!:1.6:beta10:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "21D252E2-1961-4D4F-8471-584CF6CB39E5" }, { "criteria": "cpe:2.3:a:joomla:joomla\\!:1.6:beta11:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8B0930E8-3E98-4DF5-AED3-146D34F843D7" }, { "criteria": "cpe:2.3:a:joomla:joomla\\!:1.6:beta12:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C732CFEF-CF4D-4EB7-A730-A5764B40A9BC" }, { "criteria": "cpe:2.3:a:joomla:joomla\\!:1.6:beta13:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "10880E1E-8478-485C-AD9C-ABE4C51D2EA7" }, { "criteria": "cpe:2.3:a:joomla:joomla\\!:1.6:beta14:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "816A10B4-EC28-47EF-BD47-7F431AB77561" }, { "criteria": "cpe:2.3:a:joomla:joomla\\!:1.6:beta15:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F9085C7C-6CA0-4423-93B1-9E8AF6D2978E" }, { "criteria": "cpe:2.3:a:joomla:joomla\\!:1.6:beta2:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "5BCAD021-E5B2-4232-81FF-BB04908F4FE6" }, { "criteria": "cpe:2.3:a:joomla:joomla\\!:1.6:beta3:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "0B842E1A-348B-4644-930E-CF46E1E38E70" }, { "criteria": "cpe:2.3:a:joomla:joomla\\!:1.6:beta4:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D08BB717-4841-482D-A1AD-E8DF769E57C0" }, { "criteria": "cpe:2.3:a:joomla:joomla\\!:1.6:beta5:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "065980D5-AEBA-44B1-A58D-8BF8FFF674F8" }, { "criteria": "cpe:2.3:a:joomla:joomla\\!:1.6:beta6:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "EBC711DC-C790-4558-B305-A812EE2290B9" }, { "criteria": "cpe:2.3:a:joomla:joomla\\!:1.6:beta7:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "37DE1D53-EE34-4C2C-B2AD-3DD58254C874" }, { "criteria": "cpe:2.3:a:joomla:joomla\\!:1.6:beta8:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "9E11C49B-2A3E-4D52-BEFA-CDDB751E20AD" }, { "criteria": "cpe:2.3:a:joomla:joomla\\!:1.6:beta9:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "1D6CA7BE-DD88-4899-A284-C9E4F97F4005" }, { "criteria": "cpe:2.3:a:joomla:joomla\\!:1.6:rc1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2C686887-75D3-4682-AE61-245D10EEAADE" }, { "criteria": "cpe:2.3:a:joomla:joomla\\!:1.6.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B15F42BC-7826-493B-8C5A-D70A7263DCB0" }, { "criteria": "cpe:2.3:a:joomla:joomla\\!:1.6.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "AAC6CF00-2D88-4B97-A496-DCBE1B4E9A00" } ], "operator": "OR" } ] } ]