CVE-2011-4909
Published Oct 7, 2012
Last updated 12 years ago
Overview
- Description
- Multiple cross-site scripting (XSS) vulnerabilities in Joomla! before 1.5.12 allow remote attackers to inject arbitrary web script or HTML via the HTTP_REFERER header to (1) components/com_content/views/article/tmpl/form.php, (2) components/com_user/controller.php, (3) plugins/system/legacy/html.php, or (4) templates/beez/html/com_content/article/form.php.
- Source
- secalert@redhat.com
- NVD status
- Analyzed
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 4.3
- Impact score
- 2.9
- Exploitability score
- 8.6
- Vector string
- AV:N/AC:M/Au:N/C:N/I:P/A:N
Weaknesses
- nvd@nist.gov
- CWE-79
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:joomla:joomla\\!:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "99C3575C-449A-4A65-903F-B4A63943B68A", "versionEndIncluding": "1.5.11" }, { "criteria": "cpe:2.3:a:joomla:joomla\\!:1.5.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "65184BFE-A070-4099-B672-3A238E9F83EF" }, { "criteria": "cpe:2.3:a:joomla:joomla\\!:1.5.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "920129E4-F979-49B5-9B96-62BCBC3954D5" }, { "criteria": "cpe:2.3:a:joomla:joomla\\!:1.5.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "1313BEAD-C0C0-4D8C-A3AA-F514BA6A1C92" }, { "criteria": "cpe:2.3:a:joomla:joomla\\!:1.5.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A90A8900-E441-46C4-A725-BA312358760E" }, { "criteria": "cpe:2.3:a:joomla:joomla\\!:1.5.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E74E276C-C62D-4828-89CB-80F526FEAEA5" }, { "criteria": "cpe:2.3:a:joomla:joomla\\!:1.5.5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F370EA7F-3719-4D35-A7FD-C7AD1BD709D5" }, { "criteria": "cpe:2.3:a:joomla:joomla\\!:1.5.6:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E4E48636-9EDB-49BB-ABC8-D79864BFCB38" }, { "criteria": "cpe:2.3:a:joomla:joomla\\!:1.5.7:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "580712F4-E97C-4E3F-BF9D-3445BEB4C3FE" }, { "criteria": "cpe:2.3:a:joomla:joomla\\!:1.5.8:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "466E5E84-4C69-49F2-83DA-FC86202DB7F4" }, { "criteria": "cpe:2.3:a:joomla:joomla\\!:1.5.9:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "CB968DF7-4A0B-474C-8639-06976837E03D" }, { "criteria": "cpe:2.3:a:joomla:joomla\\!:1.5.10:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "1B6BE010-649F-4E48-97DC-DDF7511406D5" } ], "operator": "OR" } ] } ]