CVE-2011-2509
27.07.2011, 20:55
Multiple cross-site scripting (XSS) vulnerabilities in Joomla! before 1.6.4 allow remote attackers to inject arbitrary web script or HTML via (1) the query string to the com_contact component, as demonstrated by the Itemid parameter to index.php; (2) the query string to the com_content component, as demonstrated by the filter_order parameter to index.php; (3) the query string to the com_newsfeeds component, as demonstrated by an arbitrary parameter to index.php; or (4) the option parameter in a reset.request action to index.php; and, when Internet Explorer or Konqueror is used, (5) allow remote attackers to inject arbitrary web script or HTML via the searchword parameter in a search action to index.php in the com_search component.
Vendor | Product | Version |
---|---|---|
joomla | joomla\! | 𝑥 ≤ 1.6.3 |
joomla | joomla\! | 1.5.0 |
joomla | joomla\! | 1.5.1 |
joomla | joomla\! | 1.5.2 |
joomla | joomla\! | 1.5.3 |
joomla | joomla\! | 1.5.4 |
joomla | joomla\! | 1.5.5 |
joomla | joomla\! | 1.5.6 |
joomla | joomla\! | 1.5.7 |
joomla | joomla\! | 1.5.8 |
joomla | joomla\! | 1.5.9 |
joomla | joomla\! | 1.5.10 |
joomla | joomla\! | 1.5.11 |
joomla | joomla\! | 1.5.12 |
joomla | joomla\! | 1.5.13 |
joomla | joomla\! | 1.5.14 |
joomla | joomla\! | 1.5.15 |
joomla | joomla\! | 1.5.15:rc |
joomla | joomla\! | 1.5.16 |
joomla | joomla\! | 1.5.17 |
joomla | joomla\! | 1.5.18 |
joomla | joomla\! | 1.5.19 |
joomla | joomla\! | 1.5.20 |
joomla | joomla\! | 1.5.21 |
joomla | joomla\! | 1.5.22 |
joomla | joomla\! | 1.5.23 |
joomla | joomla\! | 1.6:alpha |
joomla | joomla\! | 1.6:alpha2 |
joomla | joomla\! | 1.6:beta1 |
joomla | joomla\! | 1.6:beta10 |
joomla | joomla\! | 1.6:beta11 |
joomla | joomla\! | 1.6:beta12 |
joomla | joomla\! | 1.6:beta13 |
joomla | joomla\! | 1.6:beta14 |
joomla | joomla\! | 1.6:beta15 |
joomla | joomla\! | 1.6:beta2 |
joomla | joomla\! | 1.6:beta3 |
joomla | joomla\! | 1.6:beta4 |
joomla | joomla\! | 1.6:beta5 |
joomla | joomla\! | 1.6:beta6 |
joomla | joomla\! | 1.6:beta7 |
joomla | joomla\! | 1.6:beta8 |
joomla | joomla\! | 1.6:beta9 |
joomla | joomla\! | 1.6:rc1 |
joomla | joomla\! | 1.6.0 |
joomla | joomla\! | 1.6.1 |
𝑥
= Vulnerable software versions
References