CVE-2011-2892

Joomla! 1.6.x before 1.6.2 does not prevent page rendering inside a frame in a third-party HTML document, which makes it easier for remote attackers to conduct clickjacking attacks via a crafted web site.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
4.3 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 2%
VendorProductVersion
joomlajoomla\!
1.6:alpha
joomlajoomla\!
1.6:alpha2
joomlajoomla\!
1.6:beta1
joomlajoomla\!
1.6:beta10
joomlajoomla\!
1.6:beta11
joomlajoomla\!
1.6:beta12
joomlajoomla\!
1.6:beta13
joomlajoomla\!
1.6:beta14
joomlajoomla\!
1.6:beta15
joomlajoomla\!
1.6:beta2
joomlajoomla\!
1.6:beta3
joomlajoomla\!
1.6:beta4
joomlajoomla\!
1.6:beta5
joomlajoomla\!
1.6:beta6
joomlajoomla\!
1.6:beta7
joomlajoomla\!
1.6:beta8
joomlajoomla\!
1.6:beta9
joomlajoomla\!
1.6:rc1
joomlajoomla\!
1.6.0
joomlajoomla\!
1.6.1
𝑥
= Vulnerable software versions