Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2011-2509


Multiple cross-site scripting (XSS) vulnerabilities in Joomla! before 1.6.4 allow remote attackers to inject arbitrary web script or HTML via (1) the query string to the com_contact component, as demonstrated by the Itemid parameter to index.php; (2) the query string to the com_content component, as demonstrated by the filter_order parameter to index.php; (3) the query string to the com_newsfeeds component, as demonstrated by an arbitrary parameter to index.php; or (4) the option parameter in a reset.request action to index.php; and, when Internet Explorer or Konqueror is used, (5) allow remote attackers to inject arbitrary web script or HTML via the searchword parameter in a search action to index.php in the com_search component.


Published

2011-07-27T20:55:03.257

Last Modified

2025-04-11T00:51:21.963

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 4.3 (MEDIUM)

CVSSv2 Vector

AV:N/AC:M/Au:N/C:N/I:P/A:N

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: NONE
  • Integrity Impact: PARTIAL
  • Availability Impact: NONE
Exploitability Score

8.6

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-79

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application joomla joomla\! ≤ 1.6.3 Yes
Application joomla joomla\! 1.5.0 Yes
Application joomla joomla\! 1.5.1 Yes
Application joomla joomla\! 1.5.2 Yes
Application joomla joomla\! 1.5.3 Yes
Application joomla joomla\! 1.5.4 Yes
Application joomla joomla\! 1.5.5 Yes
Application joomla joomla\! 1.5.6 Yes
Application joomla joomla\! 1.5.7 Yes
Application joomla joomla\! 1.5.8 Yes
Application joomla joomla\! 1.5.9 Yes
Application joomla joomla\! 1.5.10 Yes
Application joomla joomla\! 1.5.11 Yes
Application joomla joomla\! 1.5.12 Yes
Application joomla joomla\! 1.5.13 Yes
Application joomla joomla\! 1.5.14 Yes
Application joomla joomla\! 1.5.15 Yes
Application joomla joomla\! 1.5.15 Yes
Application joomla joomla\! 1.5.16 Yes
Application joomla joomla\! 1.5.17 Yes
Application joomla joomla\! 1.5.18 Yes
Application joomla joomla\! 1.5.19 Yes
Application joomla joomla\! 1.5.20 Yes
Application joomla joomla\! 1.5.21 Yes
Application joomla joomla\! 1.5.22 Yes
Application joomla joomla\! 1.5.23 Yes
Application joomla joomla\! 1.6 Yes
Application joomla joomla\! 1.6 Yes
Application joomla joomla\! 1.6 Yes
Application joomla joomla\! 1.6 Yes
Application joomla joomla\! 1.6 Yes
Application joomla joomla\! 1.6 Yes
Application joomla joomla\! 1.6 Yes
Application joomla joomla\! 1.6 Yes
Application joomla joomla\! 1.6 Yes
Application joomla joomla\! 1.6 Yes
Application joomla joomla\! 1.6 Yes
Application joomla joomla\! 1.6 Yes
Application joomla joomla\! 1.6 Yes
Application joomla joomla\! 1.6 Yes
Application joomla joomla\! 1.6 Yes
Application joomla joomla\! 1.6 Yes
Application joomla joomla\! 1.6 Yes
Application joomla joomla\! 1.6 Yes
Application joomla joomla\! 1.6.0 Yes
Application joomla joomla\! 1.6.1 Yes

References