Skip to main content

Vendor archive

harmistechnology CVEs

Beta · best-effort

22 CVEs tagged to vendor harmistechnology2 Critical, 14 High, 6 Medium, 0 Low, 0 Unrated.

CVE-2019-9922

Published Mar 29, 2019

An issue was discovered in the Harmis JE Messenger component 1.2.2 for Joomla!. Directory Traversal allows read access to arbitrary files.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-9921

Published Mar 29, 2019

An issue was discovered in the Harmis JE Messenger component 1.2.2 for Joomla!. It is possible to read information that should only be accessible by a different user.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-9920

Published Mar 29, 2019

An issue was discovered in the Harmis JE Messenger component 1.2.2 for Joomla!. It is possible to perform an action within the context of the account of another user.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-9919

Published Mar 29, 2019

An issue was discovered in the Harmis JE Messenger component 1.2.2 for Joomla!. It is possible to craft messages in a way that JavaScript gets executed on the side of the receivin…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-9918

Published Mar 29, 2019

An issue was discovered in the Harmis JE Messenger component 1.2.2 for Joomla!. Input does not get validated and queries are not written in a way to prevent SQL injection. Therefo…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-12254

Published Jun 12, 2018

router.php in the Harmis Ek rishta (aka ek-rishta) 2.10 component for Joomla! allows SQL Injection via the PATH_INFO to a home/requested_user/Sent%20interest/ URI.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-7315

Published Feb 22, 2018

SQL Injection exists in the Ek Rishta 2.9 component for Joomla! via the gender, age1, age2, religion, mothertounge, caste, or country parameter.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2010-5028

Published Nov 2, 2011

SQL injection vulnerability in the JExtensions JE Job (com_jejob) component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter in an…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2010-4720

Published Feb 1, 2011

SQL injection vulnerability in the JExtensions JE Auto (com_jeauto) component before 1.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via unspecified vect…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2010-4517

Published Dec 9, 2010

SQL injection vulnerability in the JExtensions JE Auto (com_jeauto) component 1.0 for Joomla!, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-22 of 22 CVEsPage 1 of 1