Skip to main content

Vendor archive

joomla CVEs

Beta · best-effort

974 CVEs tagged to vendor joomla43 Critical, 519 High, 405 Medium, 7 Low, 0 Unrated.

CVE-2007-4778

Published Sep 10, 2007

Multiple SQL injection vulnerabilities in the content component (com_content) in Joomla! 1.5 Beta1, Beta2, and RC1 allow remote attackers to execute arbitrary SQL commands via the…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-4779

Published Sep 10, 2007

Cross-site scripting (XSS) vulnerability in Joomla! 1.5 before RC2 (aka Endeleo) allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, probably r…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-4780

Published Sep 10, 2007

Joomla! 1.5 before RC2 (aka Endeleo) allows remote attackers to obtain sensitive information (the full path) via unspecified vectors, probably involving direct requests to certain…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-4781

Published Sep 10, 2007

administrator/index.php in the installer component (com_installer) in Joomla! 1.5 Beta1, Beta2, and RC1 allows remote authenticated administrators to upload arbitrary files to tmp…

CVSS 6.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-4745

Published Sep 6, 2007

Multiple cross-site scripting (XSS) vulnerabilities in the AkoBook 3.42 and earlier component (com_akobook) for Mambo allow remote attackers to inject arbitrary web script or HTML…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-4502

Published Aug 23, 2007

SQL injection vulnerability in index.php in the BibTeX component (com_jombib) 1.3 and earlier for Joomla! allows remote attackers to execute arbitrary SQL commands via the afilter…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-4503

Published Aug 23, 2007

SQL injection vulnerability in index.php in the Nice Talk component (com_nicetalk) 0.9.3 and earlier for Joomla! allows remote attackers to execute arbitrary SQL commands via the…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-4504

Published Aug 23, 2007

Directory traversal vulnerability in index.php in the RSfiles component (com_rsfiles) 1.0.2 and earlier for Joomla! allows remote attackers to read arbitrary files via a .. (dot d…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-4506

Published Aug 23, 2007

SQL injection vulnerability in index.php in the NeoRecruit component (com_neorecruit) 1.4 and earlier for Joomla! allows remote attackers to execute arbitrary SQL commands via the…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-4509

Published Aug 23, 2007

SQL injection vulnerability in index.php in the EventList component (com_eventlist) 0.8 and earlier for Joomla! allows remote attackers to execute arbitrary SQL commands via the d…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-4244

Published Aug 8, 2007

PHP remote file inclusion vulnerability in langset.php in J! Reactions (com_jreactions) 1.8.1 and earlier, a Joomla! component, allows remote attackers to execute arbitrary PHP co…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-4184

Published Aug 8, 2007

SQL injection vulnerability in administrator/popups/pollwindow.php in Joomla! 1.0.12 allows remote attackers to execute arbitrary SQL commands via the pollid parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-4185

Published Aug 8, 2007

Joomla! 1.0.12 allows remote attackers to obtain sensitive information via a direct request for (1) Stat.php (2) OutputFilter.php, (3) OutputCache.php, (4) Modifier.php, (5) Reade…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-4186

Published Aug 8, 2007

PHP remote file inclusion vulnerability in admin.tour_toto.php in the Tour de France Pool (com_tour_toto) 1.0.1 module for Joomla! allows remote attackers to execute arbitrary PHP…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-4187

Published Aug 8, 2007

Multiple eval injection vulnerabilities in the com_search component in Joomla! 1.5 beta before RC1 (aka Mapya) allow remote attackers to execute arbitrary PHP code via PHP sequenc…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-4188

Published Aug 8, 2007

Session fixation vulnerability in Joomla! before 1.0.13 (aka Sunglow) allows remote attackers to hijack administrative web sessions via unspecified vectors.

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2007-4189

Published Aug 8, 2007

Multiple cross-site scripting (XSS) vulnerabilities in Joomla! before 1.0.13 (aka Sunglow) allow remote attackers to inject arbitrary web script or HTML via unspecified vectors in…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-4190

Published Aug 8, 2007

CRLF injection vulnerability in Joomla! before 1.0.13 (aka Sunglow) allows remote attackers to inject arbitrary HTTP headers and probably conduct HTTP response splitting attacks v…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-4046

Published Jul 27, 2007

SQL injection vulnerability in index.php in the Pony Gallery (com_ponygallery) 1.5 and earlier component for Joomla! allows remote attackers to execute arbitrary SQL commands via…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-3932

Published Jul 21, 2007

uploadimg.php in the Expose RC35 and earlier (com_expose) component for Joomla! sends an error message but does not exit when it detects an attempt to upload a non-JPEG file, whic…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-3249

Published Jun 18, 2007

Cross-site scripting (XSS) vulnerability in mod_lettermansubscribe.php in the Letterman Subscriber (mod_letterman) before 1.2.5 module for Joomla! allows remote attackers to injec…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-3130

Published Jun 8, 2007

Multiple PHP remote file inclusion vulnerabilities in the OpenWiki (formerly JD-Wiki) component (com_jd-wiki) 1.0.2, and possibly earlier, for Joomla! allow remote attackers to ex…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-2196

Published Apr 24, 2007

PHP remote file inclusion vulnerability in jambook.php in the Jambook (com_Jambook) 1.0 beta7 module for Mambo and Joomla! allows remote attackers to execute arbitrary PHP code vi…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort
Showing 876-900 of 974 CVEsPage 36 of 39