First published: Mon Jan 09 2006(Updated: )
The vCard functions in Joomla! 1.0.5 use predictable sequential IDs for vcards and do not restrict access to them, which allows remote attackers to obtain valid e-mail addresses to conduct spam attacks by modifying the contact_id parameter to index2.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Joomla | =1.0.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-0114 is considered a critical vulnerability due to its potential for exposing valid email addresses and facilitating spam attacks.
To fix CVE-2006-0114, upgrade Joomla! to a later version that addresses this vulnerability.
CVE-2006-0114 specifically affects Joomla! version 1.0.5.
CVE-2006-0114 can be exploited to conduct spam attacks by accessing valid email addresses.
CVE-2006-0114 compromises user information by allowing attackers to predictably access vCard information without restriction.