First published: Mon Jul 10 2006(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in Joomla! before 1.0.10 allow remote attackers to inject arbitrary web script or HTML via unspecified parameters involving the (1) getUserStateFromRequest function, and the (2) SEF and (3) com_messages modules.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Joomla | =1.0 | |
Joomla | =1.0.1 | |
Joomla | =1.0.2 | |
Joomla | =1.0.3 | |
Joomla | =1.0.4 | |
Joomla | =1.0.5 | |
Joomla | =1.0.7 | |
Joomla | =1.0.8 | |
Joomla | =1.0.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-3480 has a medium severity rating as it involves multiple cross-site scripting vulnerabilities.
To fix CVE-2006-3480, you should upgrade Joomla! to version 1.0.10 or later.
Joomla! versions 1.0 through 1.0.9 are affected by CVE-2006-3480.
Yes, CVE-2006-3480 can allow remote attackers to inject arbitrary web scripts which could lead to unauthorized access.
CVE-2006-3480 is classified as a cross-site scripting (XSS) vulnerability.