First published: Sun Dec 10 2006(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in jce.php in the JCE Admin Component in Ryan Demmer Joomla Content Editor (JCE) 1.1.0 beta 2 and earlier for Joomla! (com_jce) allow remote attackers to inject arbitrary web script or HTML via the (1) img, (2) title, (3) w, or (4) h parameter, different vectors than CVE-2006-6166. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Joomla! Content Editor (JCE) | =1.0.4 | |
Joomla! Content Editor (JCE) | =1.1.0_beta2 | |
=1.0.4 | ||
=1.1.0_beta2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-6420 is classified as a medium severity vulnerability due to its potential for cross-site scripting attacks.
To fix CVE-2006-6420, update to the latest version of the Joomla Content Editor that addresses the XSS vulnerabilities.
CVE-2006-6420 affects Joomla Content Editor versions 1.1.0 beta 2 and earlier.
Yes, CVE-2006-6420 can be exploited remotely by attackers to inject arbitrary web scripts or HTML.
CVE-2006-6420 involves the jce.php script in the JCE Admin Component of the Joomla Content Editor.