CVE-2007-4779: XSS
Published Sep 10, 2007
·Updated
Cross-site scripting (XSS) vulnerability in Joomla! 1.5 before RC2 (aka Endeleo) allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, probably related to the archive section.
Affected Software
3 affected components
Joomla joomla=1.5.0_rc1
Joomla joomla=1.5.0_beta2
Joomla joomla=1.5.0_beta
Remediation
Patch Available
Patch Available
Event History
Sep 10, 2007
CVE Published
09:17 PM
Sep 11, 2007
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-4779?
CVE-2007-4779 is classified as a moderate severity cross-site scripting (XSS) vulnerability.
2
How do I fix CVE-2007-4779?
To fix CVE-2007-4779, upgrade to Joomla! version 1.5 RC2 or later.
3
Which versions of Joomla! are affected by CVE-2007-4779?
CVE-2007-4779 affects Joomla! versions 1.5.0 RC1, 1.5.0 Beta2, and 1.5.0 Beta.
4
What type of vulnerability is CVE-2007-4779?
CVE-2007-4779 is a cross-site scripting (XSS) vulnerability that allows for the injection of arbitrary web scripts or HTML.
5
Can CVE-2007-4779 be exploited by remote attackers?
Yes, CVE-2007-4779 can be exploited remotely by attackers to inject malicious scripts.