CVE-2007-4780: Input Validation
Published Sep 10, 2007
·Updated
Joomla! 1.5 before RC2 (aka Endeleo) allows remote attackers to obtain sensitive information (the full path) via unspecified vectors, probably involving direct requests to certain PHP scripts in tmpl/ directories.
Affected Software
3 affected components
Joomla joomla=1.5.0_rc1
Joomla joomla=1.5.0_beta2
Joomla joomla=1.5.0_beta
Remediation
Patch Available
Event History
Sep 10, 2007
CVE Published
09:17 PM
Sep 11, 2007
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-4780?
CVE-2007-4780 is considered a moderate severity vulnerability due to the potential exposure of sensitive information.
2
How do I fix CVE-2007-4780?
To fix CVE-2007-4780, upgrade to Joomla! version 1.5.0 RC2 or later.
3
What versions of Joomla! are affected by CVE-2007-4780?
CVE-2007-4780 affects Joomla! versions 1.5.0_beta, 1.5.0_beta2, and 1.5.0_rc1.
4
What type of vulnerability is CVE-2007-4780?
CVE-2007-4780 is a vulnerability that allows remote attackers to obtain sensitive information.
5
What information can be exposed through CVE-2007-4780?
CVE-2007-4780 can expose the full path of the Joomla! installation.