CVE-2008-3228: High severity joomla vulnerability
Published Jul 18, 2008
·Updated
Joomla! before 1.5.4 does not configure .htaccess to apply certain security checks that "block common exploits" to SEF URLs, which has unknown impact and remote attack vectors.
Affected Software
25 affected componentsFixes available
Joomla joomla=1.0.13
Joomla joomla=1.0.9
Joomla joomla=1.5
Joomla joomla=1.5.0_rc1
Joomla joomla=1.5.0_beta2
Joomla joomla=1.0
Joomla joomla=1.5.2
Joomla joomla=1.0.1
Joomla joomla=1.0.3
Joomla joomla=1.0.6
Joomla joomla=1.0.8
Joomla joomla=1.0.4
Joomla joomla=1.0.2
Joomla joomla=1.5.0_beta
Joomla joomla=1.0.10
Joomla joomla=1.5.0_beta1
Joomla joomla=1.5.1
Joomla joomla=1.0.12
Joomla joomla=1.03
Joomla joomla=1.0.5
Joomla joomla=1.0.7
Joomla joomla=1.0.0
Joomla joomla<=1.5.3
Joomla joomla=1.0.11
composer/joomla/joomla-platform<1.5.4
1.5.4
Event History
Jul 18, 2008
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
May 1, 2022
Advisory Published
via GitHub·11:57 PM
Frequently Asked Questions
1
What is the severity of CVE-2008-3228?
The severity of CVE-2008-3228 is considered moderate due to the potential for remote attack vectors.
2
How do I fix CVE-2008-3228?
To fix CVE-2008-3228, upgrade Joomla! to version 1.5.4 or later, which addresses the .htaccess configuration issue.
3
What versions of Joomla! are affected by CVE-2008-3228?
CVE-2008-3228 affects Joomla! versions prior to 1.5.4, including several earlier versions.
4
What vulnerabilities does CVE-2008-3228 expose?
CVE-2008-3228 exposes the site to common exploits targeting SEF URLs due to improper .htaccess configuration.
5
Is there a workaround for CVE-2008-3228?
A temporary workaround for CVE-2008-3228 could involve manually configuring .htaccess settings to block common exploits until an upgrade can be performed.