First published: Thu Feb 26 2009(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in Joomla! 1.5.7 and earlier allow remote authenticated users with certain privileges to inject arbitrary web script or HTML via (1) the title and description parameters to the com_weblinks module and (2) unspecified vectors in the com_content module related to "article submission."
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Joomla | <=1.5.7 | |
Joomla | =1.0 | |
Joomla | =1.0.0 | |
Joomla | =1.0.1 | |
Joomla | =1.0.2 | |
Joomla | =1.0.3 | |
Joomla | =1.0.4 | |
Joomla | =1.0.5 | |
Joomla | =1.0.6 | |
Joomla | =1.0.7 | |
Joomla | =1.0.8 | |
Joomla | =1.0.9 | |
Joomla | =1.0.10 | |
Joomla | =1.0.11 | |
Joomla | =1.0.12 | |
Joomla | =1.0.13 | |
Joomla | =1.0.14 | |
Joomla | =1.03 | |
Joomla | =1.5 | |
Joomla | =1.5.0-beta | |
Joomla | =1.5.0-beta1 | |
Joomla | =1.5.0-beta2 | |
Joomla | =1.5.0-rc1 | |
Joomla | =1.5.0_beta | |
Joomla | =1.5.0_beta1 | |
Joomla | =1.5.0_beta2 | |
Joomla | =1.5.0_rc1 | |
Joomla | =1.5.1 | |
Joomla | =1.5.2 | |
Joomla | =1.5.3 | |
Joomla | =1.5.4 | |
Joomla | =1.5.5 | |
Joomla | =1.5.6 | |
Joomla | =1.5rc3 | |
Joomla | =1.5rc4 |
http://developer.joomla.org/security/news/284-20081102-core-comweblinks-xss-vulnerability.html
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-6299 is classified as a high severity vulnerability due to its ability to allow authenticated users to execute arbitrary script code.
To fix CVE-2008-6299, upgrade to Joomla! version 1.5.8 or later that addresses the XSS vulnerabilities in the com_weblinks and com_content modules.
CVE-2008-6299 affects Joomla! versions 1.5.7 and earlier, including multiple 1.0.x versions.
CVE-2008-6299 can be exploited to perform cross-site scripting (XSS) attacks, allowing attackers to inject malicious scripts.
Yes, a patch is included in the Joomla! updates that can be applied to eliminate the vulnerabilities associated with CVE-2008-6299.