CVE-2008-6299: XSS
Multiple cross-site scripting (XSS) vulnerabilities in Joomla! 1.5.7 and earlier allow remote authenticated users with certain privileges to inject arbitrary web script or HTML via (1) the title and description parameters to the comweblinks module and (2) unspecified vectors in the comcontent module related to "article submission."
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2008-6299?
CVE-2008-6299 is classified as a high severity vulnerability due to its ability to allow authenticated users to execute arbitrary script code.
How do I fix CVE-2008-6299?
To fix CVE-2008-6299, upgrade to Joomla! version 1.5.8 or later that addresses the XSS vulnerabilities in the com_weblinks and com_content modules.
Who is affected by CVE-2008-6299?
CVE-2008-6299 affects Joomla! versions 1.5.7 and earlier, including multiple 1.0.x versions.
What types of attacks can be executed with CVE-2008-6299?
CVE-2008-6299 can be exploited to perform cross-site scripting (XSS) attacks, allowing attackers to inject malicious scripts.
Is there a patch available for CVE-2008-6299?
Yes, a patch is included in the Joomla! updates that can be applied to eliminate the vulnerabilities associated with CVE-2008-6299.