CVE-2009-1279: XSS
Multiple cross-site scripting (XSS) vulnerabilities in Joomla! 1.5 through 1.5.9 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors to the (1) comadmin component, (2) comsearch component when "Gather Search Statistics" is enabled, and (3) the category view in the comcontent component.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What vulnerability does CVE-2009-1279 describe?
CVE-2009-1279 describes multiple cross-site scripting (XSS) vulnerabilities in Joomla! versions 1.5 through 1.5.9.
What components of Joomla! are affected by CVE-2009-1279?
The affected components include com_admin, com_search with 'Gather Search Statistics' enabled, and the category view.
What are the risks associated with CVE-2009-1279?
The risks involve remote attackers being able to inject arbitrary web script or HTML, leading to potential theft of sensitive information.
How can I mitigate the risks from CVE-2009-1279?
Mitigation can be achieved by upgrading Joomla! to a version beyond 1.5.9 where the vulnerabilities are patched.
Is my Joomla! site vulnerable if it runs version 1.5.x?
Yes, any Joomla! site running version 1.5.x is vulnerable and should be updated immediately to prevent exploitation.