First published: Thu Apr 09 2009(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in Joomla! 1.5 through 1.5.9 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors to the (1) com_admin component, (2) com_search component when "Gather Search Statistics" is enabled, and (3) the category view in the com_content component.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Joomla | =1.5.5 | |
Joomla | =1.5 | |
Joomla | =1.5.7 | |
Joomla | =1.5.0-beta2 | |
Joomla | =1.5.9 | |
Joomla | =1.5.3 | |
Joomla | =1.5.2 | |
Joomla | =1.5.0-beta1 | |
Joomla | =1.5.8 | |
Joomla | =1.5.1 | |
Joomla | =1.5.4 | |
Joomla | =1.5.0-rc1 | |
Joomla | =1.5.6 | |
Joomla | =1.5.0-beta |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-1279 describes multiple cross-site scripting (XSS) vulnerabilities in Joomla! versions 1.5 through 1.5.9.
The affected components include com_admin, com_search with 'Gather Search Statistics' enabled, and the category view.
The risks involve remote attackers being able to inject arbitrary web script or HTML, leading to potential theft of sensitive information.
Mitigation can be achieved by upgrading Joomla! to a version beyond 1.5.9 where the vulnerabilities are patched.
Yes, any Joomla! site running version 1.5.x is vulnerable and should be updated immediately to prevent exploitation.