CVE-2009-1939: XSS
Published Jun 5, 2009
·Updated
Cross-site scripting (XSS) vulnerability in the JAPurity template for Joomla! 1.5.x through 1.5.10 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Affected Software
14 affected components
Joomla joomla=1.5.5
Joomla joomla=1.5.0_rc1
Joomla joomla=1.5.7
Joomla joomla=1.5.0_beta2
Joomla joomla=1.5.9
Joomla joomla=1.5.3
Joomla joomla=1.5.10
Joomla joomla=1.5.2
Joomla joomla=1.5.8
Joomla joomla=1.5.0_beta
Joomla joomla=1.5.0_beta1
Joomla joomla=1.5.1
Joomla joomla=1.5.4
Joomla joomla=1.5.6
Remediation
Patch Available
Event History
Jun 5, 2009
CVE Published
via MITRE·06:13 PM
Data Sourced
via MITRE·06:13 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2009-1939?
CVE-2009-1939 has been classified as a moderate severity vulnerability due to the potential for cross-site scripting attacks.
2
How do I fix CVE-2009-1939?
To fix CVE-2009-1939, you should upgrade your Joomla! installation to a patched version that is not vulnerable to this XSS flaw.
3
What versions of Joomla! are affected by CVE-2009-1939?
CVE-2009-1939 affects Joomla! versions 1.5.0 through 1.5.10.
4
Can CVE-2009-1939 be exploited remotely?
Yes, CVE-2009-1939 can be exploited remotely by attackers to inject arbitrary web scripts.
5
What type of vulnerability is CVE-2009-1939?
CVE-2009-1939 is a cross-site scripting (XSS) vulnerability.