First published: Thu Sep 10 2009(Updated: )
Cross-site scripting (XSS) vulnerability in gmap.php in the Almond Classifieds (com_aclassf) component 7.5 for Joomla! allows remote attackers to inject arbitrary web script or HTML via the addr parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Joomla | ||
AlmondSoft Almond Classifieds | =7.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-3155 is classified as a cross-site scripting (XSS) vulnerability.
To fix CVE-2009-3155, upgrade the Almond Classifieds component to a patched version or implement input validation and output encoding for the addr parameter.
CVE-2009-3155 affects the Almond Classifieds component version 7.5 for Joomla!.
Yes, CVE-2009-3155 allows remote attackers to inject arbitrary web scripts or HTML.
CVE-2009-3155 exploits the addr parameter in gmap.php to perform cross-site scripting attacks.