CVE-2009-3946: Infoleak
Published Nov 16, 2009
·Updated
Joomla! before 1.5.15 allows remote attackers to read an extension's XML file, and thereby obtain the extension's version number, via a direct request.
Affected Software
15 affected components
Joomla Joomla\!<=1.5.14
Joomla Joomla\!=1.5.0
Joomla Joomla\!=1.5.1
Joomla Joomla\!=1.5.2
Joomla Joomla\!=1.5.3
Joomla Joomla\!=1.5.4
Joomla Joomla\!=1.5.5
Joomla Joomla\!=1.5.6
Joomla Joomla\!=1.5.7
Joomla Joomla\!=1.5.8
Joomla Joomla\!=1.5.9
Joomla Joomla\!=1.5.10
Joomla Joomla\!=1.5.11
Joomla Joomla\!=1.5.12
Joomla Joomla\!=1.5.13
Event History
Nov 16, 2009
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2009-3946?
CVE-2009-3946 has been classified with a medium severity, allowing for potential information disclosure.
2
How do I fix CVE-2009-3946?
To fix CVE-2009-3946, upgrade Joomla! to version 1.5.15 or later.
3
What does CVE-2009-3946 exploit?
CVE-2009-3946 exploits a vulnerability that allows remote attackers to read an extension's XML file.
4
Which versions of Joomla! are affected by CVE-2009-3946?
Joomla! versions prior to 1.5.15, including 1.5.0 to 1.5.14, are affected by CVE-2009-3946.
5
Can CVE-2009-3946 lead to further vulnerabilities?
Yes, the information gathered through CVE-2009-3946 could assist attackers in exploiting other vulnerabilities in the system.