First published: Wed Jan 06 2010(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in the Joomulus (mod_joomulus) module 2.0 for Joomla! allow remote attackers to inject arbitrary web script or HTML via the tagcloud parameter in a tags action to (1) tagcloud_ell.swf, (2) tagcloud_eng.swf, (3) tagcloud_por.swf, (4) tagcloud_rus.swf, and possibly (5) tagcloud_jpn.swf. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Joomlabear Joomulus | =2.0 | |
Joomla |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-4573 is classified as a medium severity vulnerability due to its potential for cross-site scripting attacks.
To fix CVE-2009-4573, users should update to the latest version of the Joomulus module or apply security patches provided by the developer.
CVE-2009-4573 is a vulnerability that allows remote attackers to inject arbitrary web scripts or HTML in the Joomulus module for Joomla! via the tagcloud parameter.
CVE-2009-4573 affects version 2.0 of the Joomulus module for Joomla!.
Yes, CVE-2009-4573 can be exploited remotely by attackers to perform cross-site scripting attacks.