First published: Tue Jan 11 2011(Updated: )
Cross-site scripting (XSS) vulnerability in the com_search module for Joomla! 1.0.x through 1.0.15 allows remote attackers to inject arbitrary web script or HTML via the ordering parameter to index.php.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Joomla | ||
Joomla | =1.0.0 | |
Joomla | =1.0.15 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-0005 is considered a medium severity vulnerability due to its potential for cross-site scripting attacks.
To fix CVE-2011-0005, update your Joomla! installation to a version that is not vulnerable, such as Joomla! 1.0.16 or later.
CVE-2011-0005 allows attackers to perform cross-site scripting (XSS) attacks, potentially leading to session hijacking or website defacement.
CVE-2011-0005 affects Joomla! versions 1.0.0 through 1.0.15.
If upgrading is not possible, consider implementing web application firewalls and input validation to help mitigate the risks of CVE-2011-0005.