First published: Wed Jul 27 2011(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in Joomla! before 1.6.4 allow remote attackers to inject arbitrary web script or HTML via (1) the query string to the com_contact component, as demonstrated by the Itemid parameter to index.php; (2) the query string to the com_content component, as demonstrated by the filter_order parameter to index.php; (3) the query string to the com_newsfeeds component, as demonstrated by an arbitrary parameter to index.php; or (4) the option parameter in a reset.request action to index.php; and, when Internet Explorer or Konqueror is used, (5) allow remote attackers to inject arbitrary web script or HTML via the searchword parameter in a search action to index.php in the com_search component.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Joomla | =1.6-beta15 | |
Joomla | =1.6-beta12 | |
Joomla | =1.6-beta3 | |
Joomla | =1.5.11 | |
Joomla | =1.5.13 | |
Joomla | =1.5.3 | |
Joomla | =1.6-beta13 | |
Joomla | =1.5.2 | |
Joomla | =1.5.22 | |
Joomla | =1.5.9 | |
Joomla | =1.5.18 | |
Joomla | =1.6.1 | |
Joomla | =1.6-beta8 | |
Joomla | =1.6-beta5 | |
Joomla | =1.5.16 | |
Joomla | =1.5.4 | |
Joomla | =1.6.0 | |
Joomla | =1.5.10 | |
Joomla | =1.6-beta1 | |
Joomla | =1.6-beta6 | |
Joomla | =1.5.7 | |
Joomla | =1.5.0 | |
Joomla | <=1.6.3 | |
Joomla | =1.6-beta7 | |
Joomla | =1.6-beta14 | |
Joomla | =1.5.15 | |
Joomla | =1.5.6 | |
Joomla | =1.5.1 | |
Joomla | =1.6-beta11 | |
Joomla | =1.5.23 | |
Joomla | =1.5.17 | |
Joomla | =1.5.8 | |
Joomla | =1.6-beta2 | |
Joomla | =1.6-alpha2 | |
Joomla | =1.5.19 | |
Joomla | =1.6-alpha | |
Joomla | =1.6-beta4 | |
Joomla | =1.6-rc1 | |
Joomla | =1.6-beta9 | |
Joomla | =1.5.21 | |
Joomla | =1.6-beta10 | |
Joomla | =1.5.12 | |
Joomla | =1.5.5 | |
Joomla | =1.5.20 | |
Joomla | =1.5.15-rc | |
Joomla | =1.5.14 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-2509 has a moderate severity rating due to the potential for cross-site scripting attacks that can compromise user data.
To fix CVE-2011-2509, upgrade to Joomla! version 1.6.4 or later, or apply the available security patches.
CVE-2011-2509 affects the com_contact and com_content components of Joomla!.
Remote attackers can exploit CVE-2011-2509 by injecting arbitrary web scripts or HTML via vulnerable Joomla! installations.
CVE-2011-2509 is not a risk for current supported versions of Joomla! since affected versions are outdated.