CVE-2011-2710: XSS
Multiple cross-site scripting (XSS) vulnerabilities in Joomla! before 1.7.0 allow remote attackers to inject arbitrary web script or HTML via (1) the URI to includes/application.php, reachable through index.php; and, when Internet Explorer or Konqueror is used, (2) allow remote attackers to inject arbitrary web script or HTML via the searchword parameter in a search action to index.php in the comsearch component. NOTE: vector 2 exists because of an incomplete fix for CVE-2011-2509.5.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-2710?
CVE-2011-2710 is classified as a moderate severity vulnerability due to its potential for causing cross-site scripting attacks.
How do I fix CVE-2011-2710?
To fix CVE-2011-2710, you should upgrade to Joomla! version 1.7.0 or later, which includes the necessary security patches.
Which versions of Joomla! are affected by CVE-2011-2710?
CVE-2011-2710 affects various Joomla! versions prior to 1.7.0, including 1.5.x and 1.6.x series.
What type of vulnerability is CVE-2011-2710?
CVE-2011-2710 is a cross-site scripting (XSS) vulnerability that allows remote attackers to inject arbitrary web script or HTML.
Can CVE-2011-2710 be exploited in all web browsers?
CVE-2011-2710 can be particularly exploited in web browsers like Internet Explorer and Konqueror, which may render it differently.