First published: Wed Jul 27 2011(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in Joomla! before 1.7.0 allow remote attackers to inject arbitrary web script or HTML via (1) the URI to includes/application.php, reachable through index.php; and, when Internet Explorer or Konqueror is used, (2) allow remote attackers to inject arbitrary web script or HTML via the searchword parameter in a search action to index.php in the com_search component. NOTE: vector 2 exists because of an incomplete fix for CVE-2011-2509.5.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Joomla | =1.6-beta15 | |
Joomla | =1.6.4 | |
Joomla | =1.6-beta12 | |
Joomla | =1.6-beta3 | |
Joomla | =1.5.11 | |
Joomla | =1.6.3 | |
Joomla | =1.5.13 | |
Joomla | =1.5.3 | |
Joomla | =1.6-beta13 | |
Joomla | =1.5.2 | |
Joomla | =1.5.22 | |
Joomla | =1.6.5 | |
Joomla | =1.5.9 | |
Joomla | =1.5.18 | |
Joomla | <=1.6.6 | |
Joomla | =1.6.1 | |
Joomla | =1.6-beta8 | |
Joomla | =1.6-beta5 | |
Joomla | =1.5.16 | |
Joomla | =1.5.4 | |
Joomla | =1.6.0 | |
Joomla | =1.5.10 | |
Joomla | =1.6-beta1 | |
Joomla | =1.6-beta6 | |
Joomla | =1.5.7 | |
Joomla | =1.5.0 | |
Joomla | =1.6-beta7 | |
Joomla | =1.6-beta14 | |
Joomla | =1.5.15 | |
Joomla | =1.5.6 | |
Joomla | =1.5.1 | |
Joomla | =1.6-beta11 | |
Joomla | =1.5.23 | |
Joomla | =1.5.17 | |
Joomla | =1.5.8 | |
Joomla | =1.6-beta2 | |
Joomla | =1.6-alpha2 | |
Joomla | =1.5.19 | |
Joomla | =1.6-alpha | |
Joomla | =1.6-beta4 | |
Joomla | =1.6-rc1 | |
Joomla | =1.6-beta9 | |
Joomla | =1.5.21 | |
Joomla | =1.6-beta10 | |
Joomla | =1.5.12 | |
Joomla | =1.5.5 | |
Joomla | =1.5.20 | |
Joomla | =1.5.15-rc | |
Joomla | =1.5.14 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.