First published: Wed Nov 23 2011(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in Joomla! 1.6.3 and earlier allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Joomla | =1.6-beta15 | |
Joomla | =1.6.4 | |
Joomla | =1.6-beta12 | |
Joomla | =1.6-beta3 | |
Joomla | =1.6-beta13 | |
Joomla | =1.6.5 | |
Joomla | =1.6.1 | |
Joomla | =1.6-beta8 | |
Joomla | =1.6-beta5 | |
Joomla | =1.6.0 | |
Joomla | =1.6-beta1 | |
Joomla | =1.6-beta6 | |
Joomla | <=1.6.3 | |
Joomla | =1.6-beta7 | |
Joomla | =1.6.6 | |
Joomla | =1.6-beta14 | |
Joomla | =1.6-beta11 | |
Joomla | =1.6-beta2 | |
Joomla | =1.6-alpha2 | |
Joomla | =1.6-alpha | |
Joomla | =1.6-beta4 | |
Joomla | =1.6-rc1 | |
Joomla | =1.6-beta9 | |
Joomla | =1.6-beta10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-4332 has a moderate severity level due to its potential for exploitation via cross-site scripting.
To fix CVE-2011-4332, you should update Joomla! to version 1.6.6 or later, which addresses the XSS vulnerabilities.
CVE-2011-4332 allows attackers to perform cross-site scripting attacks, potentially leading to the theft of sensitive information.
CVE-2011-4332 affects Joomla! versions 1.6.3 and earlier, including several beta and alpha versions.
Yes, CVE-2011-4332 can be exploited remotely by attackers to inject arbitrary web script or HTML.