First published: Thu Sep 06 2012(Updated: )
Cross-site scripting (XSS) vulnerability in Joomla! 1.6 and 1.7.x before 1.7.4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2012-0820.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Joomla | =1.6-alpha | |
Joomla | =1.6-alpha2 | |
Joomla | =1.6-beta1 | |
Joomla | =1.6-beta10 | |
Joomla | =1.6-beta11 | |
Joomla | =1.6-beta12 | |
Joomla | =1.6-beta13 | |
Joomla | =1.6-beta14 | |
Joomla | =1.6-beta15 | |
Joomla | =1.6-beta2 | |
Joomla | =1.6-beta3 | |
Joomla | =1.6-beta4 | |
Joomla | =1.6-beta5 | |
Joomla | =1.6-beta6 | |
Joomla | =1.6-beta7 | |
Joomla | =1.6-beta8 | |
Joomla | =1.6-beta9 | |
Joomla | =1.6-rc1 | |
Joomla | =1.6.0 | |
Joomla | =1.6.1 | |
Joomla | =1.6.3 | |
Joomla | =1.6.4 | |
Joomla | =1.6.5 | |
Joomla | =1.6.6 | |
Joomla | =1.7.0 | |
Joomla | =1.7.1 | |
Joomla | =1.7.2 | |
Joomla | =1.7.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-0822 is classified as a medium severity vulnerability due to its potential to allow remote attackers to execute arbitrary web scripts.
To fix CVE-2012-0822, you should upgrade to Joomla! version 1.7.4 or later, which addresses this vulnerability.
CVE-2012-0822 affects Joomla! versions 1.6.x and 1.7.x prior to 1.7.4.
CVE-2012-0822 is a Cross-Site Scripting (XSS) vulnerability that allows the injection of arbitrary web scripts.
Yes, CVE-2012-0822 can be exploited remotely by attackers to inject scripts into affected Joomla! sites.