CVE-2006-4466
Joomla! before 1.0.11 does not properly unset variables when the input data includes a numeric parameter with a value matching an alphanumeric parameter's hash…
MEDIUM
Joomla CMS
Description
Joomla! before 1.0.11 does not properly unset variables when the input data includes a numeric parameter with a value matching an alphanumeric parameter's hash value, which allows remote attackers to have an unspecified impact. NOTE: it could be argued that this vulnerability is due to a bug in the unset PHP command (CVE-2006-3017) and the proper fix should be in PHP; if so, then this should not be treated as a vulnerability in Joomla!.
Sévérité
5.0
Moyenne · CVSS 2.0
AV:N/AC:L/Au:N/C:N/I:P/A:N
Score retenu : NVD
| Source | Sévérité d'origine | CVSS |
|---|---|---|
| NVD | MEDIUM | 5.0 (v2.0) |
Produit et versions
- Produit
- Joomla CMS
- Corrigée dans
- Non précisée
- Publiée
- 31/08/2006
- Modifiée
- 16/06/2026
- CWE
- CWE-20
Versions concernées
- jusqu'à 1.0.10
- 1.0.9 – 1.0.9
Sources
- NVD CVE-2006-4466 vu
Ces informations proviennent des sources ci-dessus ; CVE Oyer n'y ajoute aucune interprétation.
Historique
- Détectée via nvd26/09/2026 09:26 UTC