CVE-2006-4476
Multiple unspecified vulnerabilities in Joomla!
HIGH
Joomla CMS
Description
Multiple unspecified vulnerabilities in Joomla! before 1.0.11, related to "Injection Flaws," allow attackers to have an unknown impact via (1) globals.php, which uses include_once() instead of require(); (2) the $options variable; (3) Admin Upload Image; (4) ->load(); (5) content submissions when frontpage is selected; (6) the mosPageNav constructor; (7) saveOrder functions; (8) the absence of "exploit blocking rules" in htaccess; and (9) the ACL.
Sévérité
7.5
Élevée · CVSS 2.0
AV:N/AC:L/Au:N/C:P/I:P/A:P
Score retenu : NVD
| Source | Sévérité d'origine | CVSS |
|---|---|---|
| NVD | HIGH | 7.5 (v2.0) |
Produit et versions
- Produit
- Joomla CMS
- Corrigée dans
- Non précisée
- Publiée
- 31/08/2006
- Modifiée
- 16/06/2026
- CWE
- CWE-264, CWE-94
Versions concernées
- jusqu'à 1.0.10
- 1.0.9 – 1.0.9
Sources
- NVD CVE-2006-4476 vu
Ces informations proviennent des sources ci-dessus ; CVE Oyer n'y ajoute aucune interprétation.
Historique
- Détectée via nvd26/09/2026 09:27 UTC