CVE-2006-4476

Vulnérabilités

CVE-2006-4476

Multiple unspecified vulnerabilities in Joomla!

HIGH Joomla CMS

Multiple unspecified vulnerabilities in Joomla! before 1.0.11, related to "Injection Flaws," allow attackers to have an unknown impact via (1) globals.php, which uses include_once() instead of require(); (2) the $options variable; (3) Admin Upload Image; (4) ->load(); (5) content submissions when frontpage is selected; (6) the mosPageNav constructor; (7) saveOrder functions; (8) the absence of "exploit blocking rules" in htaccess; and (9) the ACL.

7.5 Élevée · CVSS 2.0

AV:N/AC:L/Au:N/C:P/I:P/A:P

Score retenu : NVD

SourceSévérité d'origineCVSS
NVDHIGH 7.5 (v2.0)
Produit
Joomla CMS
Corrigée dans
Non précisée
Publiée
31/08/2006
Modifiée
16/06/2026
CWE
CWE-264, CWE-94
  • jusqu'à 1.0.10
  • 1.0.9 – 1.0.9

Ces informations proviennent des sources ci-dessus ; CVE Oyer n'y ajoute aucune interprétation.

  1. Détectée via nvd26/09/2026 09:27 UTC