CVE-2010-1649
Joomla! vulnerable to Cross-site Scripting
MEDIUM
Joomla CMS
Description
Multiple cross-site scripting (XSS) vulnerabilities in the back end in Joomla! 1.5 through 1.5.17 allow remote attackers to inject arbitrary web script or HTML via unknown vectors related to "various administrator screens," possibly the search parameter in administrator/index.php.
Sévérité
4.3
Moyenne · CVSS 2.0
AV:N/AC:M/Au:N/C:N/I:P/A:N
Score retenu : NVD
| Source | Sévérité d'origine | CVSS |
|---|---|---|
| NVD | MEDIUM | 4.3 (v2.0) |
| GitHub Advisories | medium | — |
| OSV | MODERATE | — |
Produit et versions
- Produit
- Joomla CMS
- Corrigée dans
- 1.5.18
- Publiée
- 08/06/2010
- Modifiée
- 16/06/2026
- CWE
- CWE-79
Versions concernées
- 1.5 – 1.5.17
Sources
- NVD CVE-2010-1649 vu
- GitHub Advisories GHSA-fj57-vhrc-73r7 vu
- OSV GHSA-fj57-vhrc-73r7 vu
Ces informations proviennent des sources ci-dessus ; CVE Oyer n'y ajoute aucune interprétation.
Historique
- Source ajoutée : nvd26/09/2026 09:34 UTC
- Source ajoutée : osv26/09/2026 09:27 UTC
- Détectée via github26/09/2026 09:27 UTC