CVE-2010-3712

Vulnérabilités

CVE-2010-3712

Cross-site scripting (XSS) vulnerability in Joomla!

MEDIUM Joomla CMS

Cross-site scripting (XSS) vulnerability in Joomla! 1.5.x before 1.5.21 and 1.6.x before 1.6.1 allows remote attackers to inject arbitrary web script or HTML via vectors involving "multiple encoded entities," as demonstrated by the query string to index.php in the com_weblinks or com_content component.

4.3 Moyenne · CVSS 2.0

AV:N/AC:M/Au:N/C:N/I:P/A:N

Score retenu : NVD

SourceSévérité d'origineCVSS
NVDMEDIUM 4.3 (v2.0)
Produit
Joomla CMS
Corrigée dans
Non précisée
Publiée
28/10/2010
Modifiée
16/06/2026
CWE
CWE-79
  • 1.5.0 – 1.5.0
  • 1.5.1 – 1.5.1
  • 1.5.2 – 1.5.2
  • 1.5.3 – 1.5.3
  • 1.5.4 – 1.5.4
  • 1.5.5 – 1.5.5
  • 1.5.6 – 1.5.6
  • 1.5.7 – 1.5.7
  • 1.5.8 – 1.5.8
  • 1.5.9 – 1.5.9
  • 1.5.10 – 1.5.10
  • 1.5.11 – 1.5.11
9 autres
  • 1.5.12 – 1.5.12
  • 1.5.13 – 1.5.13
  • 1.5.14 – 1.5.14
  • 1.5.15 – 1.5.15
  • 1.5.16 – 1.5.16
  • 1.5.17 – 1.5.17
  • 1.5.18 – 1.5.18
  • 1.5.19 – 1.5.19
  • 1.5.20 – 1.5.20

Ces informations proviennent des sources ci-dessus ; CVE Oyer n'y ajoute aucune interprétation.

  1. Détectée via nvd26/09/2026 09:34 UTC