CVE-2011-2710

Vulnérabilités

CVE-2011-2710

Multiple cross-site scripting (XSS) vulnerabilities in Joomla!

MEDIUM Joomla CMS

Multiple cross-site scripting (XSS) vulnerabilities in Joomla! before 1.7.0 allow remote attackers to inject arbitrary web script or HTML via (1) the URI to includes/application.php, reachable through index.php; and, when Internet Explorer or Konqueror is used, (2) allow remote attackers to inject arbitrary web script or HTML via the searchword parameter in a search action to index.php in the com_search component. NOTE: vector 2 exists because of an incomplete fix for CVE-2011-2509.5.

4.3 Moyenne · CVSS 2.0

AV:N/AC:M/Au:N/C:N/I:P/A:N

Score retenu : NVD

SourceSévérité d'origineCVSS
NVDMEDIUM 4.3 (v2.0)
Produit
Joomla CMS
Corrigée dans
Non précisée
Publiée
27/07/2011
Modifiée
16/06/2026
CWE
CWE-79
  • jusqu'à 1.6.6
  • 1.5.0 – 1.5.0
  • 1.5.1 – 1.5.1
  • 1.5.2 – 1.5.2
  • 1.5.3 – 1.5.3
  • 1.5.4 – 1.5.4
  • 1.5.5 – 1.5.5
  • 1.5.6 – 1.5.6
  • 1.5.7 – 1.5.7
  • 1.5.8 – 1.5.8
  • 1.5.9 – 1.5.9
  • 1.5.10 – 1.5.10
19 autres
  • 1.5.11 – 1.5.11
  • 1.5.12 – 1.5.12
  • 1.5.13 – 1.5.13
  • 1.5.14 – 1.5.14
  • 1.5.15 – 1.5.15
  • 1.5.16 – 1.5.16
  • 1.5.17 – 1.5.17
  • 1.5.18 – 1.5.18
  • 1.5.19 – 1.5.19
  • 1.5.20 – 1.5.20
  • 1.5.21 – 1.5.21
  • 1.5.22 – 1.5.22
  • 1.5.23 – 1.5.23
  • 1.6 – 1.6
  • 1.6.0 – 1.6.0
  • 1.6.1 – 1.6.1
  • 1.6.3 – 1.6.3
  • 1.6.4 – 1.6.4
  • 1.6.5 – 1.6.5

Ces informations proviennent des sources ci-dessus ; CVE Oyer n'y ajoute aucune interprétation.

  1. Détectée via nvd26/09/2026 09:34 UTC