CVE-2011-4909
Multiple cross-site scripting (XSS) vulnerabilities in Joomla!
MEDIUM
Joomla CMS
Description
Multiple cross-site scripting (XSS) vulnerabilities in Joomla! before 1.5.12 allow remote attackers to inject arbitrary web script or HTML via the HTTP_REFERER header to (1) components/com_content/views/article/tmpl/form.php, (2) components/com_user/controller.php, (3) plugins/system/legacy/html.php, or (4) templates/beez/html/com_content/article/form.php.
Sévérité
4.3
Moyenne · CVSS 2.0
AV:N/AC:M/Au:N/C:N/I:P/A:N
Score retenu : NVD
| Source | Sévérité d'origine | CVSS |
|---|---|---|
| NVD | MEDIUM | 4.3 (v2.0) |
Produit et versions
- Produit
- Joomla CMS
- Corrigée dans
- Non précisée
- Publiée
- 07/10/2012
- Modifiée
- 16/06/2026
- CWE
- CWE-79
Versions concernées
- jusqu'à 1.5.11
- 1.5.0 – 1.5.0
- 1.5.1 – 1.5.1
- 1.5.2 – 1.5.2
- 1.5.3 – 1.5.3
- 1.5.4 – 1.5.4
- 1.5.5 – 1.5.5
- 1.5.6 – 1.5.6
- 1.5.7 – 1.5.7
- 1.5.8 – 1.5.8
- 1.5.9 – 1.5.9
- 1.5.10 – 1.5.10
Sources
- NVD CVE-2011-4909 vu
Ces informations proviennent des sources ci-dessus ; CVE Oyer n'y ajoute aucune interprétation.
Historique
- Détectée via nvd26/09/2026 09:34 UTC