Vulnérabilités

Vulnérabilités

Joomla CMS et extensions — une fiche par CVE, toutes sources fusionnées.

399 résultats

CVE-2009-1940 Cross-site scripting (XSS) vulnerability in the administrator panel in the com_users core component for Joomla! Joomla CMS · 1 source · MEDIUM CVSS 4.3 CVE-2009-1939 Cross-site scripting (XSS) vulnerability in the JA_Purity template for Joomla! Joomla CMS · 1 source · MEDIUM CVSS 4.3 CVE-2009-1938 Cross-site scripting (XSS) vulnerability in Joomla! Joomla CMS · 1 source · MEDIUM CVSS 4.3 CVE-2009-1499 SQL injection vulnerability in the MailTo (aka com_mailto) component in Joomla! Joomla CMS · 1 source · HIGH CVSS 7.5 CVE-2009-1280 Multiple cross-site request forgery (CSRF) vulnerabilities in the com_media component for Joomla! Joomla CMS · 1 source · MEDIUM CVSS 6.8 CVE-2009-1279 Multiple cross-site scripting (XSS) vulnerabilities in Joomla! Joomla CMS · 1 source · LOW CVSS 2.6 CVE-2008-6299 Multiple cross-site scripting (XSS) vulnerabilities in Joomla! Joomla CMS · 1 source · LOW CVSS 3.5 CVE-2008-4122 Joomla! 1.5.8 does not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to capture this cookie by int… Joomla CMS · 1 source · HIGH CVSS 7.5 CVE-2008-5671 PHP remote file inclusion vulnerability in index.php in Joomla! Joomla CMS · 1 source · HIGH CVSS 7.5 X-ab2f3f0c6f852382 Vulnérabilités dans Joomla! Joomla CMS · 1 source · UNKNOWN CVE-2008-4107 The (1) rand and (2) mt_rand functions in PHP 5.2.6 do not produce cryptographically strong random numbers, which allows attackers to leverage exposures in pro… Joomla CMS · 1 source · MEDIUM CVSS 5.1 CVE-2008-4105 JRequest in Joomla! 1.5 before 1.5.7 does not sanitize variables that were set with JRequest::setVar, which allows remote attackers to conduct "variable inject… Joomla CMS · 1 source · HIGH CVSS 7.5 CVE-2008-4104 Joomla! Open Redirect vulnerability Joomla CMS · 2 sources · MEDIUM CVSS 5.8 CVE-2008-4102 Joomla! 1.5 before 1.5.7 initializes PHP's PRNG with a weak seed, which makes it easier for attackers to guess the pseudo-random values produced by PHP's mt_ra… Joomla CMS · 1 source · HIGH CVSS 7.5 CVE-2008-3228 Joomla! doesn't configure .htaccess to apply certain security checks that "block common exploits" to SEF URLs Joomla CMS · 2 sources · HIGH CVSS 7.5 CVE-2008-3227 Joomla! Open Redirect vulnerability Joomla CMS · 2 sources · HIGH CVSS 7.5 CVE-2008-3226 Joomla! allows attackers to access cached pages Joomla CMS · 2 sources · MEDIUM CVSS 5.0 CVE-2008-3225 Joomla! before 1.5.4 allows attackers to access administration functionality, which has unknown impact and attack vectors related to a missing "LDAP security f… Joomla CMS · 1 source · HIGH CVSS 10.0 CVE-2008-2990 PHP remote file inclusion vulnerability in facileforms.frame.php in the FacileForms (com_facileforms) component 1.4.4 for Mambo and Joomla! Joomla CMS · 1 source · HIGH CVSS 7.5 CVE-2008-2676 SQL injection vulnerability in the iJoomla News Portal (com_news_portal) component 1.0 and earlier for Joomla! Joomla CMS · 1 source · HIGH CVSS 7.5