Vulnérabilités
Joomla CMS et extensions — une fiche par CVE, toutes sources fusionnées.
CVE-2008-4617
SQL injection vulnerability in the actualite module 1.0 for Joomla!
HIGH
CVSS 7.5
CVE-2008-4105
JRequest in Joomla! 1.5 before 1.5.7 does not sanitize variables that were set with JRequest::setVar, which allows remote attackers to conduct "variable inject…
HIGH
CVSS 7.5
CVE-2008-4102
Joomla! 1.5 before 1.5.7 initializes PHP's PRNG with a weak seed, which makes it easier for attackers to guess the pseudo-random values produced by PHP's mt_ra…
HIGH
CVSS 7.5
CVE-2008-3681
components/com_user/models/reset.php in Joomla!
HIGH
CVSS 7.5
CVE-2008-3586
SQL injection vulnerability in the EZ Store (com_ezstore) component for Joomla!
HIGH
CVSS 7.5
CVE-2008-3498
SQL injection vulnerability in the nBill (com_netinvoice) component 1.2.0 SP1 for Joomla!
HIGH
CVSS 7.5
CVE-2008-3228
Joomla! doesn't configure .htaccess to apply certain security checks that "block common exploits" to SEF URLs
HIGH
CVSS 7.5
CVE-2008-3227
Joomla! Open Redirect vulnerability
HIGH
CVSS 7.5
CVE-2008-3225
Joomla! before 1.5.4 allows attackers to access administration functionality, which has unknown impact and attack vectors related to a missing "LDAP security f…
HIGH
CVSS 10.0
CVE-2008-3132
SQL injection vulnerability in the beamospetition (com_beamospetition) component for Joomla!
HIGH
CVSS 7.5
CVE-2008-3083
SQL injection vulnerability in Brightcode Weblinks (com_brightweblinks) component for Joomla!
HIGH
CVSS 7.5
CVE-2008-2990
PHP remote file inclusion vulnerability in facileforms.frame.php in the FacileForms (com_facileforms) component 1.4.4 for Mambo and Joomla!
HIGH
CVSS 7.5
CVE-2008-2892
SQL injection vulnerability in the EXP Shop (com_expshop) component 1.0 for Joomla!
HIGH
CVSS 7.5
CVE-2008-2697
SQL injection vulnerability in the Rapid Recipe (com_rapidrecipe) component 1.6.6 and 1.6.7 for Joomla!
HIGH
CVSS 7.5
CVE-2008-2692
SQL injection vulnerability in the yvComment (com_yvcomment) component 1.16.0 and earlier for Joomla!
HIGH
CVSS 7.5
CVE-2008-2676
SQL injection vulnerability in the iJoomla News Portal (com_news_portal) component 1.0 and earlier for Joomla!
HIGH
CVSS 7.5
CVE-2008-2651
SQL injection vulnerability in the Joomla!
HIGH
CVSS 7.5
CVE-2008-2643
SQL injection vulnerability in the Bible Study (com_biblestudy) component before 6.0.7c for Joomla!
HIGH
CVSS 7.5
CVE-2008-2633
Multiple SQL injection vulnerabilities in the EXP JoomRadio (com_joomradio) component 1.0 for Joomla!
HIGH
CVSS 7.5
CVE-2008-2632
SQL injection vulnerability in the acctexp (com_acctexp) component 0.12.x and earlier for Joomla!
HIGH
CVSS 7.5