Vulnérabilités

Vulnérabilités

Joomla CMS et extensions — une fiche par CVE, toutes sources fusionnées.

108 résultats

CVE-2008-6852 SQL injection vulnerability in the Ice Gallery (com_ice) component 0.5 beta 2 for Joomla! Joomla CMS · 1 source · HIGH CVSS 7.5 CVE-2009-1499 SQL injection vulnerability in the MailTo (aka com_mailto) component in Joomla! Joomla CMS · 1 source · HIGH CVSS 7.5 CVE-2008-4122 Joomla! 1.5.8 does not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to capture this cookie by int… Joomla CMS · 1 source · HIGH CVSS 7.5 CVE-2008-5671 PHP remote file inclusion vulnerability in index.php in Joomla! Joomla CMS · 1 source · HIGH CVSS 7.5 CVE-2008-4105 JRequest in Joomla! 1.5 before 1.5.7 does not sanitize variables that were set with JRequest::setVar, which allows remote attackers to conduct "variable inject… Joomla CMS · 1 source · HIGH CVSS 7.5 CVE-2008-4102 Joomla! 1.5 before 1.5.7 initializes PHP's PRNG with a weak seed, which makes it easier for attackers to guess the pseudo-random values produced by PHP's mt_ra… Joomla CMS · 1 source · HIGH CVSS 7.5 CVE-2008-3228 Joomla! doesn't configure .htaccess to apply certain security checks that "block common exploits" to SEF URLs Joomla CMS · 2 sources · HIGH CVSS 7.5 CVE-2008-3227 Joomla! Open Redirect vulnerability Joomla CMS · 2 sources · HIGH CVSS 7.5 CVE-2008-3225 Joomla! before 1.5.4 allows attackers to access administration functionality, which has unknown impact and attack vectors related to a missing "LDAP security f… Joomla CMS · 1 source · HIGH CVSS 10.0 CVE-2008-2990 PHP remote file inclusion vulnerability in facileforms.frame.php in the FacileForms (com_facileforms) component 1.4.4 for Mambo and Joomla! Joomla CMS · 1 source · HIGH CVSS 7.5 CVE-2008-2676 SQL injection vulnerability in the iJoomla News Portal (com_news_portal) component 1.0 and earlier for Joomla! Joomla CMS · 1 source · HIGH CVSS 7.5 CVE-2008-2633 Multiple SQL injection vulnerabilities in the EXP JoomRadio (com_joomradio) component 1.0 for Joomla! Joomla CMS · 1 source · HIGH CVSS 7.5 CVE-2008-2632 SQL injection vulnerability in the acctexp (com_acctexp) component 0.12.x and earlier for Joomla! Joomla CMS · 1 source · HIGH CVSS 7.5 CVE-2008-2568 SQL injection vulnerability in the Simple Shop Galore (com_simpleshop) component 3.4 and earlier for Joomla! Joomla CMS · 1 source · HIGH CVSS 7.5 CVE-2008-2564 SQL injection vulnerability in the JotLoader (com_jotloader) component 1.2.1.a and earlier for Joomla! Joomla CMS · 1 source · HIGH CVSS 7.5 CVE-2008-1935 SQL injection vulnerability in the Filiale 1.0.4 component for Joomla! Joomla CMS · 1 source · HIGH CVSS 7.5 CVE-2008-0829 SQL injection vulnerability in jooget.php in the Joomlapixel Jooget! Joomla CMS · 1 source · HIGH CVSS 7.5 CVE-2008-0795 SQL injection vulnerability in index.php in the MGFi XfaQ (com_xfaq) 1.2 component for Mambo and Joomla! Joomla CMS · 1 source · HIGH CVSS 7.5 CVE-2008-0561 SQL injection vulnerability in index.php in the Arthur Konze AkoGallery (com_akogallery) 2.5 beta component for Mambo and Joomla! Joomla CMS · 1 source · HIGH CVSS 7.5 CVE-2008-0517 SQL injection vulnerability in index.php in the Darko Selesi EstateAgent (com_estateagent) 0.1 component for Mambo 4.5.x and Joomla! Joomla CMS · 1 source · HIGH CVSS 7.5