Vulnérabilités
Joomla CMS et extensions — une fiche par CVE, toutes sources fusionnées.
CVE-2008-6852
SQL injection vulnerability in the Ice Gallery (com_ice) component 0.5 beta 2 for Joomla!
HIGH
CVSS 7.5
CVE-2009-1499
SQL injection vulnerability in the MailTo (aka com_mailto) component in Joomla!
HIGH
CVSS 7.5
CVE-2008-4122
Joomla! 1.5.8 does not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to capture this cookie by int…
HIGH
CVSS 7.5
CVE-2008-5671
PHP remote file inclusion vulnerability in index.php in Joomla!
HIGH
CVSS 7.5
CVE-2008-4105
JRequest in Joomla! 1.5 before 1.5.7 does not sanitize variables that were set with JRequest::setVar, which allows remote attackers to conduct "variable inject…
HIGH
CVSS 7.5
CVE-2008-4102
Joomla! 1.5 before 1.5.7 initializes PHP's PRNG with a weak seed, which makes it easier for attackers to guess the pseudo-random values produced by PHP's mt_ra…
HIGH
CVSS 7.5
CVE-2008-3228
Joomla! doesn't configure .htaccess to apply certain security checks that "block common exploits" to SEF URLs
HIGH
CVSS 7.5
CVE-2008-3227
Joomla! Open Redirect vulnerability
HIGH
CVSS 7.5
CVE-2008-3225
Joomla! before 1.5.4 allows attackers to access administration functionality, which has unknown impact and attack vectors related to a missing "LDAP security f…
HIGH
CVSS 10.0
CVE-2008-2990
PHP remote file inclusion vulnerability in facileforms.frame.php in the FacileForms (com_facileforms) component 1.4.4 for Mambo and Joomla!
HIGH
CVSS 7.5
CVE-2008-2676
SQL injection vulnerability in the iJoomla News Portal (com_news_portal) component 1.0 and earlier for Joomla!
HIGH
CVSS 7.5
CVE-2008-2633
Multiple SQL injection vulnerabilities in the EXP JoomRadio (com_joomradio) component 1.0 for Joomla!
HIGH
CVSS 7.5
CVE-2008-2632
SQL injection vulnerability in the acctexp (com_acctexp) component 0.12.x and earlier for Joomla!
HIGH
CVSS 7.5
CVE-2008-2568
SQL injection vulnerability in the Simple Shop Galore (com_simpleshop) component 3.4 and earlier for Joomla!
HIGH
CVSS 7.5
CVE-2008-2564
SQL injection vulnerability in the JotLoader (com_jotloader) component 1.2.1.a and earlier for Joomla!
HIGH
CVSS 7.5
CVE-2008-1935
SQL injection vulnerability in the Filiale 1.0.4 component for Joomla!
HIGH
CVSS 7.5
CVE-2008-0829
SQL injection vulnerability in jooget.php in the Joomlapixel Jooget!
HIGH
CVSS 7.5
CVE-2008-0795
SQL injection vulnerability in index.php in the MGFi XfaQ (com_xfaq) 1.2 component for Mambo and Joomla!
HIGH
CVSS 7.5
CVE-2008-0561
SQL injection vulnerability in index.php in the Arthur Konze AkoGallery (com_akogallery) 2.5 beta component for Mambo and Joomla!
HIGH
CVSS 7.5
CVE-2008-0517
SQL injection vulnerability in index.php in the Darko Selesi EstateAgent (com_estateagent) 0.1 component for Mambo 4.5.x and Joomla!
HIGH
CVSS 7.5