Vulnérabilités
Joomla CMS et extensions — une fiche par CVE, toutes sources fusionnées.
CVE-2008-4764
Directory traversal vulnerability in the eXtplorer module (com_extplorer) 2.0.0 RC2 and earlier in Joomla!
MEDIUM
CVSS 5.0
CVE-2008-4715
SQL injection vulnerability in the Jpad (com_jpad) 1.0 component for Joomla!
HIGH
CVSS 7.5
CVE-2008-4668
Directory traversal vulnerability in the Image Browser (com_imagebrowser) 0.1.5 component for Joomla!
HIGH
CVSS 9.0
CVE-2008-4623
SQL injection vulnerability in the DS-Syndicate (com_ds-syndicate) component 1.1.1 for Joomla allows remote attackers to execute arbitrary SQL commands via the…
HIGH
CVSS 7.5
CVE-2008-4617
SQL injection vulnerability in the actualite module 1.0 for Joomla!
HIGH
CVSS 7.5
CVE-2008-4107
The (1) rand and (2) mt_rand functions in PHP 5.2.6 do not produce cryptographically strong random numbers, which allows attackers to leverage exposures in pro…
MEDIUM
CVSS 5.1
CVE-2008-4105
JRequest in Joomla! 1.5 before 1.5.7 does not sanitize variables that were set with JRequest::setVar, which allows remote attackers to conduct "variable inject…
HIGH
CVSS 7.5
CVE-2008-4104
Joomla! Open Redirect vulnerability
MEDIUM
CVSS 5.8
CVE-2008-4103
The mailto (aka com_mailto) component in Joomla!
MEDIUM
CVSS 5.0
CVE-2008-4102
Joomla! 1.5 before 1.5.7 initializes PHP's PRNG with a weak seed, which makes it easier for attackers to guess the pseudo-random values produced by PHP's mt_ra…
HIGH
CVSS 7.5
CVE-2008-3681
components/com_user/models/reset.php in Joomla!
HIGH
CVSS 7.5
CVE-2008-3586
SQL injection vulnerability in the EZ Store (com_ezstore) component for Joomla!
HIGH
CVSS 7.5
CVE-2008-3498
SQL injection vulnerability in the nBill (com_netinvoice) component 1.2.0 SP1 for Joomla!
HIGH
CVSS 7.5
CVE-2008-3265
SQL injection vulnerability in the DT Register (com_dtregister) 2.2.3 component for Joomla!
MEDIUM
CVSS 6.8
CVE-2008-3228
Joomla! doesn't configure .htaccess to apply certain security checks that "block common exploits" to SEF URLs
HIGH
CVSS 7.5
CVE-2008-3227
Joomla! Open Redirect vulnerability
HIGH
CVSS 7.5
CVE-2008-3226
Joomla! allows attackers to access cached pages
MEDIUM
CVSS 5.0
CVE-2008-3225
Joomla! before 1.5.4 allows attackers to access administration functionality, which has unknown impact and attack vectors related to a missing "LDAP security f…
HIGH
CVSS 10.0
CVE-2008-3132
SQL injection vulnerability in the beamospetition (com_beamospetition) component for Joomla!
HIGH
CVSS 7.5
CVE-2008-3083
SQL injection vulnerability in Brightcode Weblinks (com_brightweblinks) component for Joomla!
HIGH
CVSS 7.5