Vulnérabilités

Vulnérabilités

Joomla CMS et extensions — une fiche par CVE, toutes sources fusionnées.

1624 résultats

CVE-2008-4764 Directory traversal vulnerability in the eXtplorer module (com_extplorer) 2.0.0 RC2 and earlier in Joomla! com_extplorer · 1 source · MEDIUM CVSS 5.0 CVE-2008-4715 SQL injection vulnerability in the Jpad (com_jpad) 1.0 component for Joomla! jpad · 1 source · HIGH CVSS 7.5 CVE-2008-4668 Directory traversal vulnerability in the Image Browser (com_imagebrowser) 0.1.5 component for Joomla! com_imagebrowser · 1 source · HIGH CVSS 9.0 CVE-2008-4623 SQL injection vulnerability in the DS-Syndicate (com_ds-syndicate) component 1.1.1 for Joomla allows remote attackers to execute arbitrary SQL commands via the… com_ds-syndicate · 1 source · HIGH CVSS 7.5 CVE-2008-4617 SQL injection vulnerability in the actualite module 1.0 for Joomla! Extension Joomla (identification incertaine) · 1 source · HIGH CVSS 7.5 CVE-2008-4107 The (1) rand and (2) mt_rand functions in PHP 5.2.6 do not produce cryptographically strong random numbers, which allows attackers to leverage exposures in pro… Joomla CMS · 1 source · MEDIUM CVSS 5.1 CVE-2008-4105 JRequest in Joomla! 1.5 before 1.5.7 does not sanitize variables that were set with JRequest::setVar, which allows remote attackers to conduct "variable inject… Joomla CMS · 1 source · HIGH CVSS 7.5 CVE-2008-4104 Joomla! Open Redirect vulnerability Joomla CMS · 2 sources · MEDIUM CVSS 5.8 CVE-2008-4103 The mailto (aka com_mailto) component in Joomla! com_mailto · 1 source · MEDIUM CVSS 5.0 CVE-2008-4102 Joomla! 1.5 before 1.5.7 initializes PHP's PRNG with a weak seed, which makes it easier for attackers to guess the pseudo-random values produced by PHP's mt_ra… Joomla CMS · 1 source · HIGH CVSS 7.5 CVE-2008-3681 components/com_user/models/reset.php in Joomla! com_user · 1 source · HIGH CVSS 7.5 CVE-2008-3586 SQL injection vulnerability in the EZ Store (com_ezstore) component for Joomla! com_ezstore · 1 source · HIGH CVSS 7.5 CVE-2008-3498 SQL injection vulnerability in the nBill (com_netinvoice) component 1.2.0 SP1 for Joomla! com_netinvoice · 1 source · HIGH CVSS 7.5 CVE-2008-3265 SQL injection vulnerability in the DT Register (com_dtregister) 2.2.3 component for Joomla! com_dtregister · 1 source · MEDIUM CVSS 6.8 CVE-2008-3228 Joomla! doesn't configure .htaccess to apply certain security checks that "block common exploits" to SEF URLs Joomla CMS · 2 sources · HIGH CVSS 7.5 CVE-2008-3227 Joomla! Open Redirect vulnerability Joomla CMS · 2 sources · HIGH CVSS 7.5 CVE-2008-3226 Joomla! allows attackers to access cached pages Joomla CMS · 2 sources · MEDIUM CVSS 5.0 CVE-2008-3225 Joomla! before 1.5.4 allows attackers to access administration functionality, which has unknown impact and attack vectors related to a missing "LDAP security f… Joomla CMS · 1 source · HIGH CVSS 10.0 CVE-2008-3132 SQL injection vulnerability in the beamospetition (com_beamospetition) component for Joomla! com_beamospetition · 1 source · HIGH CVSS 7.5 CVE-2008-3083 SQL injection vulnerability in Brightcode Weblinks (com_brightweblinks) component for Joomla! com_brightweblinks · 1 source · HIGH CVSS 7.5