Joomla! is prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input.
Credit:
The information has been provided by Janek Vind .
The original article can be found at: http://www.securityfocus.com/bid/53382
Vulnerable Systems:
* Joomla Joomla! 1.5.26
* Joomla Joomla 1.5.24
* Joomla Joomla 1.5.22
* Joomla Joomla 1.5.21
* Joomla Joomla 1.5.20
* Joomla Joomla 1.5.19
* Joomla Joomla 1.5.18
* Joomla Joomla 1.5.17
* Joomla Joomla 1.5.16
* Joomla Joomla 1.5.15
* Joomla Joomla 1.5.14
* Joomla Joomla 1.5.13
* Joomla Joomla 1.5.12
* Joomla Joomla 1.5.11
* Joomla Joomla 1.5.10
* Joomla Joomla 1.5.9
* Joomla Joomla 1.5.8
* Joomla Joomla 1.5.7
* Joomla Joomla 1.5.6
* Joomla Joomla 1.5.5
* Joomla Joomla 1.5.4
* Joomla Joomla 1.5.3
* Joomla Joomla 1.5.2
* Joomla Joomla 1.5.1
* Joomla Joomla 1.5.25
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may let the attacker steal cookie-based authentication credentials and launch other attacks.
Vendor Status:
Joomla JCE had issued an update for this vulnerability
Patch Availability:
http://www.joomla.org/download.html
Disclosure Timeline:
Initial Release: May 03 2012
Please enable JavaScript to view the comments powered by Disqus.
blog comments powered by