Looking for only exploits? Click HERE
Additional feeds: (RSS) - or - (JSON)

NVD CVE-2006-3530 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2006-3530
Description
PHP remote file inclusion vulnerability in com_pccookbook/pccookbook.php in the PccookBook Component for Mambo and Joomla 0.3 and possibly up to 1.3.1, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via the mosConfig_absolute_path parameter.

CVSS
(5.1) AV:N/AC:H/Au:N/C:P/I:P/A:P
Exploits
Milw0rm 2024 (site down: refer to www.exploit-db.org 2024) - [Search]
References
BID 18919 - [Search]
CWE CWE-94 - [Search]
SECUNIA 21015 - [Search]
VUPEN ADV-2006-2739 - [Search]
XFDB 27641 - [Search]

Dates
Initial Date Seen [2006-07-12 17:05:00]
Last Date Updated [2011-03-07 21:38:51]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2006-3750 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2006-3750
Description
PHP remote file inclusion vulnerability in server.php in the Hashcash Component (com_hashcash) 1.2.1 for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.

CVSS
(5.1) AV:N/AC:H/Au:N/C:P/I:P/A:P
Exploits
Milw0rm 2026 (site down: refer to www.exploit-db.org 2026) - [Search]
References
CWE CWE-94 - [Search]
SECUNIA 21053 - [Search]
VUPEN ADV-2006-2802 - [Search]
XFDB 27720 - [Search]

Dates
Initial Date Seen [2006-07-21 10:03:00]
Last Date Updated [2011-03-07 21:39:24]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2006-3773 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2006-3773
Description
PHP remote file inclusion vulnerability in smf.php in the SMF-Forum 1.3.1.3 Bridge Component (com_smf) For Joomla! and Mambo 4.5.3+ allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.

CVSS
(5.1) AV:N/AC:H/Au:N/C:P/I:P/A:P
Exploits
Milw0rm 2021 (site down: refer to www.exploit-db.org 2021) - [Search]
References
BID 18924 - [Search]
CWE CWE-94 - [Search]
SECUNIA 21079 - [Search]
VUPEN ADV-2006-2846 - [Search]
XFDB 27777 - [Search]

Dates
Initial Date Seen [2006-07-24 08:19:00]
Last Date Updated [2011-03-07 21:39:28]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2006-3774 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2006-3774
Description
PHP remote file inclusion vulnerability in performs.php in the perForms component (com_performs) 1.0 and earlier for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.

CVSS
(5.1) AV:N/AC:H/Au:N/C:P/I:P/A:P
References
BID 18968 - [Search]
CWE CWE-94 - [Search]
SECUNIA 21044 - [Search]
VUPEN ADV-2006-2786 - [Search]
XFDB 27724 - [Search]

Dates
Initial Date Seen [2006-07-24 08:19:00]
Last Date Updated [2011-03-07 21:39:28]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2006-3969 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2006-3969
Description
PHP remote file inclusion vulnerability in administrator/components/com_colophon/admin.colophon.php in Colophon 1.2 and earlier for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploits
Milw0rm 2085 (site down: refer to www.exploit-db.org 2085) - [Search]
References
BID 19252 - [Search]
OSVDB 27659 - [Search]
SECUNIA 21288 - [Search]
VUPEN ADV-2006-3057 - [Search]
XFDB 28076 - [Search]

Dates
Initial Date Seen [2006-08-01 18:04:00]
Last Date Updated [2011-03-07 21:39:57]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2006-3970 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2006-3970
Description
PHP remote file inclusion vulnerability in lmo.php in the LMO Component (com_lmo) 1.0b2 and earlier for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploits
Milw0rm 2092 (site down: refer to www.exploit-db.org 2092) - [Search]
References
VUPEN ADV-2006-3063 - [Search]
XFDB 28079 - [Search]

Dates
Initial Date Seen [2006-08-01 18:04:00]
Last Date Updated [2011-03-07 21:39:57]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2006-3990 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2006-3990
Description
Multiple PHP remote file inclusion vulnerabilities in Paul M. Jones Savant2, possibly when used with the com_mtree component for Mambo and Joomla!, allow remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter in (1) Savant2_Plugin_stylesheet.php, (2) Savant2_Compiler_basic.php, (3) Savant2_Error_pear.php, (4) Savant2_Error_stack.php, (5) Savant2_Filter_colorizeCode.php, (6) Savant2_Filter_trimwhitespace.php, (7) Savant2_Plugin_ahref.php, (8) Savant2_Plugin_ahrefcontact.php, (9) Savant2_Plugin_ahreflisting.php, (10) Savant2_Plugin_ahreflistingimage.php, (11) Savant2_Plugin_ahrefmap.php, (12) Savant2_Plugin_ahrefownerlisting.php, (13) Savant2_Plugin_ahrefprint.php, (14) Savant2_Plugin_ahrefrating.php, (15) Savant2_Plugin_ahrefrecommend.php, (16) Savant2_Plugin_ahrefreport.php, (17) Savant2_Plugin_ahrefreview.php, (18) Savant2_Plugin_ahrefvisit.php, (19) Savant2_Plugin_checkbox.php, (20) Savant2_Plugin_cycle.php, (21) Savant2_Plugin_dateformat.php, (22) Savant2_Plugin_editor.php, (23) Savant2_Plugin_form.php, (24) Savant2_Plugin_image.php, (25) Savant2_Plugin_input.php, (26) Savant2_Plugin_javascript.php, (27) Savant2_Plugin_listalpha.php, (28) Savant2_Plugin_listingname.php, (29) Savant2_Plugin_modify.php, (30) Savant2_Plugin_mtpath.php, (31) Savant2_Plugin_options.php, (32) Savant2_Plugin_radios.php, (33) Savant2_Plugin_rating.php, or (34) Savant2_Plugin_textarea.php.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
References
BID 19151 - [Search]
OSVDB 28679 - [Search]
OSVDB 28680 - [Search]
OSVDB 28681 - [Search]
OSVDB 28682 - [Search]
OSVDB 28683 - [Search]
OSVDB 28684 - [Search]
OSVDB 28685 - [Search]
OSVDB 28686 - [Search]
OSVDB 28687 - [Search]
OSVDB 28688 - [Search]
OSVDB 28689 - [Search]
OSVDB 28690 - [Search]
OSVDB 28691 - [Search]
OSVDB 28692 - [Search]
OSVDB 28693 - [Search]
OSVDB 28694 - [Search]
OSVDB 28695 - [Search]
OSVDB 28696 - [Search]
OSVDB 28697 - [Search]
OSVDB 28698 - [Search]
OSVDB 28699 - [Search]
OSVDB 28700 - [Search]
OSVDB 28701 - [Search]
OSVDB 28702 - [Search]
OSVDB 28703 - [Search]
OSVDB 28704 - [Search]
OSVDB 28705 - [Search]
OSVDB 28706 - [Search]
OSVDB 28707 - [Search]
OSVDB 28708 - [Search]
OSVDB 28709 - [Search]
OSVDB 28710 - [Search]
OSVDB 28711 - [Search]
OSVDB 28712 - [Search]
XFDB 27906 - [Search]

Dates
Initial Date Seen [2006-08-04 20:04:00]
Last Date Updated [2008-09-05 17:08:35]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2006-3995 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2006-3995
Description
Multiple PHP remote file inclusion vulnerabilities in (1) uhp_config.php, and possibly (2) footer.php, (3) functions.php, (4) install.uhp.php, (5) toolbar.uhp.html.php, (6) uhp.class.php, and (7) uninstall.uhp.php, in the UHP (User Home Pages) 0.5 component (aka com_uhp) for Mambo or Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.

CVSS
(5.1) AV:N/AC:H/Au:N/C:P/I:P/A:P
Exploits
Milw0rm 3553 (site down: refer to www.exploit-db.org 3553) - [Search]
Milw0rm 2089 (site down: refer to www.exploit-db.org 2089) - [Search]
References
BID 19233 - [Search]
BID 23113 - [Search]
CWE CWE-94 - [Search]
OSVDB 27651 - [Search]
OSVDB 27652 - [Search]
OSVDB 28111 - [Search]
OSVDB 28112 - [Search]
OSVDB 28113 - [Search]
SECUNIA 21305 - [Search]
VUPEN ADV-2006-3056 - [Search]
XFDB 28080 - [Search]
XFDB 33178 - [Search]

Dates
Initial Date Seen [2006-08-04 20:04:00]
Last Date Updated [2011-03-07 21:40:00]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2006-4074 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2006-4074
Description
PHP remote file inclusion vulnerability in lib/tpl/default/main.php in the JD-Wiki Component (com_jd-wiki) 1.0.2 and earlier for Joomla!, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.

CVSS
(5.1) AV:N/AC:H/Au:N/C:P/I:P/A:P
Exploits
Milw0rm 2125 (site down: refer to www.exploit-db.org 2125) - [Search]
References
BID 19373 - [Search]
CWE CWE-94 - [Search]
SECUNIA 21389 - [Search]
VUPEN ADV-2006-3192 - [Search]
XFDB 28253 - [Search]

Dates
Initial Date Seen [2006-08-10 21:04:00]
Last Date Updated [2011-03-07 21:40:20]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2006-4129 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2006-4129
Description
PHP remote file inclusion vulnerability in admin.webring.docs.php in the Webring Component (com_webring) 1.0 and earlier for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the component_dir parameter.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploits
Milw0rm 2177 (site down: refer to www.exploit-db.org 2177) - [Search]
References
BID 19492 - [Search]
BID 19511 - [Search]
SECUNIA 21495 - [Search]
VUPEN ADV-2006-3272 - [Search]
XFDB 28350 - [Search]

Dates
Initial Date Seen [2006-08-14 19:04:00]
Last Date Updated [2011-03-07 21:40:25]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2006-4130 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2006-4130
Description
PHP remote file inclusion vulnerability in admin.remository.php in the Remository Component (com_remository) 3.25 and earlier for Mambo and Joomla!, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.

CVSS
(5.1) AV:N/AC:H/Au:N/C:P/I:P/A:P
References
BID 19465 - [Search]
CWE CWE-94 - [Search]
SECUNIA 21477 - [Search]
VUPEN ADV-2006-3270 - [Search]
XFDB 28330 - [Search]

Dates
Initial Date Seen [2006-08-14 19:04:00]
Last Date Updated [2011-03-07 21:40:26]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2006-4229 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2006-4229
Description
PHP remote file inclusion vulnerability in archive.php in the mosListMessenger Component (com_lm) before 20060719 for Mambo and Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
References
SECUNIA 21531 - [Search]
VUPEN ADV-2006-3304 - [Search]
XFDB 28405 - [Search]

Dates
Initial Date Seen [2006-08-18 16:04:00]
Last Date Updated [2011-03-07 21:40:36]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2006-4242 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2006-4242
Description
PHP remote file inclusion vulnerability in install.jim.php in the JIM 1.0.1 component for Joomla or Mambo allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.

CVSS
(6.8) AV:N/AC:M/Au:N/C:P/I:P/A:P
Exploits
Milw0rm 2203 (site down: refer to www.exploit-db.org 2203) - [Search]
References
BID 19575 - [Search]
OSVDB 27990 - [Search]
SECUNIA 21545 - [Search]
VUPEN ADV-2006-3313 - [Search]
XFDB 28433 - [Search]

Dates
Initial Date Seen [2006-08-21 14:04:00]
Last Date Updated [2011-03-07 21:40:37]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2006-4263 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2006-4263
Description
Multiple PHP remote file inclusion vulnerabilities in the Product Scroller Module and other modules in mambo-phpshop (com_phpshop) for Mambo and Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter in (1) mod_phpshop.php, (2) mod_phpshop_allinone.php, (3) mod_phpshop_cart.php, (4) mod_phpshop_featureprod.php, (5) mod_phpshop_latestprod.php, (6) mod_product_categories.php, (7) mod_productscroller.php, and (8) mosproductsnap.php.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
References
BID 19591 - [Search]
OSVDB 28151 - [Search]
OSVDB 28152 - [Search]
OSVDB 28153 - [Search]
OSVDB 28154 - [Search]
OSVDB 28155 - [Search]
OSVDB 28156 - [Search]
OSVDB 28158 - [Search]
XFDB 28441 - [Search]

Dates
Initial Date Seen [2006-08-21 17:04:00]
Last Date Updated [2008-09-05 17:09:15]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2006-4269 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2006-4269
Description
** DISPUTED ** PHP remote file inclusion vulnerability in admin.x-shop.php in the x-shop component (com_x-shop) 1.7 and earlier for Mambo and Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter. NOTE: this issue has been disputed by third party researchers, stating that there is no mosConfig_absolute_path parameter and no admin.x-shop.php file in the reported package.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
References
BID 19588 - [Search]
OSVDB 28095 - [Search]
XFDB 28451 - [Search]

Dates
Initial Date Seen [2006-08-21 17:04:00]
Last Date Updated [2008-09-05 17:09:16]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2006-4282 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2006-4282
Description
PHP remote file inclusion vulnerability in MamboLogin.php in the MamboWiki component (com_mambowiki) 0.9.6 and earlier for Mambo and Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the IP parameter.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploits
Milw0rm 2213 (site down: refer to www.exploit-db.org 2213) - [Search]
References
BID 19594 - [Search]
XFDB 28463 - [Search]

Dates
Initial Date Seen [2006-08-22 13:04:00]
Last Date Updated [2011-03-07 21:40:40]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2006-4320 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2006-4320
Description
PHP remote file inclusion vulnerability in sef.php in the OpenSEF 2.0.0 component for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
References
BID 19600 - [Search]
XFDB 28479 - [Search]

Dates
Initial Date Seen [2006-08-23 21:04:00]
Last Date Updated [2008-09-05 17:09:24]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2006-4348 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2006-4348
Description
PHP remote file inclusion vulnerability in config.kochsuite.php in the Kochsuite (com_kochsuite) 0.9.4 component for Mambo and Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploits
Milw0rm 2215 (site down: refer to www.exploit-db.org 2215) - [Search]
References
BID 19590 - [Search]
OSVDB 28098 - [Search]
XFDB 28457 - [Search]

Dates
Initial Date Seen [2006-08-24 17:04:00]
Last Date Updated [2011-03-07 21:40:47]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2006-4378 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2006-4378
Description
** DISPUTED ** Multiple PHP remote file inclusion vulnerabilities in the Rssxt component for Joomla! (com_rssxt), possibly 2.0 Beta 1 or 1.0 and earlier, allow remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter in (1) pinger.php, (2) RPC.php, or (3) rssxt.php. NOTE: another researcher has disputed this issue, saying that the attacker can not control this parameter. In addition, as of 20060825, the original researcher has appeared to be unreliable with some other past reports. CVE has not performed any followup analysis with respect to this issue.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
References
BID 19593 - [Search]
OSVDB 28096 - [Search]

Dates
Initial Date Seen [2006-08-26 17:04:00]
Last Date Updated [2008-09-05 17:09:33]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2006-4468 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2006-4468
Description
Multiple unspecified vulnerabilities in Joomla! before 1.0.11, related to unvalidated input, allow attackers to have an unknown impact via unspecified vectors involving the (1) mosMail, (2) JosIsValidEmail, and (3) josSpoofValue functions; (4) the lack of inclusion of globals.php in administrator/index.php; (5) the Admin User Manager; and (6) the poll module.

CVSS
(5.1) AV:N/AC:H/Au:N/C:P/I:P/A:P
References
SECUNIA 21666 - [Search]
VUPEN ADV-2006-3408 - [Search]
XFDB 28628 - [Search]

Dates
Initial Date Seen [2006-08-31 16:04:00]
Last Date Updated [2011-03-07 21:40:59]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2006-4469 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2006-4469
Description
Unspecified vulnerability in PEAR.php in Joomla! before 1.0.11 allows remote attackers to perform "remote execution," related to "Injection Flaws."

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
References
SECUNIA 21666 - [Search]
VUPEN ADV-2006-3408 - [Search]
XFDB 28629 - [Search]

Dates
Initial Date Seen [2006-08-31 16:04:00]
Last Date Updated [2011-03-07 21:40:59]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2006-4470 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2006-4470
Description
Joomla! before 1.0.11 omits some checks for whether _VALID_MOS is defined, which allows attackers to have an unknown impact, possibly resulting in PHP remote file inclusion.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
References
SECUNIA 21666 - [Search]
VUPEN ADV-2006-3408 - [Search]
XFDB 28631 - [Search]

Dates
Initial Date Seen [2006-08-31 16:04:00]
Last Date Updated [2011-03-07 21:41:00]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2006-4471 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2006-4471
Description
The Admin Upload Image functionality in Joomla! before 1.0.11 allows remote authenticated users to upload files outside of the /images/stories/ directory via unspecified vectors.

CVSS
(6.5) AV:N/AC:L/Au:S/C:P/I:P/A:P
References
SECUNIA 21666 - [Search]
VUPEN ADV-2006-3408 - [Search]
XFDB 28630 - [Search]

Dates
Initial Date Seen [2006-08-31 16:04:00]
Last Date Updated [2011-03-07 21:41:00]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2006-4472 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2006-4472
Description
Multiple unspecified vulnerabilities in Joomla! before 1.0.11 allow attackers to bypass user authentication via unknown vectors involving the (1) do_pdf command and the (2) emailform com_content task.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
References
SECUNIA 21666 - [Search]
VUPEN ADV-2006-3408 - [Search]
XFDB 28632 - [Search]

Dates
Initial Date Seen [2006-08-31 16:04:00]
Last Date Updated [2011-03-07 21:41:00]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2006-4473 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2006-4473
Description
Unspecified vulnerability in com_content in Joomla! before 1.0.11, when $mosConfig_hideEmail is set, allows attackers to perform the emailform and emailsend tasks.

CVSS
(6.8) AV:N/AC:M/Au:N/C:P/I:P/A:P
References
SECUNIA 21666 - [Search]
VUPEN ADV-2006-3408 - [Search]

Dates
Initial Date Seen [2006-08-31 16:04:00]
Last Date Updated [2011-03-07 21:41:00]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2006-4474 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2006-4474
Description
Multiple cross-site scripting (XSS) vulnerabilities in Joomla! before 1.0.11 allow remote attackers to inject arbitrary web script or HTML via unspecified parameters in (1) Admin Module Manager, (2) Admin Help, and (3) Search.

CVSS
(5.1) AV:N/AC:H/Au:N/C:P/I:P/A:P
References
SECUNIA 21666 - [Search]
VUPEN ADV-2006-3408 - [Search]
XFDB 28633 - [Search]

Dates
Initial Date Seen [2006-08-31 16:04:00]
Last Date Updated [2011-03-07 21:41:00]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2006-4475 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2006-4475
Description
Joomla! before 1.0.11 does not limit access to the Admin Popups functionality, which has unknown impact and attack vectors.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
References
CWE CWE-264 - [Search]
SECUNIA 21666 - [Search]
VUPEN ADV-2006-3408 - [Search]

Dates
Initial Date Seen [2006-08-31 16:04:00]
Last Date Updated [2011-03-07 21:41:00]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2006-4476 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2006-4476
Description
Multiple unspecified vulnerabilities in Joomla! before 1.0.11, related to "Injection Flaws," allow attackers to have an unknown impact via (1) globals.php, which uses include_once() instead of require(); (2) the $options variable; (3) Admin Upload Image; (4) ->load(); (5) content submissions when frontpage is selected; (6) the mosPageNav constructor; (7) saveOrder functions; (8) the absence of "exploit blocking rules" in htaccess; and (9) the ACL.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
References
CWE CWE-264 - [Search]
CWE CWE-94 - [Search]
SECUNIA 21666 - [Search]
VUPEN ADV-2006-3408 - [Search]

Dates
Initial Date Seen [2006-08-31 16:04:00]
Last Date Updated [2011-03-07 21:41:00]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2006-4553 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2006-4553
Description
PHP remote file inclusion vulnerability in plugin.class.php in the com_comprofiler Components 1.0 RC2 for Mambo and Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.

CVSS
(5.1) AV:N/AC:H/Au:N/C:P/I:P/A:P
References
BID 19725 - [Search]
CWE CWE-94 - [Search]
SECUNIA 21636 - [Search]
XFDB 28596 - [Search]

Dates
Initial Date Seen [2006-09-05 20:04:00]
Last Date Updated [2008-09-05 17:10:00]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2006-4556 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2006-4556
Description
** DISPUTED ** PHP remote file inclusion vulnerability in index.php in the JIM component for Mambo and Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter. NOTE: another researcher has stated that the product distribution does not include an index.php file. Also, this might be related to CVE-2006-4242.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
References
OSVDB 28097 - [Search]

Dates
Initial Date Seen [2006-09-05 20:04:00]
Last Date Updated [2008-09-05 17:10:00]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2006-4992 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2006-4992
Description
Multiple PHP remote file inclusion vulnerabilities in JD-WordPress for Joomla! (com_jd-wp) 2.0-1.0 RC2 allow remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter in (1) wp-comments-post.php, (2) wp-feed.php, or (3) wp-trackback.php.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
References
BID 19209 - [Search]
OSVDB 28997 - [Search]
OSVDB 28998 - [Search]
OSVDB 28999 - [Search]

Dates
Initial Date Seen [2006-09-25 22:07:00]
Last Date Updated [2008-09-05 17:11:05]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2006-4995 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2006-4995
Description
PHP remote file inclusion vulnerability in BSQ Sitestats (bsq_sitestats) before 2.1.1 for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P

Dates
Initial Date Seen [2006-09-25 22:07:00]
Last Date Updated [2008-09-05 17:11:06]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2006-5039 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2006-5039
Description
Unspecified vulnerability in Events 1.3 beta module (com_events) for Joomla! has unspecified impact and attack vectors.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P

Dates
Initial Date Seen [2006-09-27 19:07:00]
Last Date Updated [2008-09-05 17:11:13]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2006-5040 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2006-5040
Description
Unspecified vulnerability in SEF404x (com_sef) for Joomla! has unspecified impact and attack vectors.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P

Dates
Initial Date Seen [2006-09-27 19:07:00]
Last Date Updated [2008-09-05 17:11:13]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2006-5041 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2006-5041
Description
Unspecified vulnerability in Hot Properties (possibly com_hotproperties) 0.97 and earlier for Joomla! has unspecified impact and attack vectors.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P

Dates
Initial Date Seen [2006-09-27 19:07:00]
Last Date Updated [2008-09-05 17:11:13]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2006-5042 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2006-5042
Description
Unspecified vulnerability in mosMedia (com_mosmedia) 1.0.8 and earlier for Joomla! has unspecified impact and attack vectors.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P

Dates
Initial Date Seen [2006-09-27 19:07:00]
Last Date Updated [2008-09-05 17:11:13]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2006-5043 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2006-5043
Description
Multiple PHP remote file inclusion vulnerabilities in the Joomlaboard Forum Component (com_joomlaboard) before 1.1.2 for Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the sbp parameter to (1) file_upload.php or (2) image_upload.php, a variant of CVE-2006-3528.

CVSS
(5.1) AV:N/AC:H/Au:N/C:P/I:P/A:P
Exploits
Milw0rm 3560 (site down: refer to www.exploit-db.org 3560) - [Search]
References
BID 23129 - [Search]
CWE CWE-94 - [Search]
SECUNIA 21059 - [Search]
VUPEN ADV-2006-2804 - [Search]
XFDB 33199 - [Search]

Dates
Initial Date Seen [2006-09-27 19:07:00]
Last Date Updated [2011-05-06 00:00:00]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2006-5044 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2006-5044
Description
Unspecified vulnerability in Prince Clan (Princeclan) Chess component (com_pcchess) 0.8 and earlier for Mambo and Joomla! has unspecified impact and attack vectors.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P

Dates
Initial Date Seen [2006-09-27 19:07:00]
Last Date Updated [2008-09-05 17:11:13]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2006-5045 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2006-5045
Description
Unspecified vulnerability in PollXT component (com_pollxt) 1.22.07 and earlier for Joomla! has unspecified impact and attack vectors, probably related to PHP remote file inclusion in the mosConfig_absolute_path to conf.pollxt.php.

CVSS
(5.1) AV:N/AC:H/Au:N/C:P/I:P/A:P
References
BID 19037 - [Search]
CWE CWE-94 - [Search]
SECUNIA 21068 - [Search]
VUPEN ADV-2006-2843 - [Search]
XFDB 27779 - [Search]

Dates
Initial Date Seen [2006-09-27 19:07:00]
Last Date Updated [2011-04-08 00:00:00]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2006-5046 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2006-5046
Description
Unspecified vulnerability in RS Gallery2 (com_rsgallery2) 1.11.3 and earlier for Joomla! has unspecified impact and attack vectors, related to lack of "hardened language files."

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P

Dates
Initial Date Seen [2006-09-27 19:07:00]
Last Date Updated [2008-09-05 17:11:14]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2006-5047 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2006-5047
Description
Unspecified vulnerability in rsgallery2.html.php in RS Gallery2 component (com_rsgallery2) before 1.11.3 for Joomla! allows attackers to execute arbitrary code.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P

Dates
Initial Date Seen [2006-09-27 19:07:00]
Last Date Updated [2008-09-05 17:11:14]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2006-5048 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2006-5048
Description
Multiple PHP remote file inclusion vulnerabilities in Security Images (com_securityimages) component 3.0.5 and earlier for Joomla! allow remote attackers to execute arbitrary code via a URL in the mosConfig_absolute_path parameter in (1) configinsert.php, (2) lang.php, (3) client.php, and (4) server.php.

CVSS
(5.1) AV:N/AC:H/Au:N/C:P/I:P/A:P
Exploits
Milw0rm 2083 (site down: refer to www.exploit-db.org 2083) - [Search]
References
BID 19217 - [Search]
CWE CWE-94 - [Search]
OSVDB 27655 - [Search]
OSVDB 27656 - [Search]
OSVDB 27657 - [Search]
OSVDB 27658 - [Search]
SECUNIA 21260 - [Search]
VUPEN ADV-2006-3062 - [Search]
XFDB 28078 - [Search]

Dates
Initial Date Seen [2006-09-27 19:07:00]
Last Date Updated [2011-04-07 00:00:00]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2006-5049 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2006-5049
Description
Unspecified vulnerability in Classifieds (com_classifieds) component 1.3 and earlier for Joomla! has unspecified impact and attack vectors.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P

Dates
Initial Date Seen [2006-09-27 19:07:00]
Last Date Updated [2008-09-05 17:11:14]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2006-5096 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2006-5096
Description
Multiple cross-site scripting (XSS) vulnerabilities in index.php in VirtueMart (formerly known as mambo-phpShop) Joomla! eCommerce Edition CMS 1.0.11, and possibly earlier, allow remote attackers to inject arbitrary web script or HTML via the Itemid parameter in a (1) com_contact or (2) subscribe action.

CVSS
(5.1) AV:N/AC:H/Au:N/C:P/I:P/A:P
References
BID 20236 - [Search]
SECUNIA 22162 - [Search]
VUPEN ADV-2006-3848 - [Search]
XFDB 29207 - [Search]

Dates
Initial Date Seen [2006-09-29 17:07:00]
Last Date Updated [2011-03-07 21:42:33]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2006-5106 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2006-5106
Description
Cross-site scripting (XSS) vulnerability in FacileForms before 1.4.7 for Mambo and Joomla!, when either register_globals or RG_EMULATION is enabled, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS
(6.8) AV:N/AC:M/Au:N/C:P/I:P/A:P
References
BID 20254 - [Search]
OSVDB 29237 - [Search]
SECUNIA 22125 - [Search]
VUPEN ADV-2006-3817 - [Search]

Dates
Initial Date Seen [2006-10-03 00:03:00]
Last Date Updated [2011-03-07 21:42:34]

Copyright
© 2012 The MITRE Corporation

NESSUS 21788 match rank: 100%

Source
http://www.nessus.org/plugins/index.php?view=single&id=21788
Title
FreeBSD : Joomla -- multiple vulnerabilities (1f935f61-075d-11db-822b-728b50d539a3)
Description
The remote FreeBSD host is missing a security-related update.

References
CPE cpe:/o:freebsd:freebsd - [Search]
SECUNIA 20746 - [Search]
Tools
NESSUS 21788 - [Search]

Dates
Initial Date Seen [2006-07-03 00:00:00]
Last Date Updated [2011-11-18 00:00:00]

Copyright
© 2012 Tenable Network Security@

NVD CVE-2006-6051 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2006-6051
Description
PHP remote file inclusion vulnerability in reporter.logic.php in the MosReporter (com_reporter) component for Mambo and Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploits
Milw0rm 2807 (site down: refer to www.exploit-db.org 2807) - [Search]
References
BID 21160 - [Search]
XFDB 30410 - [Search]

Dates
Initial Date Seen [2006-11-21 19:07:00]
Last Date Updated [2011-03-07 21:44:50]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2006-6832 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2006-6832
Description
Cross-site scripting (XSS) vulnerability in Joomla! before 1.0.12 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, possibly related to poll.php or the module title.

CVSS
(2.6) AV:N/AC:H/Au:N/C:N/I:P/A:N
References
BID 21810 - [Search]
CWE CWE-79 - [Search]
SECUNIA 23563 - [Search]
VUPEN ADV-2006-5202 - [Search]

Dates
Initial Date Seen [2006-12-31 00:00:00]
Last Date Updated [2011-03-07 21:47:08]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2006-6833 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2006-6833
Description
com_categories in Joomla! before 1.0.12 does not validate input, which has unknown impact and remote attack vectors.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
References
BID 21810 - [Search]
SECUNIA 23563 - [Search]
VUPEN ADV-2006-5202 - [Search]

Dates
Initial Date Seen [2006-12-31 00:00:00]
Last Date Updated [2011-03-07 21:47:08]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2006-6834 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2006-6834
Description
Multiple unspecified vulnerabilities in Joomla! before 1.0.12 have unknown impact and attack vectors related to (1) "unneeded legacy functions" and (2) "Several low level security fixes."

CVSS
(5.1) AV:N/AC:H/Au:N/C:P/I:P/A:P
References
BID 21810 - [Search]
SECUNIA 23563 - [Search]
VUPEN ADV-2006-5202 - [Search]

Dates
Initial Date Seen [2006-12-31 00:00:00]
Last Date Updated [2011-03-07 21:47:08]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2006-6843 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2006-6843
Description
PHP remote file inclusion vulnerability in the BE IT EasyPartner 0.0.9 beta component for Joomla! allows remote attackers to execute arbitrary PHP code via unspecified vectors. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
References
BID 21776 - [Search]

Dates
Initial Date Seen [2006-12-31 00:00:00]
Last Date Updated [2008-09-05 17:15:46]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2006-6962 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2006-6962
Description
PHP remote file inclusion vulnerability in rsgallery2.html.php in the RS Gallery2 component (com_rsgallery2) 1.11.2 for Joomla! allows attackers to execute arbitrary PHP code via the mosConfig_absolute_path parameter. NOTE: this issue may overlap CVE-2006-5047.

CVSS
(5.1) AV:N/AC:H/Au:N/C:P/I:P/A:P
Exploits
Milw0rm 1959 (site down: refer to www.exploit-db.org 1959) - [Search]
References
BID 18705 - [Search]
CWE CWE-94 - [Search]
VUPEN ADV-2006-2581 - [Search]
XFDB 27418 - [Search]

Dates
Initial Date Seen [2007-01-29 11:28:00]
Last Date Updated [2011-03-07 21:47:36]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2006-7008 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2006-7008
Description
Unspecified vulnerability in Joomla! before 1.0.10 has unknown impact and attack vectors, related to "securing mosmsg from misuse." NOTE: it is possible that this issue overlaps CVE-2006-1029.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
References
OSVDB 26915 - [Search]
SECUNIA 20874 - [Search]

Dates
Initial Date Seen [2007-02-12 18:28:00]
Last Date Updated [2008-09-05 17:16:11]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2006-7009 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2006-7009
Description
Joomla! before 1.0.10 allows remote attackers to spoof the frontend submission forms, which has unknown impact and attack vectors.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
References
SECUNIA 20874 - [Search]

Dates
Initial Date Seen [2007-02-12 18:28:00]
Last Date Updated [2008-09-05 17:16:11]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2006-7010 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2006-7010
Description
The mosgetparam implementation in Joomla! before 1.0.10, does not set a variable's data type to integer when the variable's default value is numeric, which has unspecified impact and attack vectors, which may permit SQL injection attacks.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
References
OSVDB 26916 - [Search]
SECUNIA 20874 - [Search]

Dates
Initial Date Seen [2007-02-12 18:28:00]
Last Date Updated [2008-09-05 17:16:11]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2006-7122 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2006-7122
Description
Cross-site scripting (XSS) vulnerability in the IP Address Lookup functionality in BSQ Sitestats (component for Joomla) 1.8.0, and possibly other versions before 2.2.1, allows remote attackers to inject arbitrary web script and HTML via the ip parameter.

CVSS
(5.1) AV:N/AC:H/Au:N/C:P/I:P/A:P
References
BID 20267 - [Search]
XFDB 29266 - [Search]

Dates
Initial Date Seen [2007-03-05 20:19:00]
Last Date Updated [2008-09-05 17:16:28]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2006-7123 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2006-7123
Description
Multiple SQL injection vulnerabilities in BSQ Sitestats (component for Joomla) 1.8.0, and possibly other versions before 2.2.1, allow remote attackers to execute arbitrary SQL commands via (1) unspecified parameters when importing the (a) ip-to-country.csv file; and the (2) HTTP Referer, (3) HTTP User Agent, and (4) HTTP Accept Language headers to (b) bsqtemplateinc.php.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
References
BID 20267 - [Search]
XFDB 29268 - [Search]

Dates
Initial Date Seen [2007-03-05 20:19:00]
Last Date Updated [2008-09-05 17:16:28]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2006-7124 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2006-7124
Description
PHP remote file inclusion vulnerability in external/rssfeeds.php in BSQ Sitestats (component for Joomla) 1.8.0, and possibly other versions before 2.2.1, allows remote attackers to execute arbitrary PHP code via the baseDir parameter.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
References
BID 20267 - [Search]
OSVDB 29287 - [Search]
XFDB 29269 - [Search]

Dates
Initial Date Seen [2007-03-05 20:19:00]
Last Date Updated [2008-09-05 17:16:29]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2006-7125 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2006-7125
Description
Cross-site scripting (XSS) vulnerability in Joomla BSQ Sitestats 1.8.0 and 2.2.1 allows remote attackers to inject arbitrary web script or HTML via the HTTP Referer header, which is not properly handled when the administrator views site statistics.

CVSS
(5.1) AV:N/AC:H/Au:N/C:P/I:P/A:P
References
BID 20614 - [Search]
VUPEN ADV-2006-4090 - [Search]
XFDB 29661 - [Search]

Dates
Initial Date Seen [2007-03-05 20:19:00]
Last Date Updated [2011-03-07 21:47:54]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2006-7126 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2006-7126
Description
SQL injection vulnerability in Joomla BSQ Sitestats 1.8.0 and 2.2.1 allows remote attackers to execute arbitrary SQL commands via the query string, possibly PHP_SELF.

CVSS
(5.1) AV:N/AC:H/Au:N/C:P/I:P/A:P
References
BID 20614 - [Search]
VUPEN ADV-2006-4090 - [Search]
XFDB 29662 - [Search]

Dates
Initial Date Seen [2007-03-05 20:19:00]
Last Date Updated [2011-03-07 21:47:54]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2006-7247 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2006-7247
Description
SQL injection vulnerability in the Weblinks (com_weblinks) component for Joomla! and Mambo 1.0.9 and earlier allows remote attackers to execute arbitrary SQL commands via the title parameter.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploits
www.exploit-db.org 1922 - [Search]
References
CWE CWE-89 - [Search]
OSVDB 26626 - [Search]
SECUNIA 20746 - [Search]

Dates
Initial Date Seen [2012-09-06 15:55:00]
Last Date Updated [2012-09-13 00:00:00]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2007-0373 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2007-0373
Description
Multiple SQL injection vulnerabilities in Joomla! 1.5.0 Beta allow remote attackers to execute arbitrary SQL commands via (1) the searchword parameter in certain files; the where parameter in (2) plugins/search/content.php or (3) plugins/search/weblinks.php; the text parameter in (4) plugins/search/contacts.php, (5) plugins/search/categories.php, or (6) plugins/search/sections.php; or (7) the email parameter in database/table/user.php, which is not properly handled by the check function.

CVSS
(5.1) AV:N/AC:H/Au:N/C:P/I:P/A:P
References
BID 22122 - [Search]
OSVDB 32527 - [Search]
OSVDB 32528 - [Search]
OSVDB 32529 - [Search]
OSVDB 32530 - [Search]
OSVDB 32531 - [Search]
OSVDB 32532 - [Search]
OSVDB 32533 - [Search]

Dates
Initial Date Seen [2007-01-19 18:28:00]
Last Date Updated [2008-11-15 01:40:10]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2007-0374 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2007-0374
Description
SQL injection vulnerability in (1) Joomla! 1.0.11 and 1.5 Beta, and (2) Mambo 4.6.1, allows remote attackers to execute arbitrary SQL commands via the id parameter when cancelling content editing.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
References
BID 19734 - [Search]
OSVDB 32520 - [Search]

Dates
Initial Date Seen [2007-01-19 18:28:00]
Last Date Updated [2008-11-15 01:40:10]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2007-0375 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2007-0375
Description
Joomla! 1.5.0 Beta allows remote attackers to obtain sensitive information via a direct request for (1) plugins/user/example.php; (2) gmail.php, (3) example.php, or (4) ldap.php in plugins/authentication/; (5) modules/mod_mainmenu/menu.php; or other unspecified PHP scripts, which reveals the path in various error messages, related to a jimport function call at the beginning of each script.

CVSS
(5) AV:N/AC:L/Au:N/C:P/I:N/A:N
References
OSVDB 32522 - [Search]
OSVDB 32523 - [Search]
OSVDB 32524 - [Search]
OSVDB 32525 - [Search]
OSVDB 32526 - [Search]

Dates
Initial Date Seen [2007-01-19 18:28:00]
Last Date Updated [2008-11-15 01:40:10]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2007-0382 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2007-0382
Description
Multiple SQL injection vulnerabilities in letterman.class.php in the Letterman 1.2.3 (com_letterman) component for Joomla! before 1.0.12 allow remote attackers to execute arbitrary SQL commands via the id parameter, related to the (1) lm_sendMail, (2) saveNewsletter, and (3) cancelNewsletter functions.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
References
BID 22117 - [Search]
OSVDB 33688 - [Search]

Dates
Initial Date Seen [2007-01-19 18:28:00]
Last Date Updated [2008-11-13 01:31:44]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2007-0387 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2007-0387
Description
SQL injection vulnerability in models/category.php in the Weblinks component for Joomla! SVN 20070118 (com_weblinks) allows remote attackers to execute arbitrary SQL commands via the catid parameter.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
References
OSVDB 34792 - [Search]

Dates
Initial Date Seen [2007-01-19 18:28:00]
Last Date Updated [2008-11-13 01:31:45]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2007-1596 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2007-1596
Description
Multiple PHP remote file inclusion vulnerabilities in the NFN Address Book (com_nfn_addressbook) 0.4 component for Mambo and Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter to (1) components/com_nfn_addressbook/nfnaddressbook.php or (2) administrator/components/com_nfn_addressbook/nfnaddressbook.php.

CVSS
(7.6) AV:N/AC:H/Au:N/C:C/I:C/A:C
Exploits
Milw0rm 3539 (site down: refer to www.exploit-db.org 3539) - [Search]
References
BID 23092 - [Search]
OSVDB 43553 - [Search]
OSVDB 43554 - [Search]
VUPEN ADV-2007-1073 - [Search]
XFDB 33133 - [Search]

Dates
Initial Date Seen [2007-03-22 19:19:00]
Last Date Updated [2011-03-07 21:52:26]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2007-1699 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2007-1699
Description
Multiple PHP remote file inclusion vulnerabilities in the SWmenu (com_swmenupro and com_swmenufree) 4.0 component for Mambo and Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter to ImageManager/Classes/ImageManager.php under the (1) components/ or (2) administrator/components/ directory trees.

CVSS
(10) AV:N/AC:L/Au:N/C:C/I:C/A:C
Exploits
Milw0rm 3557 (site down: refer to www.exploit-db.org 3557) - [Search]
References
BID 23116 - [Search]
OSVDB 38790 - [Search]
OSVDB 38791 - [Search]
VUPEN ADV-2007-1100 - [Search]
XFDB 33204 - [Search]

Dates
Initial Date Seen [2007-03-26 21:19:00]
Last Date Updated [2011-03-07 21:52:41]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2007-1703 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2007-1703
Description
SQL injection vulnerability in index.php in the RWCards (com_rwcards) 2.4.3 and earlier component for Joomla! allows remote attackers to execute arbitrary SQL commands via the category_id parameter.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploits
Milw0rm 3565 (site down: refer to www.exploit-db.org 3565) - [Search]
References
BID 23126 - [Search]
OSVDB 37213 - [Search]
VUPEN ADV-2007-1105 - [Search]
XFDB 33194 - [Search]

Dates
Initial Date Seen [2007-03-26 21:19:00]
Last Date Updated [2011-03-07 21:52:42]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2007-1704 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2007-1704
Description
SQL injection vulnerability in index.php in the Car Manager (com_resman) 1.1 and earlier component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploits
Milw0rm 3564 (site down: refer to www.exploit-db.org 3564) - [Search]
References
BID 23131 - [Search]
OSVDB 37199 - [Search]
VUPEN ADV-2007-1104 - [Search]
XFDB 33193 - [Search]

Dates
Initial Date Seen [2007-03-26 21:19:00]
Last Date Updated [2011-03-07 21:52:42]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2007-1776 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2007-1776
Description
SQL injection vulnerability in index.php in the DesignForJoomla.com D4J eZine (com_ezine) 2.8 and earlier component for Joomla! allows remote attackers to execute arbitrary SQL commands via the article parameter in a read action.

CVSS
(5.1) AV:N/AC:H/Au:N/C:P/I:P/A:P
Exploits
Milw0rm 3590 (site down: refer to www.exploit-db.org 3590) - [Search]
References
BID 23165 - [Search]
CWE CWE-89 - [Search]
OSVDB 34511 - [Search]
SECUNIA 24675 - [Search]
VUPEN ADV-2007-1135 - [Search]
XFDB 33249 - [Search]

Dates
Initial Date Seen [2007-03-29 21:19:00]
Last Date Updated [2011-08-05 00:00:00]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2007-2005 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2007-2005
Description
Multiple PHP remote file inclusion vulnerabilities in the Taskhopper 1.1 component for Mambo and Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter to (1) contact_type.php, (2) itemstatus_type.php, (3) projectstatus_type.php, (4) request_type.php, (5) responses_type.php, (6) timelog_type.php, or (7) urgency_type.php in inc/.

CVSS
(5.1) AV:N/AC:H/Au:N/C:P/I:P/A:P
Exploits
Milw0rm 3703 (site down: refer to www.exploit-db.org 3703) - [Search]
References
BID 23408 - [Search]
CWE CWE-94 - [Search]
OSVDB 34795 - [Search]
OSVDB 34796 - [Search]
OSVDB 34797 - [Search]
OSVDB 34798 - [Search]
OSVDB 34799 - [Search]
OSVDB 34800 - [Search]
OSVDB 34801 - [Search]
VUPEN ADV-2007-1346 - [Search]
XFDB 33552 - [Search]

Dates
Initial Date Seen [2007-04-12 15:19:00]
Last Date Updated [2011-03-07 21:53:21]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2007-2043 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2007-2043
Description
Multiple PHP remote file inclusion vulnerabilities in the Avant-Garde Solutions MOSMedia (com_mosmedia) 1.08 and earlier module for Mambo and Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter to (1) media.tab.php or (2) media.divs.php.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploits
Milw0rm 3714 (site down: refer to www.exploit-db.org 3714) - [Search]
References
BID 23432 - [Search]
OSVDB 37433 - [Search]
OSVDB 37434 - [Search]
VUPEN ADV-2007-1357 - [Search]

Dates
Initial Date Seen [2007-04-16 18:19:00]
Last Date Updated [2011-03-07 21:53:25]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2007-2044 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2007-2044
Description
PHP remote file inclusion vulnerability in mod_weather.php in the Antonis Ventouris Weather module for Mambo and Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the absolute_path parameter.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploits
Milw0rm 3712 (site down: refer to www.exploit-db.org 3712) - [Search]
References
OSVDB 37435 - [Search]
VUPEN ADV-2007-1356 - [Search]

Dates
Initial Date Seen [2007-04-16 18:19:00]
Last Date Updated [2011-03-07 21:53:25]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2007-2089 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2007-2089
Description
Multiple PHP remote file inclusion vulnerabilities in the Jx Development Article 1.1 and earlier component for Mambo and Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the absolute_path parameter to com_articles.php in (1) components/ or (2) classes/html/.

CVSS
(5.1) AV:N/AC:H/Au:N/C:P/I:P/A:P
Exploits
Milw0rm 3736 (site down: refer to www.exploit-db.org 3736) - [Search]
References
BID 23513 - [Search]
VUPEN ADV-2007-1394 - [Search]
XFDB 33663 - [Search]

Dates
Initial Date Seen [2007-04-18 06:19:00]
Last Date Updated [2011-03-07 21:53:29]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2007-2143 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2007-2143
Description
PHP remote file inclusion vulnerability in index.php in the Be2004-2 template for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploits
Milw0rm 3759 (site down: refer to www.exploit-db.org 3759) - [Search]
References
BID 23549 - [Search]
OSVDB 37572 - [Search]
XFDB 33728 - [Search]

Dates
Initial Date Seen [2007-04-19 06:19:00]
Last Date Updated [2008-11-13 01:37:53]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2007-2144 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2007-2144
Description
PHP remote file inclusion vulnerability in includes/CAltInstaller.php in the JoomlaPack (com_jpack) 1.0.4a2 RE component for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.

CVSS
(5.1) AV:N/AC:H/Au:N/C:P/I:P/A:P
Exploits
Milw0rm 3753 (site down: refer to www.exploit-db.org 3753) - [Search]
References
BID 23529 - [Search]
CWE CWE-94 - [Search]
OSVDB 37573 - [Search]
VUPEN ADV-2007-1429 - [Search]
XFDB 33702 - [Search]

Dates
Initial Date Seen [2007-04-19 06:19:00]
Last Date Updated [2011-03-07 21:53:35]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2007-2196 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2007-2196
Description
** DISPUTED ** PHP remote file inclusion vulnerability in jambook.php in the Jambook (com_Jambook) 1.0 beta7 module for Mambo and Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter. NOTE: this issue has been disputed by a reliable third party because the jambook.php protects against direct request.

CVSS
(5.1) AV:N/AC:H/Au:N/C:P/I:P/A:P
References
BID 23509 - [Search]
OSVDB 34151 - [Search]

Dates
Initial Date Seen [2007-04-24 13:19:00]
Last Date Updated [2008-09-05 17:22:27]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2007-2199 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2007-2199
Description
PHP remote file inclusion vulnerability in lib/pcltar.lib.php (aka pcltar.php) in the PclTar module 1.3 and 1.3.1 for Vincent Blavet PhpConcept Library, as used in multiple products including (1) Joomla! 1.5.0 Beta, (2) N/X Web Content Management System (WCMS) 4.5, (3) CJG EXPLORER PRO 3.3, and (4) phpSiteBackup 0.1, allows remote attackers to execute arbitrary PHP code via a URL in the g_pcltar_lib_dir parameter.

CVSS
(5.1) AV:N/AC:H/Au:N/C:P/I:P/A:P
Exploits
Milw0rm 4111 (site down: refer to www.exploit-db.org 4111) - [Search]
Milw0rm 3915 (site down: refer to www.exploit-db.org 3915) - [Search]
Milw0rm 3781 (site down: refer to www.exploit-db.org 3781) - [Search]
References
BID 23613 - [Search]
BID 23708 - [Search]
BID 24660 - [Search]
BID 25528 - [Search]
CWE CWE-94 - [Search]
OSVDB 34803 - [Search]
OSVDB 36009 - [Search]
SECUNIA 25230 - [Search]
VUPEN ADV-2007-1511 - [Search]
XFDB 33837 - [Search]
XFDB 34273 - [Search]
XFDB 35092 - [Search]

Dates
Initial Date Seen [2007-04-24 16:19:00]
Last Date Updated [2011-08-22 00:00:00]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2007-2319 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2007-2319
Description
PHP remote file inclusion vulnerability in the AutoStand 1.1 and earlier module for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter to mod_as_category.php in (1) modules/mod_as_category/ or (2) modules/.

CVSS
(5.1) AV:N/AC:H/Au:N/C:P/I:P/A:P
Exploits
Milw0rm 3734 (site down: refer to www.exploit-db.org 3734) - [Search]
References
BID 23490 - [Search]
CWE CWE-94 - [Search]
OSVDB 35753 - [Search]
VUPEN ADV-2007-1392 - [Search]
XFDB 33660 - [Search]

Dates
Initial Date Seen [2007-04-26 17:19:00]
Last Date Updated [2011-03-07 21:53:59]

Copyright
© 2012 The MITRE Corporation

NESSUS 22294 match rank: 100%

Source
http://www.nessus.org/plugins/index.php?view=single&id=22294
Title
FreeBSD : joomla -- multiple vulnerabilities (0ab423e7-3822-11db-81e1-000e0c2e438a)
Description
The remote FreeBSD host is missing a security-related update.

References
CPE cpe:/o:freebsd:freebsd - [Search]
Tools
NESSUS 22294 - [Search]

Dates
Initial Date Seen [2006-08-31 00:00:00]
Last Date Updated [2011-11-18 00:00:00]

Copyright
© 2012 Tenable Network Security@

NVD CVE-2007-2792 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2007-2792
Description
SQL injection vulnerability in the Yet another Newsletter Component (aka YaNC or com_yanc) component before 1.5 beta 3 for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the listid parameter to index.php. NOTE: some of these details are obtained from third party information.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploits
Milw0rm 3944 (site down: refer to www.exploit-db.org 3944) - [Search]
www.exploit-db.org 11603 - [Search]
References
BID 24030 - [Search]
BID 38454 - [Search]
OSVDB 37948 - [Search]
OSVDB 62620 - [Search]
SECUNIA 38780 - [Search]
XFDB 56585 - [Search]

Dates
Initial Date Seen [2007-05-21 20:30:00]
Last Date Updated [2010-04-08 01:09:57]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2007-2933 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2007-2933
Description
SQL injection vulnerability in index.php in the Phil-a-Form (com_philaform) 1.2.0.0 and earlier component for Joomla! allows remote attackers to execute arbitrary SQL commands via the form_id parameter.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploits
Milw0rm 4003 (site down: refer to www.exploit-db.org 4003) - [Search]
References
OSVDB 38150 - [Search]
XFDB 34562 - [Search]

Dates
Initial Date Seen [2007-05-30 20:30:00]
Last Date Updated [2008-11-15 01:50:45]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2007-3130 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2007-3130
Description
Multiple PHP remote file inclusion vulnerabilities in the OpenWiki (formerly JD-Wiki) component (com_jd-wiki) 1.0.2, and possibly earlier, for Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter to (1) dwpage.php or (2) wantedpages.php, different vectors than CVE-2006-4074. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

CVSS
(5.1) AV:N/AC:H/Au:N/C:P/I:P/A:P
References
BID 24342 - [Search]
CWE CWE-94 - [Search]
OSVDB 37472 - [Search]
OSVDB 37473 - [Search]

Dates
Initial Date Seen [2007-06-08 12:30:00]
Last Date Updated [2008-11-15 01:51:29]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2007-3249 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2007-3249
Description
Cross-site scripting (XSS) vulnerability in mod_lettermansubscribe.php in the Letterman Subscriber (mod_letterman) before 1.2.5 module for Joomla! allows remote attackers to inject arbitrary web script or HTML via the Itemid parameter.

CVSS
(2.6) AV:N/AC:H/Au:N/C:N/I:P/A:N
References
BID 24479 - [Search]
OSVDB 36376 - [Search]
SECUNIA 25670 - [Search]
VUPEN ADV-2007-2215 - [Search]
XFDB 34870 - [Search]

Dates
Initial Date Seen [2007-06-18 06:30:00]
Last Date Updated [2011-03-07 21:55:55]

Copyright
© 2012 The MITRE Corporation

NESSUS 24227 match rank: 100%

Source
http://www.nessus.org/plugins/index.php?view=single&id=24227
Title
FreeBSD : joomla -- multiple remote vulnerabilities (7bb127c1-a5aa-11db-9ddc-0011098b2f36)
Description
The remote FreeBSD host is missing a security-related update.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
References
BID 21810 - [Search]
CPE cpe:/o:freebsd:freebsd - [Search]
CVE-2006-6832 - [Search]
CVE-2006-6833 - [Search]
CVE-2006-6834 - [Search]
CWE 79 - [Search]
SECUNIA 23563 - [Search]
Tools
NESSUS 24227 - [Search]

Dates
Initial Date Seen [2007-01-18 00:00:00]
Last Date Updated [2011-11-18 00:00:00]

Copyright
© 2012 Tenable Network Security@

NVD CVE-2007-3932 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2007-3932
Description
uploadimg.php in the Expose RC35 and earlier (com_expose) component for Joomla! sends an error message but does not exit when it detects an attempt to upload a non-JPEG file, which allows remote attackers to upload and execute arbitrary PHP code in the img/ folder.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploits
Milw0rm 4194 (site down: refer to www.exploit-db.org 4194) - [Search]
References
BID 24958 - [Search]
OSVDB 41262 - [Search]
XFDB 35488 - [Search]

Dates
Initial Date Seen [2007-07-20 20:30:00]
Last Date Updated [2008-11-15 01:54:38]

Copyright
© 2012 The MITRE Corporation

NESSUS 39427 match rank: 100%

Source
http://www.nessus.org/plugins/index.php?view=single&id=39427
Title
FreeBSD : joomla -- multiple vulnerabilities (bdccd14b-5aac-11de-a438-003048590f9e)
Description
The remote FreeBSD host is missing a security-related update.

CVSS
(4.3) AV:N/AC:M/Au:N/C:N/I:P/A:N
References
CPE cpe:/o:freebsd:freebsd - [Search]
CVE-2009-1938 - [Search]
CVE-2009-1939 - [Search]
CVE-2009-1940 - [Search]
CWE 79 - [Search]
SECUNIA 35278 - [Search]
Tools
NESSUS 39427 - [Search]

Dates
Initial Date Seen [2009-06-17 00:00:00]
Last Date Updated [2011-11-18 00:00:00]

Copyright
© 2012 Tenable Network Security@

NVD CVE-2007-4046 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2007-4046
Description
SQL injection vulnerability in index.php in the Pony Gallery (com_ponygallery) 1.5 and earlier component for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploits
Milw0rm 4201 (site down: refer to www.exploit-db.org 4201) - [Search]
References
BID 24972 - [Search]
OSVDB 37098 - [Search]
VUPEN ADV-2007-2616 - [Search]
XFDB 35493 - [Search]

Dates
Initial Date Seen [2007-07-27 18:30:00]
Last Date Updated [2011-03-07 21:57:40]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2007-4128 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2007-4128
Description
SQL injection vulnerability in index.php in the Firestorm Technologies GMaps (com_gmaps) 1.00 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the mapId parameter in a viewmap action.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploits
Milw0rm 4248 (site down: refer to www.exploit-db.org 4248) - [Search]
References
BID 25146 - [Search]
OSVDB 39192 - [Search]
VUPEN ADV-2007-2745 - [Search]
XFDB 35701 - [Search]

Dates
Initial Date Seen [2007-08-01 12:17:00]
Last Date Updated [2011-03-07 21:57:51]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2007-4184 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2007-4184
Description
SQL injection vulnerability in administrator/popups/pollwindow.php in Joomla! 1.0.12 allows remote attackers to execute arbitrary SQL commands via the pollid parameter.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P

Dates
Initial Date Seen [2007-08-07 21:17:00]
Last Date Updated [2008-09-05 17:27:37]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2007-4185 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2007-4185
Description
Joomla! 1.0.12 allows remote attackers to obtain sensitive information via a direct request for (1) Stat.php (2) OutputFilter.php, (3) OutputCache.php, (4) Modifier.php, (5) Reader.php, and (6) TemplateCache.php in includes/patTemplate/patTemplate/; (7) includes/Cache/Lite/Output.php; and other unspecified components, which reveal the path in various error messages.

CVSS
(5) AV:N/AC:L/Au:N/C:P/I:N/A:N
References
OSVDB 39037 - [Search]
OSVDB 39038 - [Search]
OSVDB 39039 - [Search]
OSVDB 39040 - [Search]
OSVDB 39041 - [Search]
OSVDB 39042 - [Search]
OSVDB 39043 - [Search]

Dates
Initial Date Seen [2007-08-07 21:17:00]
Last Date Updated [2008-11-15 01:56:08]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2007-4186 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2007-4186
Description
PHP remote file inclusion vulnerability in admin.tour_toto.php in the Tour de France Pool (com_tour_toto) 1.0.1 module for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.

CVSS
(5.1) AV:N/AC:H/Au:N/C:P/I:P/A:P
References
BID 25183 - [Search]
OSVDB 39059 - [Search]
XFDB 35779 - [Search]

Dates
Initial Date Seen [2007-08-07 21:17:00]
Last Date Updated [2008-11-15 01:56:08]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2007-4187 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2007-4187
Description
Multiple eval injection vulnerabilities in the com_search component in Joomla! 1.5 beta before RC1 (aka Mapya) allow remote attackers to execute arbitrary PHP code via PHP sequences in the searchword parameter, related to default_results.php in (1) components/com_search/views/search/tmpl/ and (2) templates/beez/html/com_search/search/.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
References
CWE CWE-94 - [Search]
OSVDB 41260 - [Search]

Dates
Initial Date Seen [2007-08-07 21:17:00]
Last Date Updated [2008-11-15 01:56:08]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2007-4188 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2007-4188
Description
Session fixation vulnerability in Joomla! before 1.0.13 (aka Sunglow) allows remote attackers to hijack administrative web sessions via unspecified vectors.

CVSS
(7.6) AV:N/AC:H/Au:N/C:C/I:C/A:C
References
CWE CWE-287 - [Search]
SECUNIA 26239 - [Search]
VUPEN ADV-2007-2719 - [Search]
XFDB 35953 - [Search]

Dates
Initial Date Seen [2007-08-07 21:17:00]
Last Date Updated [2011-03-07 21:57:57]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2007-4189 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2007-4189
Description
Multiple cross-site scripting (XSS) vulnerabilities in Joomla! before 1.0.13 (aka Sunglow) allow remote attackers to inject arbitrary web script or HTML via unspecified vectors in the (1) com_search, (2) com_content, and (3) mod_login components. NOTE: some of these details are obtained from third party information.

CVSS
(2.6) AV:N/AC:H/Au:N/C:N/I:P/A:N
References
OSVDB 38755 - [Search]
OSVDB 38756 - [Search]
OSVDB 38757 - [Search]
SECUNIA 26239 - [Search]
VUPEN ADV-2007-2719 - [Search]

Dates
Initial Date Seen [2007-08-07 21:17:00]
Last Date Updated [2011-03-07 21:57:57]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2007-4190 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2007-4190
Description
CRLF injection vulnerability in Joomla! before 1.0.13 (aka Sunglow) allows remote attackers to inject arbitrary HTTP headers and probably conduct HTTP response splitting attacks via CRLF sequences in the url parameter. NOTE: this can be leveraged for cross-site scripting (XSS) attacks. NOTE: some of these details are obtained from third party information.

CVSS
(2.6) AV:N/AC:H/Au:N/C:N/I:P/A:N
References
OSVDB 38739 - [Search]
SECUNIA 26239 - [Search]
VUPEN ADV-2007-2719 - [Search]

Dates
Initial Date Seen [2007-08-07 21:17:00]
Last Date Updated [2011-03-07 21:57:57]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2007-4244 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2007-4244
Description
PHP remote file inclusion vulnerability in langset.php in J! Reactions (com_jreactions) 1.8.1 and earlier, a Joomla! component, allows remote attackers to execute arbitrary PHP code via a URL in the comPath parameter.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
References
BID 25198 - [Search]
CWE CWE-94 - [Search]
XFDB 35808 - [Search]

Dates
Initial Date Seen [2007-08-08 19:17:00]
Last Date Updated [2008-09-05 17:27:46]

Copyright
© 2012 The MITRE Corporation

NESSUS 34018 match rank: 100%

Source
http://www.nessus.org/plugins/index.php?view=single&id=34018
Title
FreeBSD : joomla -- flaw in the reset token validation (8514b6e7-6f0f-11dd-b3db-001c2514716c)
Description
The remote FreeBSD host is missing a security-related update.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
References
CPE cpe:/o:freebsd:freebsd - [Search]
CVE-2008-3681 - [Search]
CWE 264 - [Search]
Tools
NESSUS 34018 - [Search]

Dates
Initial Date Seen [2008-08-21 00:00:00]
Last Date Updated [2011-11-18 00:00:00]

Copyright
© 2012 Tenable Network Security@

NVD CVE-2007-4456 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2007-4456
Description
SQL injection vulnerability in index.php in the SimpleFAQ (com_simplefaq) 2.11 component for Mambo allows remote attackers to execute arbitrary SQL commands via the aid parameter. NOTE: it was later reported that 2.40 is also affected, and that the component can be used in Joomla! in addition to Mambo.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploits
Milw0rm 4296 (site down: refer to www.exploit-db.org 4296) - [Search]
References
BID 25376 - [Search]
CWE CWE-89 - [Search]
SECUNIA 26556 - [Search]
XFDB 36113 - [Search]

Dates
Initial Date Seen [2007-08-21 17:17:00]
Last Date Updated [2008-09-05 17:28:17]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2007-4502 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2007-4502
Description
SQL injection vulnerability in index.php in the BibTeX component (com_jombib) 1.3 and earlier for Joomla! allows remote attackers to execute arbitrary SQL commands via the afilter parameter.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploits
Milw0rm 4310 (site down: refer to www.exploit-db.org 4310) - [Search]
References
OSVDB 38357 - [Search]
XFDB 36225 - [Search]

Dates
Initial Date Seen [2007-08-23 15:17:00]
Last Date Updated [2008-11-15 01:57:17]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2007-4503 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2007-4503
Description
SQL injection vulnerability in index.php in the Nice Talk component (com_nicetalk) 0.9.3 and earlier for Joomla! allows remote attackers to execute arbitrary SQL commands via the tagid parameter.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploits
Milw0rm 6794 (site down: refer to www.exploit-db.org 6794) - [Search]
Milw0rm 4308 (site down: refer to www.exploit-db.org 4308) - [Search]
References
BID 31818 - [Search]
OSVDB 36587 - [Search]
SECUNIA 26576 - [Search]
VUPEN ADV-2008-2858 - [Search]
XFDB 36224 - [Search]

Dates
Initial Date Seen [2007-08-23 15:17:00]
Last Date Updated [2011-03-07 21:58:40]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2007-4504 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2007-4504
Description
Directory traversal vulnerability in index.php in the RSfiles component (com_rsfiles) 1.0.2 and earlier for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the path parameter in a files.display action.

CVSS
(5) AV:N/AC:L/Au:N/C:P/I:N/A:N
Exploits
Milw0rm 4307 (site down: refer to www.exploit-db.org 4307) - [Search]
References
XFDB 36222 - [Search]

Dates
Initial Date Seen [2007-08-23 15:17:00]
Last Date Updated [2008-09-05 17:28:24]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2007-4506 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2007-4506
Description
SQL injection vulnerability in index.php in the NeoRecruit component (com_neorecruit) 1.4 and earlier for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in an offer_view action.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploits
Milw0rm 4305 (site down: refer to www.exploit-db.org 4305) - [Search]
References
BID 25578 - [Search]
OSVDB 36852 - [Search]
SECUNIA 26689 - [Search]
VUPEN ADV-2007-3079 - [Search]
XFDB 36216 - [Search]

Dates
Initial Date Seen [2007-08-23 15:17:00]
Last Date Updated [2011-03-07 21:58:41]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2007-4509 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2007-4509
Description
SQL injection vulnerability in index.php in the EventList component (com_eventlist) 0.8 and earlier for Joomla! allows remote attackers to execute arbitrary SQL commands via the did parameter in a details action.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploits
Milw0rm 4309 (site down: refer to www.exploit-db.org 4309) - [Search]
References
OSVDB 38360 - [Search]
XFDB 36223 - [Search]

Dates
Initial Date Seen [2007-08-23 15:17:00]
Last Date Updated [2008-11-15 01:57:19]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2007-4777 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2007-4777
Description
SQL injection vulnerability in Joomla! 1.5 before RC2 (aka Endeleo) allows remote attackers to execute arbitrary SQL commands via unspecified vectors, probably related to the archive section. NOTE: this may be the same as CVE-2007-4778.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
References
BID 25508 - [Search]
CWE CWE-89 - [Search]
OSVDB 39070 - [Search]
OSVDB 39071 - [Search]
OSVDB 39072 - [Search]
XFDB 36423 - [Search]

Dates
Initial Date Seen [2007-09-10 17:17:00]
Last Date Updated [2009-02-05 00:00:00]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2007-4778 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2007-4778
Description
Multiple SQL injection vulnerabilities in the content component (com_content) in Joomla! 1.5 Beta1, Beta2, and RC1 allow remote attackers to execute arbitrary SQL commands via the filter parameter in an archive action to (1) archive.php, (2) category.php, or (3) section.php in models/. NOTE: this may be the same as CVE-2007-4777.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
References
BID 25508 - [Search]
CWE CWE-89 - [Search]
OSVDB 39070 - [Search]
OSVDB 39071 - [Search]
OSVDB 39072 - [Search]
XFDB 36423 - [Search]

Dates
Initial Date Seen [2007-09-10 17:17:00]
Last Date Updated [2009-02-05 00:00:00]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2007-4779 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2007-4779
Description
Cross-site scripting (XSS) vulnerability in Joomla! 1.5 before RC2 (aka Endeleo) allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, probably related to the archive section.

CVSS
(2.6) AV:N/AC:H/Au:N/C:N/I:P/A:N
References
BID 25508 - [Search]
CWE CWE-79 - [Search]
OSVDB 38416 - [Search]
XFDB 36425 - [Search]

Dates
Initial Date Seen [2007-09-10 17:17:00]
Last Date Updated [2008-11-15 01:58:31]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2007-4780 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2007-4780
Description
Joomla! 1.5 before RC2 (aka Endeleo) allows remote attackers to obtain sensitive information (the full path) via unspecified vectors, probably involving direct requests to certain PHP scripts in tmpl/ directories.

CVSS
(5.1) AV:N/AC:H/Au:N/C:P/I:P/A:P
References
BID 25508 - [Search]
CWE CWE-20 - [Search]
OSVDB 45875 - [Search]
XFDB 36426 - [Search]

Dates
Initial Date Seen [2007-09-10 17:17:00]
Last Date Updated [2008-11-15 01:58:31]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2007-4781 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2007-4781
Description
administrator/index.php in the installer component (com_installer) in Joomla! 1.5 Beta1, Beta2, and RC1 allows remote authenticated administrators to upload arbitrary files to tmp/ via the "Upload Package File" functionality, which is accessible when com_installer is the value of the option parameter.

CVSS
(7.9) AV:N/AC:M/Au:S/C:N/I:C/A:C
Exploits
Milw0rm 4350 (site down: refer to www.exploit-db.org 4350) - [Search]
References
BID 25508 - [Search]
CWE CWE-20 - [Search]
OSVDB 45888 - [Search]
XFDB 36424 - [Search]

Dates
Initial Date Seen [2007-09-10 17:17:00]
Last Date Updated [2008-11-15 01:58:32]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2007-4817 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2007-4817
Description
Unrestricted file upload vulnerability in the Restaurante (com_restaurante) component for Joomla! allows remote attackers to upload and execute arbitrary PHP code via an upload action specifying a filename with a double extension such as .php.jpg, which creates an accessible file under img_original/.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploits
Milw0rm 4383 (site down: refer to www.exploit-db.org 4383) - [Search]
References
BID 25612 - [Search]
CWE CWE-94 - [Search]
SECUNIA 26756 - [Search]
VUPEN ADV-2007-3139 - [Search]
XFDB 36538 - [Search]

Dates
Initial Date Seen [2007-09-11 15:17:00]
Last Date Updated [2011-03-07 21:59:14]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2007-4954 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2007-4954
Description
PHP remote file inclusion vulnerability in admin.joom12pic.php in the joom12Pic (com_joom12pic) 1.0 component for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_live_site parameter.

CVSS
(5.1) AV:N/AC:H/Au:N/C:P/I:P/A:P
Exploits
Milw0rm 4416 (site down: refer to www.exploit-db.org 4416) - [Search]
References
BID 25691 - [Search]
CWE CWE-94 - [Search]
SECUNIA 26849 - [Search]
XFDB 36639 - [Search]

Dates
Initial Date Seen [2007-09-18 16:17:00]
Last Date Updated [2008-09-05 17:29:30]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2007-4955 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2007-4955
Description
PHP remote file inclusion vulnerability in admin.joomlaflashfun.php in the Flash Fun! (com_joomlaflashfun) 1.0 component for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_live_site parameter.

CVSS
(5.1) AV:N/AC:H/Au:N/C:P/I:P/A:P
Exploits
Milw0rm 4415 (site down: refer to www.exploit-db.org 4415) - [Search]
References
BID 25680 - [Search]
CWE CWE-94 - [Search]
SECUNIA 26799 - [Search]
XFDB 36638 - [Search]

Dates
Initial Date Seen [2007-09-18 16:17:00]
Last Date Updated [2008-09-05 17:29:30]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2007-5065 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2007-5065
Description
PHP remote file inclusion vulnerability in admin.slideshow1.php in the Flash Slide Show (com_slideshow) component for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_live_site parameter.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploits
Milw0rm 4440 (site down: refer to www.exploit-db.org 4440) - [Search]
References
BID 25760 - [Search]
CWE CWE-94 - [Search]
OSVDB 38157 - [Search]
XFDB 36719 - [Search]

Dates
Initial Date Seen [2007-09-24 18:17:00]
Last Date Updated [2008-11-15 01:59:35]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2007-5309 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2007-5309
Description
PHP remote file inclusion vulnerability in admin.wmtgallery.php in the webmaster-tips.net Flash Image Gallery (com_wmtgallery) 1.0 component for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_live_site parameter.

CVSS
(5.1) AV:N/AC:H/Au:N/C:P/I:P/A:P
Exploits
Milw0rm 4496 (site down: refer to www.exploit-db.org 4496) - [Search]
References
BID 25958 - [Search]
CWE CWE-94 - [Search]
OSVDB 38645 - [Search]
VUPEN ADV-2007-3434 - [Search]
XFDB 37016 - [Search]

Dates
Initial Date Seen [2007-10-09 17:17:00]
Last Date Updated [2011-03-07 22:00:29]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2007-5310 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2007-5310
Description
PHP remote file inclusion vulnerability in admin.wmtportfolio.php in the webmaster-tips.net wmtportfolio 1.0 (com_wmtportfolio) component for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.

CVSS
(5.1) AV:N/AC:H/Au:N/C:P/I:P/A:P
Exploits
Milw0rm 4497 (site down: refer to www.exploit-db.org 4497) - [Search]
References
BID 25959 - [Search]
CWE CWE-94 - [Search]
OSVDB 38644 - [Search]
XFDB 36993 - [Search]

Dates
Initial Date Seen [2007-10-09 17:17:00]
Last Date Updated [2008-11-15 02:00:34]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2007-5362 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2007-5362
Description
Multiple PHP remote file inclusion vulnerabilities in the Avant-Garde Solutions MOSMedia Lite (com_mosmedia) 4.5.1 component for Mambo and Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter to (1) credits.html.php, (2) info.html.php, (3) media.divs.php, (4) media.divs.js.php, (5) purchase.html.php, or (6) support.html.php in includes/. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. NOTE: vector 3 may be the same as CVE-2007-2043.2.

CVSS
(5.1) AV:N/AC:H/Au:N/C:P/I:P/A:P
References
BID 25960 - [Search]
CWE CWE-94 - [Search]
OSVDB 38586 - [Search]
OSVDB 38587 - [Search]
OSVDB 38588 - [Search]
XFDB 37015 - [Search]

Dates
Initial Date Seen [2007-10-10 21:17:00]
Last Date Updated [2008-11-15 02:00:44]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2007-5363 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2007-5363
Description
PHP remote file inclusion vulnerability in admin.panoramic.php in the Panoramic Picture Viewer (com_panoramic) mambot (plugin) 1.0 for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_live_site parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

CVSS
(5.1) AV:N/AC:H/Au:N/C:P/I:P/A:P
References
BID 25946 - [Search]
CWE CWE-94 - [Search]
OSVDB 38585 - [Search]
VUPEN ADV-2007-3428 - [Search]
XFDB 36992 - [Search]

Dates
Initial Date Seen [2007-10-10 21:17:00]
Last Date Updated [2011-03-07 22:00:34]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2007-5389 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2007-5389
Description
** DISPUTED ** PHP remote file inclusion vulnerability in preview.php in the swMenuFree (com_swmenufree) 4.6 component for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter. NOTE: a reliable third party disputes this issue because preview.php tests a certain constant to prevent direct requests.

CVSS
(5.1) AV:N/AC:H/Au:N/C:P/I:P/A:P
References
CWE CWE-94 - [Search]
OSVDB 37903 - [Search]

Dates
Initial Date Seen [2007-10-12 06:17:00]
Last Date Updated [2008-11-15 02:00:50]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2007-5407 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2007-5407
Description
Multiple PHP remote file inclusion vulnerabilities in the JContentSubscription (com_jcs) 1.5.8 component for Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter to (1) jcs.function.php; (2) add.php, (3) history.php, and (4) register.php, in view/; and (5) list.sub.html.php, (6) list.user.sub.html.php, and (7) reports.html.php in views/.

CVSS
(5.1) AV:N/AC:H/Au:N/C:P/I:P/A:P
Exploits
Milw0rm 4508 (site down: refer to www.exploit-db.org 4508) - [Search]
References
BID 26003 - [Search]
CWE CWE-94 - [Search]
OSVDB 43619 - [Search]
OSVDB 43620 - [Search]
OSVDB 43621 - [Search]
OSVDB 43622 - [Search]
OSVDB 43623 - [Search]
OSVDB 43624 - [Search]
OSVDB 43627 - [Search]
XFDB 37055 - [Search]

Dates
Initial Date Seen [2007-10-12 14:17:00]
Last Date Updated [2008-11-15 02:00:53]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2007-5410 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2007-5410
Description
PHP remote file inclusion vulnerability in admin.wmtrssreader.php in the webmaster-tips.net Flash RSS Reader (com_wmtrssreader) 1.0 component for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_live_site parameter.

CVSS
(5.1) AV:N/AC:H/Au:N/C:P/I:P/A:P
References
BID 25999 - [Search]
CWE CWE-94 - [Search]
OSVDB 43765 - [Search]
XFDB 37056 - [Search]

Dates
Initial Date Seen [2007-10-12 14:17:00]
Last Date Updated [2008-11-15 02:00:53]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2007-5412 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2007-5412
Description
Multiple PHP remote file inclusion vulnerabilities in the Quoc-Huy MP3 Allopass (com_mp3_allopass) 1.0 component for Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the mosConfig_live_site parameter to (1) allopass.php and (2) allopass-error.php.

CVSS
(5.1) AV:N/AC:H/Au:N/C:P/I:P/A:P
Exploits
Milw0rm 4507 (site down: refer to www.exploit-db.org 4507) - [Search]
References
BID 26002 - [Search]
CWE CWE-94 - [Search]
OSVDB 43630 - [Search]
OSVDB 43631 - [Search]
XFDB 37054 - [Search]

Dates
Initial Date Seen [2007-10-12 14:17:00]
Last Date Updated [2008-11-15 02:00:53]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2007-5427 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2007-5427
Description
Cross-site scripting (XSS) vulnerability in the com_search component in Joomla! 1.0.13 and earlier allows remote attackers to inject arbitrary web script or HTML via the searchword parameter. NOTE: this might be related to CVE-2007-4189.1.

CVSS
(2.6) AV:N/AC:H/Au:N/C:N/I:P/A:N
References
BID 26031 - [Search]
CWE CWE-79 - [Search]
OSVDB 37709 - [Search]
SECUNIA 27196 - [Search]
VUPEN ADV-2007-3495 - [Search]

Dates
Initial Date Seen [2007-10-12 19:17:00]
Last Date Updated [2011-03-07 22:00:40]

Copyright
© 2012 The MITRE Corporation

NESSUS 37451 match rank: 100%

Source
http://www.nessus.org/plugins/index.php?view=single&id=37451
Title
Mandriva Linux Security Advisory : joomla (MDVSA-2008:060)
Description
The remote Mandriva Linux host is missing one or more security updates.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
References
CPE cpe:/o:mandriva:linux:2007 - [Search]
CPE cpe:/o:mandriva:linux:2007.1 - [Search]
CPE cpe:/o:mandriva:linux:2008.0 - [Search]
CVE-2007-6642 - [Search]
CVE-2007-6643 - [Search]
CVE-2007-6644 - [Search]
CVE-2007-6645 - [Search]
CWE 264 - [Search]
OSVDB 39979 - [Search]
OSVDB 41263 - [Search]
OSVDB 43276 - [Search]
OSVDB 43277 - [Search]
Tools
NESSUS 37451 - [Search]

Dates
Initial Date Seen [2009-04-23 00:00:00]
Last Date Updated [2013-02-09 00:00:00]

Copyright
© 2012 Tenable Network Security@

NVD CVE-2007-5451 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2007-5451
Description
PHP remote file inclusion vulnerability in admin.color.php in the com_colorlab (aka com_color) 1.0 component for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_live_site parameter.

CVSS
(5.1) AV:N/AC:H/Au:N/C:P/I:P/A:P
Exploits
Milw0rm 4524 (site down: refer to www.exploit-db.org 4524) - [Search]
References
BID 26059 - [Search]
CWE CWE-94 - [Search]
OSVDB 40609 - [Search]

Dates
Initial Date Seen [2007-10-14 14:17:00]
Last Date Updated [2008-11-15 02:01:01]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2007-5577 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2007-5577
Description
Multiple cross-site scripting (XSS) vulnerabilities in Joomla! before 1.0.13 (aka Sunglow) allow remote attackers to inject arbitrary web script or HTML via the (1) Title or (2) Section Name form fields in the Section Manager component, or (3) multiple unspecified fields in New Menu Item.

CVSS
(2.6) AV:N/AC:H/Au:N/C:N/I:P/A:N
References
BID 24663 - [Search]
CWE CWE-79 - [Search]
OSVDB 37173 - [Search]
SECUNIA 25804 - [Search]
XFDB 35119 - [Search]

Dates
Initial Date Seen [2007-10-18 17:17:00]
Last Date Updated [2008-11-15 02:01:25]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2007-6027 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2007-6027
Description
PHP remote file inclusion vulnerability in admin.jjgallery.php in the Carousel Flash Image Gallery (com_jjgallery) component for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.

CVSS
(5.1) AV:N/AC:H/Au:N/C:P/I:P/A:P
Exploits
Milw0rm 4626 (site down: refer to www.exploit-db.org 4626) - [Search]
References
BID 26471 - [Search]
CWE CWE-94 - [Search]
VUPEN ADV-2007-3907 - [Search]
XFDB 38500 - [Search]

Dates
Initial Date Seen [2007-11-19 20:46:00]
Last Date Updated [2011-03-07 22:01:40]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2007-6038 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2007-6038
Description
PHP remote file inclusion vulnerability in xajax_functions.php in the JUser (com_juser) 1.0.14 component for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.

CVSS
(5.1) AV:N/AC:H/Au:N/C:P/I:P/A:P
Exploits
Milw0rm 4636 (site down: refer to www.exploit-db.org 4636) - [Search]
References
BID 26499 - [Search]
CWE CWE-94 - [Search]
XFDB 38555 - [Search]

Dates
Initial Date Seen [2007-11-20 06:46:00]
Last Date Updated [2008-09-05 17:32:14]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2007-6272 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2007-6272
Description
Multiple SQL injection vulnerabilities in index.php in Joomla! 1.5 RC3 allow remote attackers to execute arbitrary SQL commands via (1) the view parameter to the com_content component, (2) the task parameter to the com_search component, or (3) the option parameter in a search action to the com_search component.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
References
BID 26707 - [Search]
CWE CWE-89 - [Search]
XFDB 38867 - [Search]

Dates
Initial Date Seen [2007-12-07 06:46:00]
Last Date Updated [2008-09-05 17:32:49]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2007-6362 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2007-6362
Description
SQL injection vulnerability in index.php in the RSGallery (com_rsgallery) 2.0 beta 5 and earlier component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter in an inline page action.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploits
Milw0rm 4691 (site down: refer to www.exploit-db.org 4691) - [Search]
References
BID 26704 - [Search]
CWE CWE-89 - [Search]

Dates
Initial Date Seen [2007-12-14 20:46:00]
Last Date Updated [2008-09-05 17:33:03]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2007-6555 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2007-6555
Description
PHP remote file inclusion vulnerability in modules/mod_pxt_latest.php in the mosDirectory (com_directory) 2.3.2 component for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[mosConfig_absolute_path] parameter.

CVSS
(7.6) AV:N/AC:H/Au:N/C:C/I:C/A:C
Exploits
Milw0rm 4783 (site down: refer to www.exploit-db.org 4783) - [Search]
References
BID 27014 - [Search]
CWE CWE-94 - [Search]
OSVDB 40023 - [Search]

Dates
Initial Date Seen [2007-12-27 19:46:00]
Last Date Updated [2008-11-15 02:05:05]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2007-6642 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2007-6642
Description
Multiple cross-site request forgery (CSRF) vulnerabilities in Joomla! before 1.5 RC4 allow remote attackers to (1) add a Super Admin, (2) upload an extension containing arbitrary PHP code, and (3) modify the configuration as administrators via unspecified vectors.

CVSS
(5.1) AV:N/AC:H/Au:N/C:P/I:P/A:P
References
BID 28111 - [Search]
CWE CWE-352 - [Search]
OSVDB 41263 - [Search]
SECUNIA 29257 - [Search]

Dates
Initial Date Seen [2008-01-03 20:46:00]
Last Date Updated [2008-11-15 02:05:42]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2007-6643 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2007-6643
Description
Cross-site scripting (XSS) vulnerability in the com_poll component in Joomla! before 1.5 RC4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS
(2.6) AV:N/AC:H/Au:N/C:N/I:P/A:N
References
BID 28111 - [Search]
CWE CWE-79 - [Search]
OSVDB 39979 - [Search]
SECUNIA 29257 - [Search]

Dates
Initial Date Seen [2008-01-03 20:46:00]
Last Date Updated [2008-11-15 02:05:42]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2007-6644 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2007-6644
Description
Joomla! before 1.5 RC4 allows remote authenticated administrators to promote arbitrary users to the administrator group, in violation of the intended security model.

CVSS
(6.5) AV:N/AC:L/Au:S/C:P/I:P/A:P
References
BID 28111 - [Search]
CWE CWE-264 - [Search]
OSVDB 43277 - [Search]
SECUNIA 29257 - [Search]

Dates
Initial Date Seen [2008-01-03 20:46:00]
Last Date Updated [2008-11-15 02:05:42]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2007-6645 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2007-6645
Description
Unspecified vulnerability in Joomla! before 1.5 RC4 allows remote authenticated users to gain privileges via unspecified vectors, aka "registered user privilege escalation vulnerability."

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
References
BID 28111 - [Search]
CWE CWE-264 - [Search]
OSVDB 43276 - [Search]
SECUNIA 29257 - [Search]

Dates
Initial Date Seen [2008-01-03 20:46:00]
Last Date Updated [2008-11-15 02:05:42]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2007-6663 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2007-6663
Description
SQL injection vulnerability in (1) Puarcade.php and (2) PUarcade.html.php in Pragmatic Utopia PU Arcade (com_puarcade) 2.0.3, 2.1.2, and 2.1.3 Beta component for Joomla! allows remote attackers to execute arbitrary SQL commands via the fid parameter to index.php.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploits
Milw0rm 4827 (site down: refer to www.exploit-db.org 4827) - [Search]
References
BID 27089 - [Search]
CWE CWE-89 - [Search]
OSVDB 39787 - [Search]
OSVDB 39886 - [Search]
SECUNIA 28295 - [Search]
VUPEN ADV-2008-0052 - [Search]
XFDB 39332 - [Search]

Dates
Initial Date Seen [2008-01-04 06:46:00]
Last Date Updated [2011-08-05 00:00:00]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2008-0510 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-0510
Description
SQL injection vulnerability in index.php in the Newsletter (com_newsletter) component for Mambo 4.5 and Joomla! allows remote attackers to execute arbitrary SQL commands via the listid parameter.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploits
Milw0rm 5007 (site down: refer to www.exploit-db.org 5007) - [Search]
References
BID 27502 - [Search]
CWE CWE-89 - [Search]
VUPEN ADV-2008-0354 - [Search]
XFDB 40036 - [Search]

Dates
Initial Date Seen [2008-01-31 15:00:00]
Last Date Updated [2011-03-07 22:04:49]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2008-0511 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-0511
Description
SQL injection vulnerability in index.php in the MaMML (com_mamml) component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the listid parameter.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploits
Milw0rm 5009 (site down: refer to www.exploit-db.org 5009) - [Search]
References
BID 27503 - [Search]
CWE CWE-89 - [Search]
VUPEN ADV-2008-0356 - [Search]
XFDB 40037 - [Search]

Dates
Initial Date Seen [2008-01-31 15:00:00]
Last Date Updated [2011-03-07 22:04:49]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2008-0512 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-0512
Description
SQL injection vulnerability in index.php in the fq (com_fq) component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the listid parameter.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploits
Milw0rm 5008 (site down: refer to www.exploit-db.org 5008) - [Search]
References
BID 27501 - [Search]
CWE CWE-89 - [Search]
VUPEN ADV-2008-0355 - [Search]
XFDB 40035 - [Search]

Dates
Initial Date Seen [2008-01-31 15:00:00]
Last Date Updated [2011-03-07 22:04:49]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2008-0514 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-0514
Description
SQL injection vulnerability in index.php in the Glossary (com_glossary) 2.0 component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter in a display action.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploits
Milw0rm 5010 (site down: refer to www.exploit-db.org 5010) - [Search]
References
BID 27505 - [Search]
CWE CWE-89 - [Search]
VUPEN ADV-2008-0357 - [Search]
XFDB 40038 - [Search]

Dates
Initial Date Seen [2008-01-31 15:00:00]
Last Date Updated [2011-03-07 22:04:49]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2008-0515 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-0515
Description
SQL injection vulnerability in index.php in the musepoes (com_musepoes) component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the aid parameter in an answer action.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploits
Milw0rm 5011 (site down: refer to www.exploit-db.org 5011) - [Search]
References
BID 27507 - [Search]
CWE CWE-89 - [Search]
VUPEN ADV-2008-0358 - [Search]

Dates
Initial Date Seen [2008-01-31 15:00:00]
Last Date Updated [2011-03-07 22:04:49]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2008-0517 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-0517
Description
SQL injection vulnerability in index.php in the Darko Selesi EstateAgent (com_estateagent) 0.1 component for Mambo 4.5.x and Joomla! allows remote attackers to execute arbitrary SQL commands via the objid parameter in a contact showObject action.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploits
Milw0rm 5016 (site down: refer to www.exploit-db.org 5016) - [Search]
References
BID 27520 - [Search]
CWE CWE-89 - [Search]
VUPEN ADV-2008-0362 - [Search]
XFDB 40060 - [Search]

Dates
Initial Date Seen [2008-01-31 15:00:00]
Last Date Updated [2011-03-07 22:04:50]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2008-0518 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-0518
Description
SQL injection vulnerability in index.php in the Recipes (com_recipes) 1.00 component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a detail action.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploits
Milw0rm 5014 (site down: refer to www.exploit-db.org 5014) - [Search]
References
BID 27519 - [Search]
CWE CWE-89 - [Search]
VUPEN ADV-2008-0360 - [Search]
XFDB 40064 - [Search]

Dates
Initial Date Seen [2008-01-31 15:00:00]
Last Date Updated [2011-03-07 22:04:50]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2008-0519 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-0519
Description
SQL injection vulnerability in index.php in the Atapin Jokes (com_jokes) 1.0 component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the cat parameter in a CatView action.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploits
Milw0rm 5015 (site down: refer to www.exploit-db.org 5015) - [Search]
References
BID 27522 - [Search]
CWE CWE-89 - [Search]
VUPEN ADV-2008-0361 - [Search]
XFDB 40067 - [Search]

Dates
Initial Date Seen [2008-01-31 15:00:00]
Last Date Updated [2011-03-07 22:04:50]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2008-0557 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-0557
Description
SQL injection vulnerability in index.php in the CatalogShop (com_catalogshop) 1.0b1 componenent for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a detail action.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploits
Milw0rm 5030 (site down: refer to www.exploit-db.org 5030) - [Search]
References
BID 27558 - [Search]
CWE CWE-89 - [Search]
XFDB 40142 - [Search]

Dates
Initial Date Seen [2008-02-04 18:00:00]
Last Date Updated [2009-09-15 01:11:21]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2008-0561 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-0561
Description
SQL injection vulnerability in index.php in the Arthur Konze AkoGallery (com_akogallery) 2.5 beta component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a detail action.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploits
Milw0rm 5029 (site down: refer to www.exploit-db.org 5029) - [Search]
References
BID 27557 - [Search]
CWE CWE-89 - [Search]
XFDB 40141 - [Search]

Dates
Initial Date Seen [2008-02-04 18:00:00]
Last Date Updated [2008-09-05 17:35:24]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2008-0562 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-0562
Description
SQL injection vulnerability in index.php in the Restaurant (com_restaurant) 1.0 component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a detail action.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploits
Milw0rm 5031 (site down: refer to www.exploit-db.org 5031) - [Search]
References
BID 27551 - [Search]
CWE CWE-89 - [Search]
XFDB 40144 - [Search]

Dates
Initial Date Seen [2008-02-04 18:00:00]
Last Date Updated [2008-09-05 17:35:24]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2008-0567 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-0567
Description
Multiple PHP remote file inclusion vulnerabilities in ChronoEngine ChronoForms (com_chronocontact) 2.3.5 component for Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter to (1) PPS/File.php, (2) Writer.php, and (3) PPS.php in excelwriter/; and (4) BIFFwriter.php, (5) Workbook.php, (6) Worksheet.php, and (7) Format.php in excelwriter/Writer/.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploits
Milw0rm 5020 (site down: refer to www.exploit-db.org 5020) - [Search]
References
BID 27531 - [Search]
CWE CWE-94 - [Search]

Dates
Initial Date Seen [2008-02-04 21:00:00]
Last Date Updated [2008-09-05 17:35:25]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2008-0579 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-0579
Description
SQL injection vulnerability in index.php in the buslicense (com_buslicense) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the aid parameter in a list action.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploits
Milw0rm 5011 (site down: refer to www.exploit-db.org 5011) - [Search]
References
BID 27508 - [Search]
CWE CWE-89 - [Search]
VUPEN ADV-2008-0359 - [Search]

Dates
Initial Date Seen [2008-02-04 22:00:00]
Last Date Updated [2011-03-07 22:04:56]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2008-0603 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-0603
Description
SQL injection vulnerability in index.php in the amazOOP Awesom! (com_awesom) 0.3.2component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the listid parameter in a viewlist task.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploits
Milw0rm 5058 (site down: refer to www.exploit-db.org 5058) - [Search]
References
BID 27607 - [Search]
CWE CWE-89 - [Search]

Dates
Initial Date Seen [2008-02-06 07:00:00]
Last Date Updated [2008-09-05 17:35:31]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2008-0606 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-0606
Description
SQL injection vulnerability in index.php in the Shambo2 (com_shambo2) component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the Itemid parameter.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploits
Milw0rm 5059 (site down: refer to www.exploit-db.org 5059) - [Search]
References
BID 27609 - [Search]
CWE CWE-89 - [Search]
XFDB 40238 - [Search]

Dates
Initial Date Seen [2008-02-06 07:00:00]
Last Date Updated [2008-09-05 17:35:31]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2008-0607 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-0607
Description
SQL injection vulnerability in index.php in the Sigsiu Online Business Index 2 (SOBI2, com_sobi2) 2.5.3 component for Joomla! and Mambo allows remote attackers to execute arbitrary SQL commands via the catid parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploits
Milw0rm 5038 (site down: refer to www.exploit-db.org 5038) - [Search]
References
BID 27617 - [Search]
CWE CWE-89 - [Search]

Dates
Initial Date Seen [2008-02-06 07:00:00]
Last Date Updated [2008-09-05 17:35:31]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2008-0652 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-0652
Description
SQL injection vulnerability in index.php in the Downloads (com_downloads) component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the filecatid parameter in a selectfolder action.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploits
Milw0rm 5073 (site down: refer to www.exploit-db.org 5073) - [Search]
References
BID 27648 - [Search]
CWE CWE-89 - [Search]

Dates
Initial Date Seen [2008-02-07 16:00:00]
Last Date Updated [2008-09-05 17:35:38]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2008-0653 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-0653
Description
SQL injection vulnerability in index.php in the Ynews (com_ynews) 1.0.0 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a showYNews action.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploits
Milw0rm 5072 (site down: refer to www.exploit-db.org 5072) - [Search]
References
BID 27649 - [Search]
CWE CWE-89 - [Search]

Dates
Initial Date Seen [2008-02-07 16:00:00]
Last Date Updated [2009-08-25 01:09:02]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2008-0670 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-0670
Description
SQL injection vulnerability in index.php in the Noticias (com_noticias) 1.0 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a detalhe action.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploits
Milw0rm 5081 (site down: refer to www.exploit-db.org 5081) - [Search]
References
BID 27691 - [Search]
CWE CWE-89 - [Search]

Dates
Initial Date Seen [2008-02-11 20:00:00]
Last Date Updated [2008-09-05 17:35:41]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2008-0686 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-0686
Description
SQL injection vulnerability in index.php in the NeoReferences (com_neoreferences) 1.3.1 and 1.3.3 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploits
Milw0rm 5034 (site down: refer to www.exploit-db.org 5034) - [Search]
References
BID 27564 - [Search]
CWE CWE-89 - [Search]
SECUNIA 28736 - [Search]
XFDB 40167 - [Search]

Dates
Initial Date Seen [2008-02-11 20:00:00]
Last Date Updated [2008-09-05 17:35:43]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2008-0689 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-0689
Description
SQL injection vulnerability in index.php in the Marketplace (com_marketplace) 1.1.1 and 1.1.1-pl1 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter in a show_category action.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploits
Milw0rm 5055 (site down: refer to www.exploit-db.org 5055) - [Search]
References
BID 27600 - [Search]
CWE CWE-89 - [Search]

Dates
Initial Date Seen [2008-02-11 20:00:00]
Last Date Updated [2008-11-15 02:08:42]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2008-0690 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-0690
Description
SQL injection vulnerability in index.php in the mosDirectory (com_directory) 2.3.2 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter in a viewcat action.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploits
Milw0rm 5047 (site down: refer to www.exploit-db.org 5047) - [Search]
References
BID 27585 - [Search]
CWE CWE-89 - [Search]

Dates
Initial Date Seen [2008-02-11 20:00:00]
Last Date Updated [2008-11-04 02:01:32]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2008-0746 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-0746
Description
SQL injection vulnerability in index.php in the Gallery (com_gallery) component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a detail action.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploits
Milw0rm 5084 (site down: refer to www.exploit-db.org 5084) - [Search]
References
BID 27695 - [Search]
CWE CWE-89 - [Search]

Dates
Initial Date Seen [2008-02-13 15:00:00]
Last Date Updated [2008-09-05 17:35:52]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2008-0752 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-0752
Description
SQL injection vulnerability in index.php in the Neogallery (com_neogallery) 1.1 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter in a show action.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploits
Milw0rm 5083 (site down: refer to www.exploit-db.org 5083) - [Search]
References
BID 27692 - [Search]
CWE CWE-89 - [Search]
XFDB 40357 - [Search]

Dates
Initial Date Seen [2008-02-13 15:00:00]
Last Date Updated [2008-09-05 17:35:53]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2008-0754 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-0754
Description
Multiple SQL injection vulnerabilities in index.php in the Rapid Recipe (com_rapidrecipe) 1.6.5 component for Joomla! allow remote attackers to execute arbitrary SQL commands via (1) the user_id parameter in a showuser action or (2) the category_id parameter in a viewcategorysrecipes action.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
References
BID 27724 - [Search]
CWE CWE-89 - [Search]
SECUNIA 28883 - [Search]

Dates
Initial Date Seen [2008-02-13 15:00:00]
Last Date Updated [2009-09-19 00:00:00]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2008-0761 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-0761
Description
SQL injection vulnerability in index.php in the Prince Clan Chess Club (com_pcchess) 0.8 and earlier component for Joomla! allows remote attackers to execute arbitrary SQL commands via the user_id parameter in a players action.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploits
Milw0rm 5104 (site down: refer to www.exploit-db.org 5104) - [Search]
References
BID 27761 - [Search]
CWE CWE-89 - [Search]
XFDB 40436 - [Search]

Dates
Initial Date Seen [2008-02-13 16:00:00]
Last Date Updated [2008-09-05 17:35:55]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2008-0762 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-0762
Description
SQL injection vulnerability in index.php in the com_iomezun component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in an edit action.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
References
BID 27748 - [Search]
CWE CWE-89 - [Search]
XFDB 40447 - [Search]

Dates
Initial Date Seen [2008-02-13 16:00:00]
Last Date Updated [2008-09-05 17:35:55]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2008-0772 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-0772
Description
SQL injection vulnerability in index.php in the com_doc component for Joomla! and Mambo allows remote attackers to execute arbitrary SQL commands via the sid parameter in a view task.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploits
Milw0rm 5080 (site down: refer to www.exploit-db.org 5080) - [Search]
References
BID 27679 - [Search]
CWE CWE-89 - [Search]

Dates
Initial Date Seen [2008-02-13 19:00:00]
Last Date Updated [2008-09-05 17:35:56]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2008-0795 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-0795
Description
SQL injection vulnerability in index.php in the MGFi XfaQ (com_xfaq) 1.2 component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the aid parameter in an answer action.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploits
Milw0rm 5109 (site down: refer to www.exploit-db.org 5109) - [Search]
References
BID 27784 - [Search]
CWE CWE-89 - [Search]
XFDB 40494 - [Search]

Dates
Initial Date Seen [2008-02-15 17:00:00]
Last Date Updated [2008-09-05 17:36:00]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2008-0799 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-0799
Description
SQL injection vulnerability in index.php in the Quiz (com_quiz) 0.81 and earlier component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the tid parameter in a user_tst_shw action.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploits
Milw0rm 5119 (site down: refer to www.exploit-db.org 5119) - [Search]
References
BID 27808 - [Search]
CWE CWE-89 - [Search]
SECUNIA 28980 - [Search]

Dates
Initial Date Seen [2008-02-15 17:00:00]
Last Date Updated [2008-09-05 17:36:01]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2008-0800 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-0800
Description
SQL injection vulnerability in index.php in the McQuiz (com_mcquiz) 0.9 Final component for Joomla! allows remote attackers to execute arbitrary SQL commands via the tid parameter in a user_tst_shw action.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploits
Milw0rm 5118 (site down: refer to www.exploit-db.org 5118) - [Search]
References
BID 27809 - [Search]
CWE CWE-89 - [Search]
SECUNIA 28940 - [Search]

Dates
Initial Date Seen [2008-02-15 17:00:00]
Last Date Updated [2008-09-05 17:36:01]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2008-0801 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-0801
Description
SQL injection vulnerability in index.php in the PAXXGallery (com_paxxgallery) 0.2 component for Mambo and Joomla! allow remote attackers to execute arbitrary SQL commands via (1) the iid parameter in a view action, and possibly (2) the userid parameter.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploits
Milw0rm 5117 (site down: refer to www.exploit-db.org 5117) - [Search]
References
BID 27811 - [Search]
CWE CWE-89 - [Search]
XFDB 40497 - [Search]

Dates
Initial Date Seen [2008-02-15 17:00:00]
Last Date Updated [2011-09-08 00:00:00]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2008-0802 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-0802
Description
SQL injection vulnerability in index.php in the MediaSlide (com_mediaslide) 0.5 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the albumnum parameter in a contact action.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploits
Milw0rm 5120 (site down: refer to www.exploit-db.org 5120) - [Search]
References
BID 27805 - [Search]
CWE CWE-89 - [Search]
SECUNIA 28962 - [Search]
XFDB 40517 - [Search]

Dates
Initial Date Seen [2008-02-15 17:00:00]
Last Date Updated [2008-09-05 17:36:01]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2008-0810 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-0810
Description
SQL injection vulnerability in the com_scheduling module for Joomla! and Mambo allows remote attackers to execute arbitrary SQL commands via the id parameter.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
References
BID 27830 - [Search]
CWE CWE-89 - [Search]

Dates
Initial Date Seen [2008-02-18 21:00:00]
Last Date Updated [2008-09-05 17:36:03]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2008-0815 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-0815
Description
SQL injection vulnerability in the com_mezun component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in an edit task.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
References
BID 27755 - [Search]
CWE CWE-89 - [Search]
XFDB 40448 - [Search]

Dates
Initial Date Seen [2008-02-18 21:00:00]
Last Date Updated [2008-09-05 17:36:03]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2008-0816 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-0816
Description
SQL injection vulnerability in the com_sg component for Joomla! and Mambo allows remote attackers to execute arbitrary SQL commands via the pid parameter in an order task.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
References
BID 27821 - [Search]
CWE CWE-89 - [Search]

Dates
Initial Date Seen [2008-02-18 21:00:00]
Last Date Updated [2008-09-05 17:36:03]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2008-0817 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-0817
Description
SQL injection vulnerability in the com_filebase component for Joomla! and Mambo allows remote attackers to execute arbitrary SQL commands via the filecatid parameter in a selectfolder action.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
References
BID 27829 - [Search]
CWE CWE-89 - [Search]
XFDB 40616 - [Search]

Dates
Initial Date Seen [2008-02-18 21:00:00]
Last Date Updated [2008-09-05 17:36:04]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2008-0829 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-0829
Description
SQL injection vulnerability in jooget.php in the Joomlapixel Jooget! (com_jooget) 2.6.8 component for Joomla! and Mambo allows remote attackers to execute arbitrary SQL commands via the id parameter in a detail task.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploits
Milw0rm 5132 (site down: refer to www.exploit-db.org 5132) - [Search]
References
BID 27836 - [Search]
CWE CWE-89 - [Search]
SECUNIA 28998 - [Search]

Dates
Initial Date Seen [2008-02-19 16:44:00]
Last Date Updated [2008-09-05 17:36:06]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2008-0831 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-0831
Description
Multiple SQL injection vulnerabilities in the Rapid Recipe (com_rapidrecipe) 1.6.5 and earlier component for Joomla! allow remote attackers to execute arbitrary SQL commands via the (1) user_id or (2) category_id parameter. NOTE: this might overlap CVE-2008-0754.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploits
Milw0rm 5103 (site down: refer to www.exploit-db.org 5103) - [Search]
References
CWE CWE-89 - [Search]

Dates
Initial Date Seen [2008-02-20 14:44:00]
Last Date Updated [2008-09-05 17:36:06]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2008-0832 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-0832
Description
SQL injection vulnerability in index.php in the Kemas Antonius com_quran 1.1 and earlier component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the surano parameter in a viewayat action.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploits
Milw0rm 5128 (site down: refer to www.exploit-db.org 5128) - [Search]
References
BID 27842 - [Search]
CWE CWE-89 - [Search]
OSVDB 52226 - [Search]
SECUNIA 28986 - [Search]
XFDB 40573 - [Search]

Dates
Initial Date Seen [2008-02-20 14:44:00]
Last Date Updated [2009-08-25 01:09:21]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2008-0833 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-0833
Description
SQL injection vulnerability in index.php in the com_galeria component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a detail action.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploits
Milw0rm 5134 (site down: refer to www.exploit-db.org 5134) - [Search]
References
BID 27833 - [Search]
CWE CWE-89 - [Search]

Dates
Initial Date Seen [2008-02-20 14:44:00]
Last Date Updated [2009-08-25 01:09:21]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2008-0839 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-0839
Description
SQL injection vulnerability in refer.php in the astatsPRO (com_astatspro) 1.0 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploits
Milw0rm 5138 (site down: refer to www.exploit-db.org 5138) - [Search]
References
BID 27850 - [Search]
CWE CWE-89 - [Search]
SECUNIA 29008 - [Search]
XFDB 40611 - [Search]

Dates
Initial Date Seen [2008-02-20 16:44:00]
Last Date Updated [2008-09-05 17:36:07]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2008-0841 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-0841
Description
SQL injection vulnerability in index.php in the Giorgio Nordo Ricette (com_ricette) 1.0 component for Joomla! and Mambo allows remote attackers to execute arbitrary SQL commands via the id parameter.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploits
Milw0rm 5133 (site down: refer to www.exploit-db.org 5133) - [Search]
References
BID 27834 - [Search]
CWE CWE-89 - [Search]

Dates
Initial Date Seen [2008-02-20 16:44:00]
Last Date Updated [2008-09-05 17:36:07]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2008-0842 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-0842
Description
SQL injection vulnerability in index.php in the Classifier (com_clasifier) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the cat_id parameter.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploits
Milw0rm 5146 (site down: refer to www.exploit-db.org 5146) - [Search]
References
BID 27917 - [Search]
CWE CWE-89 - [Search]
VUPEN ADV-2008-0620 - [Search]
XFDB 40629 - [Search]

Dates
Initial Date Seen [2008-02-20 16:44:00]
Last Date Updated [2011-03-07 22:05:32]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2008-0844 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-0844
Description
SQL injection vulnerability in index.php in the PccookBook (com_pccookbook) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the user_id parameter.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploits
Milw0rm 5145 (site down: refer to www.exploit-db.org 5145) - [Search]
References
BID 27864 - [Search]
CWE CWE-89 - [Search]
XFDB 40620 - [Search]

Dates
Initial Date Seen [2008-02-20 16:44:00]
Last Date Updated [2008-09-05 17:36:08]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2008-0846 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-0846
Description
SQL injection vulnerability in index.php in the com_profile component for Joomla! allows remote attackers to execute arbitrary SQL commands via the oid parameter.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
References
BID 27851 - [Search]
CWE CWE-89 - [Search]

Dates
Initial Date Seen [2008-02-20 16:44:00]
Last Date Updated [2008-09-05 17:36:08]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2008-0849 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-0849
Description
SQL injection vulnerability in index.php in the Downloads (com_downloads) component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the cat parameter in a selectcat function, a different vector than CVE-2008-0652.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
References
BID 27860 - [Search]
CWE CWE-89 - [Search]
XFDB 40621 - [Search]

Dates
Initial Date Seen [2008-02-20 19:44:00]
Last Date Updated [2008-09-05 17:36:09]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2008-0853 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-0853
Description
SQL injection vulnerability in the com_detail component for Joomla! and Mambo allows remote attackers to execute arbitrary SQL commands via the id parameter to index.php. NOTE: this issue might be site-specific. If so, it should not be included in CVE.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
References
BID 27853 - [Search]
CWE CWE-89 - [Search]

Dates
Initial Date Seen [2008-02-20 19:44:00]
Last Date Updated [2008-09-05 17:36:09]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2008-0854 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-0854
Description
SQL injection vulnerability in the com_salesrep component for Joomla! and Mambo allows remote attackers to execute arbitrary SQL commands via the rid parameter in a showrep action to index.php.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
References
BID 27827 - [Search]
CWE CWE-89 - [Search]
XFDB 40619 - [Search]

Dates
Initial Date Seen [2008-02-20 19:44:00]
Last Date Updated [2008-09-05 17:36:09]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2008-0855 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-0855
Description
SQL injection vulnerability in the Facile Forms (com_facileforms) component for Joomla! and Mambo allows remote attackers to execute arbitrary SQL commands via the catid parameter to index.php.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
References
BID 27880 - [Search]
CWE CWE-89 - [Search]

Dates
Initial Date Seen [2008-02-20 19:44:00]
Last Date Updated [2008-09-05 17:36:10]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2008-0916 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-0916
Description
SQL injection vulnerability in the Highwood Design hwdVideoShare (com_hwdvideoshare) 1.1.3 Alpha component for Joomla! allows remote attackers to execute arbitrary SQL commands via the cat_id parameter in a viewcategory action to index.php.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploits
Milw0rm 5160 (site down: refer to www.exploit-db.org 5160) - [Search]
References
BID 27907 - [Search]
CWE CWE-89 - [Search]
SECUNIA 29044 - [Search]
XFDB 40711 - [Search]

Dates
Initial Date Seen [2008-02-22 18:44:00]
Last Date Updated [2008-09-05 17:36:19]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2008-0918 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-0918
Description
SQL injection vulnerability in includes/count_dl_or_link.inc.php in the astatsPRO (com_astatspro) 1.0.1 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter to getfile.php, a different vector than CVE-2008-0839. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
References
CWE CWE-89 - [Search]
SECUNIA 29008 - [Search]
XFDB 40852 - [Search]

Dates
Initial Date Seen [2008-02-22 18:44:00]
Last Date Updated [2008-09-05 17:36:20]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2008-1077 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-1077
Description
SQL injection vulnerability in index.php in the Simpleboard (com_simpleboard) 1.0.3 Stable component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter in a view action.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploits
Milw0rm 5195 (site down: refer to www.exploit-db.org 5195) - [Search]
References
BID 28018 - [Search]
CWE CWE-89 - [Search]

Dates
Initial Date Seen [2008-02-28 19:44:00]
Last Date Updated [2008-09-05 17:36:45]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2008-1137 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-1137
Description
SQL injection vulnerability in the Garys Cookbook (com_garyscookbook) 1.1.1 and earlier component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a detail action to index.php.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploits
Milw0rm 5178 (site down: refer to www.exploit-db.org 5178) - [Search]
References
BID 27972 - [Search]
CWE CWE-89 - [Search]
SECUNIA 29090 - [Search]
XFDB 40803 - [Search]

Dates
Initial Date Seen [2008-03-04 15:44:00]
Last Date Updated [2008-12-20 01:51:41]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2008-1297 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-1297
Description
SQL injection vulnerability in index.php in the eWriting (com_ewriting) 1.2.1 module for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the cat parameter in a selectcat action.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploits
Milw0rm 5226 (site down: refer to www.exploit-db.org 5226) - [Search]
References
BID 28179 - [Search]
CWE CWE-89 - [Search]
SECUNIA 29292 - [Search]

Dates
Initial Date Seen [2008-03-12 13:44:00]
Last Date Updated [2008-09-05 17:37:22]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2008-1427 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-1427
Description
SQL injection vulnerability in the Joobi Acajoom (com_acajoom) 1.1.5 and 1.2.5 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the mailingid parameter in a mailing view action to index.php.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploits
Milw0rm 5273 (site down: refer to www.exploit-db.org 5273) - [Search]
References
BID 28305 - [Search]
CWE CWE-89 - [Search]
SECUNIA 29429 - [Search]
XFDB 41290 - [Search]

Dates
Initial Date Seen [2008-03-20 14:44:00]
Last Date Updated [2008-09-05 17:37:43]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2008-1459 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-1459
Description
SQL injection vulnerability in the Alberghi (com_alberghi) 2.1.3 and earlier component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a detail action to index.php.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploits
Milw0rm 5278 (site down: refer to www.exploit-db.org 5278) - [Search]
References
BID 28331 - [Search]
CWE CWE-89 - [Search]
SECUNIA 29473 - [Search]
XFDB 41285 - [Search]

Dates
Initial Date Seen [2008-03-24 14:44:00]
Last Date Updated [2008-09-05 00:00:00]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2008-1460 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-1460
Description
SQL injection vulnerability in the Joovideo (com_joovideo) 1.0 and 1.2.2 component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a detail action to index.php.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploits
Milw0rm 5277 (site down: refer to www.exploit-db.org 5277) - [Search]
References
BID 28318 - [Search]
CWE CWE-89 - [Search]
SECUNIA 29474 - [Search]
XFDB 41279 - [Search]

Dates
Initial Date Seen [2008-03-24 14:44:00]
Last Date Updated [2008-09-05 00:00:00]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2008-1465 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-1465
Description
SQL injection vulnerability in the Detodas Restaurante (com_restaurante) 1.0 component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a detail action to index.php, a different product than CVE-2008-0562.

CVSS
(7.6) AV:N/AC:H/Au:N/C:C/I:C/A:C
Exploits
Milw0rm 5280 (site down: refer to www.exploit-db.org 5280) - [Search]
References
BID 28324 - [Search]
CWE CWE-89 - [Search]
SECUNIA 29471 - [Search]
XFDB 41283 - [Search]

Dates
Initial Date Seen [2008-03-24 17:44:00]
Last Date Updated [2011-07-25 00:00:00]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2008-1505 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-1505
Description
PHP remote file inclusion vulnerability in the SSTREAMTV custompages (com_custompages) 1.1 and earlier component for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the cpage parameter to index.php.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploits
Milw0rm 5294 (site down: refer to www.exploit-db.org 5294) - [Search]
References
BID 28409 - [Search]
CWE CWE-94 - [Search]
SECUNIA 29520 - [Search]
XFDB 41396 - [Search]

Dates
Initial Date Seen [2008-03-25 15:44:00]
Last Date Updated [2008-09-05 00:00:00]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2008-1533 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-1533
Description
Unspecified vulnerability in the XML-RPC Blogger API plugin in Joomla! 1.5 allows remote attackers to perform unauthorized article operations on articles via unknown vectors.

CVSS
(5.1) AV:N/AC:H/Au:N/C:P/I:P/A:P
References
BID 27719 - [Search]
SECUNIA 28861 - [Search]
XFDB 41563 - [Search]

Dates
Initial Date Seen [2008-03-27 20:44:00]
Last Date Updated [2008-09-05 00:00:00]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2008-1535 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-1535
Description
SQL injection vulnerability in the Matti Kiviharju rekry (aka com_rekry or rekry!Joom) 1.0.0 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the op_id parameter in a view action to index.php.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploits
Milw0rm 5297 (site down: refer to www.exploit-db.org 5297) - [Search]
References
BID 28422 - [Search]
CWE CWE-20 - [Search]
CWE CWE-89 - [Search]
SECUNIA 29510 - [Search]
XFDB 41385 - [Search]

Dates
Initial Date Seen [2008-03-28 14:44:00]
Last Date Updated [2008-09-05 17:38:00]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2008-1540 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-1540
Description
SQL injection vulnerability in the Datsogallery (com_datsogallery) 1.3.1 module for Joomla! and Mambo allows remote attackers to execute arbitrary SQL commands via the id parameter in a detail action to index.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
References
BID 28361 - [Search]
CWE CWE-89 - [Search]
XFDB 41348 - [Search]

Dates
Initial Date Seen [2008-03-28 14:44:00]
Last Date Updated [2008-09-05 17:38:01]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2008-1559 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-1559
Description
SQL injection vulnerability in the Bernard Gilly AlphaContent (com_alphacontent) 2.5.8 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a view action to index.php.

CVSS
(5.1) AV:N/AC:H/Au:N/C:P/I:P/A:P
Exploits
Milw0rm 5310 (site down: refer to www.exploit-db.org 5310) - [Search]
References
BID 28443 - [Search]
CWE CWE-89 - [Search]
XFDB 41428 - [Search]

Dates
Initial Date Seen [2008-03-31 13:44:00]
Last Date Updated [2011-07-25 00:00:00]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2008-1682 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-1682
Description
PHP remote file inclusion vulnerability in quiz/common/db_config.inc.php in the Online FlashQuiz (com_onlineflashquiz) 1.0.2 component for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the base_dir parameter.

CVSS
(5.1) AV:N/AC:H/Au:N/C:P/I:P/A:P
Exploits
Milw0rm 5345 (site down: refer to www.exploit-db.org 5345) - [Search]
References
BID 28574 - [Search]
CWE CWE-94 - [Search]
XFDB 41592 - [Search]

Dates
Initial Date Seen [2008-04-04 15:44:00]
Last Date Updated [2012-10-30 22:55:21]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2008-1733 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-1733
Description
SQL injection vulnerability in puarcade.class.php 2.2 and earlier in the Pragmatic Utopia PU Arcade (com_puarcade) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the gid parameter to index.php.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
References
BID 28701 - [Search]
CWE CWE-89 - [Search]
OSVDB 44391 - [Search]
XFDB 41726 - [Search]

Dates
Initial Date Seen [2008-04-11 15:05:00]
Last Date Updated [2009-07-29 00:00:00]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2008-1848 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-1848
Description
Cross-site scripting (XSS) vulnerability in the joomlaXplorer (com_joomlaxplorer) Mambo/Joomla! component 1.6.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the error parameter in a show_error action to index.php.

CVSS
(2.6) AV:N/AC:H/Au:N/C:N/I:P/A:N
Exploits
Milw0rm 5431 (site down: refer to www.exploit-db.org 5431) - [Search]
References
BID 28746 - [Search]
CWE CWE-79 - [Search]
XFDB 41779 - [Search]

Dates
Initial Date Seen [2008-04-16 13:05:00]
Last Date Updated [2008-12-19 15:54:14]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2008-1849 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-1849
Description
Directory traversal vulnerability in index.php in the joomlaXplorer (com_joomlaxplorer) Mambo/Joomla! component 1.6.2 and earlier allows remote attackers to list arbitrary directories via a .. (dot dot) in the dir parameter in a show_error action.

CVSS
(5) AV:N/AC:L/Au:N/C:P/I:N/A:N
Exploits
Milw0rm 5431 (site down: refer to www.exploit-db.org 5431) - [Search]
References
BID 28746 - [Search]
CWE CWE-22 - [Search]
XFDB 41778 - [Search]

Dates
Initial Date Seen [2008-04-16 13:05:00]
Last Date Updated [2008-09-05 00:00:00]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2008-1890 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-1890
Description
SQL injection vulnerability in the Jom Comment 2.0 build 345 component for Joomla! allows remote attackers to execute arbitrary SQL commands via unspecified vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
References
BID 28812 - [Search]
CWE CWE-89 - [Search]
SECUNIA 29820 - [Search]
XFDB 41866 - [Search]

Dates
Initial Date Seen [2008-04-18 18:05:00]
Last Date Updated [2008-09-05 00:00:00]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2008-1935 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-1935
Description
SQL injection vulnerability in the Filiale 1.0.4 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the idFiliale parameter.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploits
Milw0rm 5488 (site down: refer to www.exploit-db.org 5488) - [Search]
References
BID 28900 - [Search]
CWE CWE-89 - [Search]
VUPEN ADV-2008-1346 - [Search]
XFDB 41980 - [Search]

Dates
Initial Date Seen [2008-04-25 02:05:00]
Last Date Updated [2011-03-07 22:08:16]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2008-2093 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-2093
Description
SQL injection vulnerability in the Profiler (com_comprofiler) component in Community Builder for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the user parameter in a userProfile action to index.php.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploits
Milw0rm 5491 (site down: refer to www.exploit-db.org 5491) - [Search]
References
BID 28911 - [Search]
CWE CWE-89 - [Search]
XFDB 42008 - [Search]

Dates
Initial Date Seen [2008-05-06 12:20:00]
Last Date Updated [2012-10-29 23:11:08]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2008-2095 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-2095
Description
SQL injection vulnerability in index.php in the FlippingBook (com_flippingbook) 1.0.4 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the book_id parameter.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploits
Milw0rm 5484 (site down: refer to www.exploit-db.org 5484) - [Search]
References
BID 28886 - [Search]
CWE CWE-89 - [Search]
VUPEN ADV-2008-1342 - [Search]
XFDB 41942 - [Search]

Dates
Initial Date Seen [2008-05-06 12:20:00]
Last Date Updated [2011-03-07 22:08:41]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2008-2454 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-2454
Description
SQL injection vulnerability in the xsstream-dm (com_xsstream-dm) component 0.01 Beta for Joomla! allows remote attackers to execute arbitrary SQL commands via the movie parameter to index.php.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploits
Milw0rm 5587 (site down: refer to www.exploit-db.org 5587) - [Search]
References
BID 29144 - [Search]
CWE CWE-89 - [Search]
XFDB 42323 - [Search]

Dates
Initial Date Seen [2008-05-27 10:32:00]
Last Date Updated [2009-04-02 01:34:47]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2008-2564 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-2564
Description
SQL injection vulnerability in the JotLoader (com_jotloader) component 1.2.1.a and earlier for Joomla! allows remote attackers to execute arbitrary SQL commands via the cid parameter to index.php.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploits
Milw0rm 5737 (site down: refer to www.exploit-db.org 5737) - [Search]
References
BID 29554 - [Search]
CWE CWE-89 - [Search]
SECUNIA 30541 - [Search]
XFDB 42840 - [Search]

Dates
Initial Date Seen [2008-06-06 14:32:00]
Last Date Updated [2008-09-10 21:10:51]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2008-2568 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-2568
Description
SQL injection vulnerability in the Simple Shop Galore (com_simpleshop) component 3.4 and earlier for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter in a browse action to index.php.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploits
Milw0rm 5833 (site down: refer to www.exploit-db.org 5833) - [Search]
Milw0rm 5743 (site down: refer to www.exploit-db.org 5743) - [Search]
References
BID 29565 - [Search]
CWE CWE-89 - [Search]
SECUNIA 30461 - [Search]
XFDB 42871 - [Search]

Dates
Initial Date Seen [2008-06-06 14:32:00]
Last Date Updated [2008-09-10 21:10:51]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2008-2569 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-2569
Description
SQL injection vulnerability in the EasyBook (com_easybook) component 1.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the gbid parameter in a deleteentry action to index.php.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploits
Milw0rm 5740 (site down: refer to www.exploit-db.org 5740) - [Search]
References
CWE CWE-89 - [Search]
SECUNIA 30539 - [Search]
XFDB 42853 - [Search]

Dates
Initial Date Seen [2008-06-06 14:32:00]
Last Date Updated [2008-09-10 21:10:51]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2008-2627 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-2627
Description
SQL injection vulnerability in the IDoBlog (com_idoblog) component b24 and earlier and 1.0, a component for Joomla!, allows remote attackers to execute arbitrary SQL commands via the userid parameter in a userblog action to index.php.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploits
Milw0rm 5730 (site down: refer to www.exploit-db.org 5730) - [Search]
References
CWE CWE-89 - [Search]
SECUNIA 30505 - [Search]
XFDB 42819 - [Search]

Dates
Initial Date Seen [2008-06-09 20:32:00]
Last Date Updated [2008-09-05 00:00:00]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2008-2628 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-2628
Description
SQL injection vulnerability in the eQuotes (com_equotes) component 0.9.4 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter to index.php.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploits
Milw0rm 5723 (site down: refer to www.exploit-db.org 5723) - [Search]
References
CWE CWE-89 - [Search]
XFDB 42805 - [Search]

Dates
Initial Date Seen [2008-06-09 20:32:00]
Last Date Updated [2008-09-05 00:00:00]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2008-2630 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-2630
Description
SQL injection vulnerability in the JooBlog (com_jb2) component 0.1.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the CategoryID parameter in a category action to index.php.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploits
Milw0rm 5734 (site down: refer to www.exploit-db.org 5734) - [Search]
References
CWE CWE-89 - [Search]
SECUNIA 30443 - [Search]
VUPEN ADV-2008-1736 - [Search]
XFDB 42838 - [Search]

Dates
Initial Date Seen [2008-06-09 20:32:00]
Last Date Updated [2011-03-07 22:09:31]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2008-2632 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-2632
Description
SQL injection vulnerability in the acctexp (com_acctexp) component 0.12.x and earlier for Joomla! allows remote attackers to execute arbitrary SQL commands via the usage parameter in a subscribe action to index.php.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploits
Milw0rm 5721 (site down: refer to www.exploit-db.org 5721) - [Search]
References
CWE CWE-89 - [Search]
XFDB 42794 - [Search]

Dates
Initial Date Seen [2008-06-09 20:32:00]
Last Date Updated [2008-09-05 17:40:48]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2008-2633 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-2633
Description
Multiple SQL injection vulnerabilities in the EXP JoomRadio (com_joomradio) component 1.0 for Joomla! allow remote attackers to execute arbitrary SQL commands via the id parameter in a (1) show_radio or (2) show_video action to index.php.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploits
Milw0rm 5729 (site down: refer to www.exploit-db.org 5729) - [Search]
References
BID 29504 - [Search]
CWE CWE-89 - [Search]
SECUNIA 30513 - [Search]
XFDB 42814 - [Search]

Dates
Initial Date Seen [2008-06-09 20:32:00]
Last Date Updated [2009-03-13 01:37:11]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2008-2643 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-2643
Description
SQL injection vulnerability in the Bible Study (com_biblestudy) component before 6.0.7c for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a mediaplayer action to index.php.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploits
Milw0rm 5710 (site down: refer to www.exploit-db.org 5710) - [Search]
References
CWE CWE-89 - [Search]
SECUNIA 30492 - [Search]
XFDB 42788 - [Search]

Dates
Initial Date Seen [2008-06-10 14:32:00]
Last Date Updated [2008-09-05 17:40:50]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2008-2676 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-2676
Description
SQL injection vulnerability in the iJoomla News Portal (com_news_portal) component 1.0 and earlier for Joomla! allows remote attackers to execute arbitrary SQL commands via the Itemid parameter to index.php.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploits
Milw0rm 5761 (site down: refer to www.exploit-db.org 5761) - [Search]
References
CWE CWE-89 - [Search]
XFDB 42936 - [Search]

Dates
Initial Date Seen [2008-06-12 08:21:00]
Last Date Updated [2008-09-05 00:00:00]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2008-2692 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-2692
Description
SQL injection vulnerability in the yvComment (com_yvcomment) component 1.16.0 and earlier for Joomla! allows remote attackers to execute arbitrary SQL commands via the ArticleID parameter in a comment action to index.php.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploits
Milw0rm 5755 (site down: refer to www.exploit-db.org 5755) - [Search]
References
BID 29596 - [Search]
CWE CWE-89 - [Search]
SECUNIA 30567 - [Search]
XFDB 42920 - [Search]

Dates
Initial Date Seen [2008-06-13 15:41:00]
Last Date Updated [2009-04-14 01:32:27]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2008-2697 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-2697
Description
SQL injection vulnerability in the Rapid Recipe (com_rapidrecipe) component 1.6.6 and 1.6.7 for Joomla! allows remote attackers to execute arbitrary SQL commands via the recipe_id parameter in a viewrecipe action to index.php.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploits
Milw0rm 5759 (site down: refer to www.exploit-db.org 5759) - [Search]
References
BID 29593 - [Search]
CWE CWE-89 - [Search]
SECUNIA 30566 - [Search]
XFDB 42924 - [Search]

Dates
Initial Date Seen [2008-06-13 15:41:00]
Last Date Updated [2009-04-14 01:32:28]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2008-2701 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-2701
Description
SQL injection vulnerability in the GameQ (com_gameq) component 4.0 and earlier for Joomla! allows remote attackers to execute arbitrary SQL commands via the category_id parameter in a page action to index.php.

CVSS
(5.1) AV:N/AC:H/Au:N/C:P/I:P/A:P
Exploits
Milw0rm 5752 (site down: refer to www.exploit-db.org 5752) - [Search]
References
BID 29592 - [Search]
BID 32633 - [Search]
CWE CWE-89 - [Search]
SECUNIA 30570 - [Search]
XFDB 42929 - [Search]

Dates
Initial Date Seen [2008-06-13 15:41:00]
Last Date Updated [2009-04-08 01:26:46]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2008-2892 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-2892
Description
SQL injection vulnerability in the EXP Shop (com_expshop) component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter in a show_payment action to index.php.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploits
Milw0rm 5893 (site down: refer to www.exploit-db.org 5893) - [Search]
References
BID 29869 - [Search]
CWE CWE-89 - [Search]
SECUNIA 30791 - [Search]
XFDB 43246 - [Search]

Dates
Initial Date Seen [2008-06-27 14:41:00]
Last Date Updated [2009-04-08 01:27:11]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2008-2990 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-2990
Description
PHP remote file inclusion vulnerability in facileforms.frame.php in the FacileForms (com_facileforms) component 1.4.4 for Mambo and Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the ff_compath parameter.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploits
Milw0rm 5915 (site down: refer to www.exploit-db.org 5915) - [Search]
References
BID 29904 - [Search]
CWE CWE-94 - [Search]
XFDB 43290 - [Search]

Dates
Initial Date Seen [2008-07-02 13:14:00]
Last Date Updated [2009-01-29 01:51:55]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2008-3083 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-3083
Description
SQL injection vulnerability in Brightcode Weblinks (com_brightweblinks) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploits
Milw0rm 5993 (site down: refer to www.exploit-db.org 5993) - [Search]
References
BID 30060 - [Search]
CWE CWE-89 - [Search]
SECUNIA 30922 - [Search]
XFDB 43535 - [Search]

Dates
Initial Date Seen [2008-07-08 20:41:00]
Last Date Updated [2008-09-10 21:11:52]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2008-3132 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-3132
Description
SQL injection vulnerability in the beamospetition (com_beamospetition) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the pet parameter to index.php.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploits
Milw0rm 5965 (site down: refer to www.exploit-db.org 5965) - [Search]
References
BID 30005 - [Search]
CWE CWE-89 - [Search]
VUPEN ADV-2008-1975 - [Search]
XFDB 43466 - [Search]

Dates
Initial Date Seen [2008-07-10 19:41:00]
Last Date Updated [2011-03-07 22:10:15]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2008-3225 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-3225
Description
Joomla! before 1.5.4 allows attackers to access administration functionality, which has unknown impact and attack vectors related to a missing "LDAP security fix."

CVSS
(10) AV:N/AC:L/Au:N/C:C/I:C/A:C
References
BID 30125 - [Search]
CWE CWE-264 - [Search]
XFDB 43648 - [Search]

Dates
Initial Date Seen [2008-07-18 12:41:00]
Last Date Updated [2009-06-09 01:25:10]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2008-3226 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-3226
Description
The file caching implementation in Joomla! before 1.5.4 allows attackers to access cached pages via unknown attack vectors.

CVSS
(5) AV:N/AC:L/Au:N/C:P/I:N/A:N
References
BID 30125 - [Search]
CWE CWE-264 - [Search]
XFDB 43650 - [Search]

Dates
Initial Date Seen [2008-07-18 12:41:00]
Last Date Updated [2009-06-09 01:25:10]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2008-3227 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-3227
Description
Unspecified vulnerability in Joomla! before 1.5.4 has unknown impact and attack vectors related to a "User Redirect Spam fix," possibly an open redirect vulnerability.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
References
CWE CWE-59 - [Search]
XFDB 44205 - [Search]

Dates
Initial Date Seen [2008-07-18 12:41:00]
Last Date Updated [2008-09-10 21:12:10]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2008-3228 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-3228
Description
Joomla! before 1.5.4 does not configure .htaccess to apply certain security checks that "block common exploits" to SEF URLs, which has unknown impact and remote attack vectors.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
References
CWE CWE-16 - [Search]
XFDB 44206 - [Search]

Dates
Initial Date Seen [2008-07-18 12:41:00]
Last Date Updated [2008-09-10 21:12:10]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2008-3265 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-3265
Description
SQL injection vulnerability in the DT Register (com_dtregister) 2.2.3 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the eventId parameter in a pay_options action to index.php.

CVSS
(5.1) AV:N/AC:H/Au:N/C:P/I:P/A:P
Exploits
Milw0rm 6086 (site down: refer to www.exploit-db.org 6086) - [Search]
References
BID 30256 - [Search]
CWE CWE-89 - [Search]
OSVDB 47061 - [Search]
SECUNIA 31126 - [Search]
XFDB 43851 - [Search]

Dates
Initial Date Seen [2008-07-24 11:41:00]
Last Date Updated [2009-08-19 01:17:16]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2008-3498 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-3498
Description
SQL injection vulnerability in the nBill (com_netinvoice) component 1.2.0 SP1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the cid parameter in an orders action to index.php. NOTE: some of these details are obtained from third party information.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploits
Milw0rm 5939 (site down: refer to www.exploit-db.org 5939) - [Search]
References
BID 29951 - [Search]
CWE CWE-89 - [Search]
SECUNIA 30752 - [Search]
VUPEN ADV-2008-1948 - [Search]
XFDB 43369 - [Search]

Dates
Initial Date Seen [2008-08-06 14:41:00]
Last Date Updated [2013-01-24 00:00:00]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2008-3586 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-3586
Description
SQL injection vulnerability in the EZ Store (com_ezstore) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a detail action to index.php.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploits
Milw0rm 6199 (site down: refer to www.exploit-db.org 6199) - [Search]
References
BID 30527 - [Search]
CWE CWE-89 - [Search]
XFDB 44196 - [Search]

Dates
Initial Date Seen [2008-08-11 19:41:00]
Last Date Updated [2009-03-18 01:40:47]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2008-3681 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-3681
Description
components/com_user/models/reset.php in Joomla! 1.5 through 1.5.5 does not properly validate reset tokens, which allows remote attackers to reset the "first enabled user (lowest id)" password, typically for the administrator.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploits
Milw0rm 6234 (site down: refer to www.exploit-db.org 6234) - [Search]
References
BID 30667 - [Search]
CWE CWE-264 - [Search]
SECUNIA 31457 - [Search]
XFDB 44430 - [Search]

Dates
Initial Date Seen [2008-08-14 15:41:00]
Last Date Updated [2009-02-06 01:58:00]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2008-4102 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-4102
Description
Joomla! 1.5 before 1.5.7 initializes PHP's PRNG with a weak seed, which makes it easier for attackers to guess the pseudo-random values produced by PHP's mt_rand function, as demonstrated by guessing password reset tokens, a different vulnerability than CVE-2008-3681.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
References
CWE CWE-189 - [Search]
SECUNIA 31789 - [Search]
XFDB 45068 - [Search]

Dates
Initial Date Seen [2008-09-18 13:59:32]
Last Date Updated [2009-08-19 01:19:23]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2008-4103 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-4103
Description
The mailto (aka com_mailto) component in Joomla! 1.5 before 1.5.7 sends e-mail messages without validating the URL, which allows remote attackers to transmit spam.

CVSS
(5) AV:N/AC:L/Au:N/C:P/I:N/A:N
References
CWE CWE-20 - [Search]
SECUNIA 31789 - [Search]
XFDB 45070 - [Search]

Dates
Initial Date Seen [2008-09-18 13:59:32]
Last Date Updated [2009-08-19 01:19:23]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2008-4104 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-4104
Description
Multiple open redirect vulnerabilities in Joomla! 1.5 before 1.5.7 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a "passed in" URL.

CVSS
(4) AV:N/AC:H/Au:N/C:N/I:P/A:P
References
CWE CWE-59 - [Search]
XFDB 45071 - [Search]

Dates
Initial Date Seen [2008-09-18 13:59:32]
Last Date Updated [2009-08-19 01:19:23]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2008-4105 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-4105
Description
JRequest in Joomla! 1.5 before 1.5.7 does not sanitize variables that were set with JRequest::setVar, which allows remote attackers to conduct "variable injection" attacks and have unspecified other impact.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
References
CWE CWE-20 - [Search]
SECUNIA 31789 - [Search]
XFDB 45069 - [Search]

Dates
Initial Date Seen [2008-09-18 13:59:32]
Last Date Updated [2009-08-19 01:19:23]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2008-4107 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-4107
Description
The (1) rand and (2) mt_rand functions in PHP 5.2.6 do not produce cryptographically strong random numbers, which allows attackers to leverage exposures in products that rely on these functions for security-relevant functionality, as demonstrated by the password-reset functionality in Joomla! 1.5.x and WordPress before 2.6.2, a different vulnerability than CVE-2008-2107, CVE-2008-2108, and CVE-2008-4102.

CVSS
(6.8) AV:N/AC:M/Au:N/C:P/I:P/A:P
References
BID 31115 - [Search]
CWE CWE-189 - [Search]
OSVDB 48700 - [Search]
SECUNIA 31737 - [Search]
SECUNIA 31870 - [Search]
VUPEN ADV-2008-2553 - [Search]
XFDB 45956 - [Search]

Dates
Initial Date Seen [2008-09-18 13:59:33]
Last Date Updated [2012-10-29 23:16:38]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2008-4122 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-4122
Description
Joomla! 1.5.8 does not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.

CVSS
(5) AV:N/AC:L/Au:N/C:P/I:N/A:N
References
CVE-2008-4122 - [Search]
CWE CWE-310 - [Search]

Dates
Initial Date Seen [2008-12-19 12:30:02]
Last Date Updated [2009-01-29 01:55:33]

Copyright
© 2012 The MITRE Corporation

NESSUS 59583 match rank: 100%

Source
http://www.nessus.org/plugins/index.php?view=single&id=59583
Title
FreeBSD : joomla -- Privilege Escalation (f46c4c6a-ba25-11e1-806a-001143cd36d8)
Description
The remote FreeBSD host is missing a security-related update.

References
CPE cpe:/o:freebsd:freebsd - [Search]
Tools
NESSUS 59583 - [Search]

Dates
Initial Date Seen [2012-06-20 00:00:00]
Last Date Updated [2012-06-20 00:00:00]

Copyright
© 2012 Tenable Network Security@

NVD CVE-2008-4617 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-4617
Description
SQL injection vulnerability in the actualite module 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploits
Milw0rm 5337 (site down: refer to www.exploit-db.org 5337) - [Search]
References
BID 28565 - [Search]
CWE CWE-89 - [Search]
XFDB 41579 - [Search]

Dates
Initial Date Seen [2008-10-20 16:00:00]
Last Date Updated [2009-01-29 01:56:56]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2008-4623 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-4623
Description
SQL injection vulnerability in the DS-Syndicate (com_ds-syndicate) component 1.1.1 for Joomla allows remote attackers to execute arbitrary SQL commands via the feed_id parameter to index2.php.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploits
Milw0rm 6792 (site down: refer to www.exploit-db.org 6792) - [Search]
References
BID 31819 - [Search]
CWE CWE-89 - [Search]
SECUNIA 32321 - [Search]
VUPEN ADV-2008-2859 - [Search]
XFDB 45979 - [Search]

Dates
Initial Date Seen [2008-10-20 21:18:02]
Last Date Updated [2011-08-05 00:00:00]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2008-4668 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-4668
Description
Directory traversal vulnerability in the Image Browser (com_imagebrowser) 0.1.5 component for Joomla! allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the folder parameter to index.php.

CVSS
(9) AV:N/AC:L/Au:N/C:C/I:P/A:P
Exploits
Milw0rm 6618 (site down: refer to www.exploit-db.org 6618) - [Search]
References
BID 31458 - [Search]
CWE CWE-22 - [Search]
XFDB 45490 - [Search]

Dates
Initial Date Seen [2008-10-22 06:30:01]
Last Date Updated [2009-01-29 01:57:08]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2008-4715 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-4715
Description
SQL injection vulnerability in the Jpad (com_jpad) 1.0 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the cid parameter to index.php.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploits
Milw0rm 5493 (site down: refer to www.exploit-db.org 5493) - [Search]
References
BID 28923 - [Search]
CWE CWE-89 - [Search]
XFDB 41983 - [Search]

Dates
Initial Date Seen [2008-10-23 13:17:14]
Last Date Updated [2011-01-20 00:00:00]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2008-4764 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-4764
Description
Directory traversal vulnerability in the eXtplorer module (com_extplorer) 2.0.0 RC2 and earlier in Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the dir parameter in a show_error action.

CVSS
(5) AV:N/AC:L/Au:N/C:P/I:N/A:N
Exploits
Milw0rm 5435 (site down: refer to www.exploit-db.org 5435) - [Search]
References
BID 28764 - [Search]
CWE CWE-22 - [Search]
XFDB 41873 - [Search]

Dates
Initial Date Seen [2008-10-27 22:03:38]
Last Date Updated [2012-07-13 00:00:00]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2008-4777 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-4777
Description
SQL injection vulnerability in the Showroom Joomlearn LMS (com_lms) component for Joomla! and Mambo allows remote attackers to execute arbitrary SQL commands via the cat parameter in a showTests task.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
References
BID 28586 - [Search]
CWE CWE-89 - [Search]
XFDB 41614 - [Search]

Dates
Initial Date Seen [2008-10-29 10:22:38]
Last Date Updated [2009-03-18 01:44:13]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2008-5051 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-5051
Description
SQL injection vulnerability in the JooBlog (com_jb2) component 0.1.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the PostID parameter to index.php.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploits
Milw0rm 7078 (site down: refer to www.exploit-db.org 7078) - [Search]
References
BID 32236 - [Search]
CWE CWE-89 - [Search]
VUPEN ADV-2008-3094 - [Search]

Dates
Initial Date Seen [2008-11-12 21:30:01]
Last Date Updated [2011-03-07 22:13:47]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2008-5053 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-5053
Description
PHP remote file inclusion vulnerability in admin.rssreader.php in the Simple RSS Reader (com_rssreader) 1.0 component for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_live_site parameter.

CVSS
(10) AV:N/AC:L/Au:N/C:C/I:C/A:C
Exploits
Milw0rm 7096 (site down: refer to www.exploit-db.org 7096) - [Search]
www.exploit-db.org 7096 - [Search]
References
BID 32265 - [Search]
CWE CWE-94 - [Search]
OSVDB 49859 - [Search]
VUPEN ADV-2008-3119 - [Search]
XFDB 46559 - [Search]

Dates
Initial Date Seen [2008-11-13 06:30:01]
Last Date Updated [2012-11-05 23:11:21]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2008-5200 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-5200
Description
SQL injection vulnerability in the Xe webtv (com_xewebtv) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a detail action to index.php.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploits
Milw0rm 5966 (site down: refer to www.exploit-db.org 5966) - [Search]
References
BID 30006 - [Search]
CWE CWE-89 - [Search]
VUPEN ADV-2008-1974 - [Search]
XFDB 43469 - [Search]

Dates
Initial Date Seen [2008-11-21 12:30:00]
Last Date Updated [2011-03-07 22:14:09]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2008-5208 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-5208
Description
SQL injection vulnerability in sub_votepic.php in the Datsogallery (com_datsogallery) module 1.6 for Joomla! allows remote attackers to execute arbitrary SQL commands via the User-Agent HTTP header.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploits
Milw0rm 5583 (site down: refer to www.exploit-db.org 5583) - [Search]
References
BID 29138 - [Search]
CWE CWE-89 - [Search]
SECUNIA 30139 - [Search]
XFDB 42324 - [Search]

Dates
Initial Date Seen [2008-11-24 12:30:00]
Last Date Updated [2009-04-01 01:38:50]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2008-5494 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-5494
Description
SQL injection vulnerability in the Contact Information Module (com_contactinfo) component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter to index.php.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploits
Milw0rm 7093 (site down: refer to www.exploit-db.org 7093) - [Search]
References
BID 32260 - [Search]
CWE CWE-89 - [Search]
VUPEN ADV-2008-3122 - [Search]
XFDB 46563 - [Search]

Dates
Initial Date Seen [2008-12-12 11:30:00]
Last Date Updated [2011-03-07 22:14:39]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2008-5607 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-5607
Description
SQL injection vulnerability in the JMovies (aka JM or com_jmovies) component 1.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter to index.php.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploits
Milw0rm 7331 (site down: refer to www.exploit-db.org 7331) - [Search]
References
BID 32615 - [Search]
CWE CWE-89 - [Search]

Dates
Initial Date Seen [2008-12-16 14:07:32]
Last Date Updated [2009-01-29 01:59:39]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2008-5643 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-5643
Description
SQL injection vulnerability in the Books (com_books) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the book_id parameter in a book_details action to index.php.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploits
Milw0rm 7092 (site down: refer to www.exploit-db.org 7092) - [Search]
References
BID 32255 - [Search]
CWE CWE-89 - [Search]
XFDB 46561 - [Search]

Dates
Initial Date Seen [2008-12-17 13:30:00]
Last Date Updated [2009-01-29 01:59:45]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2008-5671 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-5671
Description
PHP remote file inclusion vulnerability in index.php in Joomla! 1.0.11 through 1.0.14, when RG_EMULATION is enabled in configuration.php, allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
References
BID 27795 - [Search]
CWE CWE-94 - [Search]
SECUNIA 29106 - [Search]

Dates
Initial Date Seen [2008-12-18 20:52:02]
Last Date Updated [2009-08-19 01:22:14]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2008-5789 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-5789
Description
Multiple PHP remote file inclusion vulnerabilities in the Recly Interactive Feederator (com_feederator) component 1.0.5 for Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the (1) mosConfig_absolute_path parameter to (a) add_tmsp.php, (b) edit_tmsp.php and (c) tmsp.php in includes/tmsp/; and the (2) GLOBALS[mosConfig_absolute_path] parameter to (d) includes/tmsp/subscription.php.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploits
Milw0rm 7040 (site down: refer to www.exploit-db.org 7040) - [Search]
References
BID 32194 - [Search]
CWE CWE-94 - [Search]
XFDB 46438 - [Search]

Dates
Initial Date Seen [2008-12-31 06:30:00]
Last Date Updated [2009-01-29 02:00:15]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2008-5790 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-5790
Description
Multiple PHP remote file inclusion vulnerabilities in the Recly!Competitions (com_competitions) component 1.0 for Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the (1) GLOBALS[mosConfig_absolute_path] parameter to (a) add.php and (b) competitions.php in includes/competitions/, and the (2) mosConfig_absolute_path parameter to (c) includes/settings/settings.php.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploits
Milw0rm 7039 (site down: refer to www.exploit-db.org 7039) - [Search]
References
BID 32192 - [Search]
CWE CWE-94 - [Search]

Dates
Initial Date Seen [2008-12-31 06:30:00]
Last Date Updated [2009-01-02 00:00:00]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2008-5793 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-5793
Description
Multiple PHP remote file inclusion vulnerabilities in the Clickheat - Heatmap stats (com_clickheat) component 1.0.1 for Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the (1) GLOBALS[mosConfig_absolute_path] parameter to (a) install.clickheat.php, (b) Cache.php and (c) Clickheat_Heatmap.php in Recly/Clickheat/, and (d) Recly/common/GlobalVariables.php; and the (2) mosConfig_absolute_path parameter to (e) _main.php and (f) main.php in includes/heatmap, and (g) includes/overview/main.php.

CVSS
(5.1) AV:N/AC:H/Au:N/C:P/I:P/A:P
Exploits
Milw0rm 7038 (site down: refer to www.exploit-db.org 7038) - [Search]
References
BID 32190 - [Search]
CWE CWE-94 - [Search]
XFDB 46439 - [Search]

Dates
Initial Date Seen [2008-12-31 06:30:00]
Last Date Updated [2009-01-29 02:00:16]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2008-5811 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-5811
Description
SQL injection vulnerability in the PaxGallery (com_paxgallery) component 0.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the gid parameter in a table action to index.php.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploits
Milw0rm 7587 (site down: refer to www.exploit-db.org 7587) - [Search]
References
BID 33035 - [Search]
CWE CWE-89 - [Search]
OSVDB 51009 - [Search]
SECUNIA 33352 - [Search]

Dates
Initial Date Seen [2009-01-02 13:11:09]
Last Date Updated [2009-02-26 02:05:04]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2008-5864 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-5864
Description
SQL injection vulnerability in the Top Hotel (com_tophotelmodule) component 1.0 in the Hotel Booking Reservation System (aka HBS) 1.0.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a showhoteldetails action to index.php.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploits
Milw0rm 7539 (site down: refer to www.exploit-db.org 7539) - [Search]
References
BID 32952 - [Search]
CWE CWE-89 - [Search]
XFDB 47540 - [Search]

Dates
Initial Date Seen [2009-01-06 12:30:00]
Last Date Updated [2009-08-20 01:24:14]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2008-5865 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-5865
Description
SQL injection vulnerability in the com_hbssearch component 1.0 in the Hotel Booking Reservation System (aka HBS) 1.0.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the r_type parameter in a showhoteldetails action to index.php.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploits
Milw0rm 7538 (site down: refer to www.exploit-db.org 7538) - [Search]
References
BID 32951 - [Search]
CWE CWE-89 - [Search]
SECUNIA 33215 - [Search]
XFDB 47539 - [Search]

Dates
Initial Date Seen [2009-01-06 12:30:00]
Last Date Updated [2009-08-19 01:22:37]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2008-5874 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-5874
Description
Multiple SQL injection vulnerabilities in the Hotel Booking Reservation System (aka HBS) for Joomla! allow remote attackers to execute arbitrary SQL commands via the id parameter in a showhoteldetails action to index.php in the (1) com_allhotels or (2) com_5starhotels module. NOTE: some of these details are obtained from third party information.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploits
Milw0rm 7575 (site down: refer to www.exploit-db.org 7575) - [Search]
Milw0rm 7568 (site down: refer to www.exploit-db.org 7568) - [Search]
References
BID 32952 - [Search]
CWE CWE-89 - [Search]

Dates
Initial Date Seen [2009-01-08 14:30:11]
Last Date Updated [2009-07-10 01:28:30]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2008-5875 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-5875
Description
SQL injection vulnerability in the com_lowcosthotels component in the Hotel Booking Reservation System (aka HBS) for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a showhoteldetails action to index.php.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploits
Milw0rm 7567 (site down: refer to www.exploit-db.org 7567) - [Search]
References
BID 32952 - [Search]
CWE CWE-89 - [Search]

Dates
Initial Date Seen [2009-01-08 14:30:11]
Last Date Updated [2009-07-10 01:28:30]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2008-5957 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-5957
Description
SQL injection vulnerability in the Mydyngallery (com_mydyngallery) component 1.4.2 for Joomla! allows remote attackers to execute arbitrary SQL commands via the directory parameter to index.php.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploits
Milw0rm 7343 (site down: refer to www.exploit-db.org 7343) - [Search]
References
BID 32639 - [Search]
CWE CWE-89 - [Search]
XFDB 47087 - [Search]

Dates
Initial Date Seen [2009-01-23 14:00:05]
Last Date Updated [2009-05-14 01:32:55]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2008-6050 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-6050
Description
SQL injection vulnerability in the Tech Articles (com_tech_article) 1.0 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the item parameter to index.php.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploits
Milw0rm 7504 (site down: refer to www.exploit-db.org 7504) - [Search]
References
BID 32897 - [Search]
CWE CWE-89 - [Search]

Dates
Initial Date Seen [2009-02-04 00:00:00]
Last Date Updated [2009-02-04 10:30:02]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2008-6068 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-6068
Description
SQL injection vulnerability in the JoomlaDate (com_joomladate) component 1.2 for Joomla! allows remote attackers to execute arbitrary SQL commands via the user parameter in a viewProfile action to index.php.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploits
Milw0rm 5748 (site down: refer to www.exploit-db.org 5748) - [Search]
References
CWE CWE-89 - [Search]
SECUNIA 30441 - [Search]
XFDB 42873 - [Search]

Dates
Initial Date Seen [2009-02-10 01:59:34]
Last Date Updated [2009-04-14 01:40:02]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2008-6076 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-6076
Description
SQL injection vulnerability in the Daily Message (com_dailymessage) 1.0.3 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter to index.php.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploits
Milw0rm 6802 (site down: refer to www.exploit-db.org 6802) - [Search]
References
BID 31870 - [Search]
CWE CWE-89 - [Search]
XFDB 46033 - [Search]

Dates
Initial Date Seen [2009-02-06 00:00:00]
Last Date Updated [2009-02-06 06:30:00]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2008-6080 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-6080
Description
Directory traversal vulnerability in download.php in the ionFiles (com_ionfiles) 4.4.2 component for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter.

CVSS
(5) AV:N/AC:L/Au:N/C:P/I:N/A:N
Exploits
Milw0rm 6809 (site down: refer to www.exploit-db.org 6809) - [Search]
References
BID 31877 - [Search]
CWE CWE-22 - [Search]
SECUNIA 32377 - [Search]
XFDB 46039 - [Search]

Dates
Initial Date Seen [2009-02-06 00:00:00]
Last Date Updated [2009-02-06 06:30:00]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2008-6088 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-6088
Description
SQL injection vulnerability in the Joomtracker (com_joomtracker) 1.01 module for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a tordetails action to index.php.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploits
Milw0rm 6709 (site down: refer to www.exploit-db.org 6709) - [Search]
References
BID 31676 - [Search]
CWE CWE-89 - [Search]
XFDB 45798 - [Search]

Dates
Initial Date Seen [2009-02-06 14:30:00]
Last Date Updated [2009-08-19 01:23:05]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2008-6116 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-6116
Description
SQL injection vulnerability in the EXtrovert Software Thyme (com_thyme) 1.0 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the event parameter to index.php.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploits
Milw0rm 7182 (site down: refer to www.exploit-db.org 7182) - [Search]
References
BID 32417 - [Search]
CWE CWE-89 - [Search]
XFDB 46777 - [Search]

Dates
Initial Date Seen [2009-02-11 12:30:00]
Last Date Updated [2009-02-12 00:00:00]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2008-6148 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-6148
Description
SQL injection vulnerability in the Live Ticker (com_liveticker) module 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the tid parameter in a viewticker action to index.php.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploits
Milw0rm 7573 (site down: refer to www.exploit-db.org 7573) - [Search]
References
BID 33010 - [Search]
CWE CWE-89 - [Search]
SECUNIA 33312 - [Search]
XFDB 47605 - [Search]

Dates
Initial Date Seen [2009-02-16 00:00:00]
Last Date Updated [2009-02-16 12:30:04]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2008-6149 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-6149
Description
SQL injection vulnerability in the mDigg (com_mdigg) component 2.2.8 for Joomla! allows remote attackers to execute arbitrary SQL commands via the cagtegory parameter in a story_lists action to index.php.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploits
Milw0rm 7574 (site down: refer to www.exploit-db.org 7574) - [Search]
References
BID 33009 - [Search]
CWE CWE-89 - [Search]
OSVDB 51005 - [Search]
SECUNIA 33306 - [Search]
XFDB 47612 - [Search]

Dates
Initial Date Seen [2009-02-16 00:00:00]
Last Date Updated [2009-02-16 12:30:04]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2008-6166 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-6166
Description
SQL injection vulnerability in the KBase (com_kbase) 1.2 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in an article action to index.php.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploits
Milw0rm 6827 (site down: refer to www.exploit-db.org 6827) - [Search]
References
BID 31902 - [Search]
CWE CWE-89 - [Search]
SECUNIA 32365 - [Search]
XFDB 46076 - [Search]

Dates
Initial Date Seen [2009-02-18 19:30:00]
Last Date Updated [2009-04-30 01:32:19]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2008-6172 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-6172
Description
Directory traversal vulnerability in captcha/captcha_image.php in the RWCards (com_rwcards) 3.0.11 component for Joomla!, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the img parameter.

CVSS
(5.1) AV:N/AC:H/Au:N/C:P/I:P/A:P
Exploits
Milw0rm 6817 (site down: refer to www.exploit-db.org 6817) - [Search]
References
BID 31892 - [Search]
CWE CWE-22 - [Search]
SECUNIA 32367 - [Search]
XFDB 46081 - [Search]

Dates
Initial Date Seen [2009-02-19 11:30:00]
Last Date Updated [2009-04-30 01:32:20]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2008-6181 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-6181
Description
SQL injection vulnerability in the Mad4Joomla Mailforms (com_mad4joomla) component before 1.1.8.2 for Joomla! allows remote attackers to execute arbitrary SQL commands via the jid parameter to index.php.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploits
Milw0rm 6724 (site down: refer to www.exploit-db.org 6724) - [Search]
References
BID 31712 - [Search]
CWE CWE-89 - [Search]
SECUNIA 32239 - [Search]
XFDB 45815 - [Search]

Dates
Initial Date Seen [2009-02-19 13:30:00]
Last Date Updated [2009-02-20 00:00:00]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2008-6182 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-6182
Description
SQL injection vulnerability in the Ignite Gallery (com_ignitegallery) component 0.8.0 through 0.8.3 for Joomla! allows remote attackers to execute arbitrary SQL commands via the gallery parameter in a view action to index.php.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploits
Milw0rm 6723 (site down: refer to www.exploit-db.org 6723) - [Search]
References
BID 31714 - [Search]
CWE CWE-89 - [Search]
SECUNIA 32240 - [Search]
XFDB 45816 - [Search]

Dates
Initial Date Seen [2009-02-19 13:30:00]
Last Date Updated [2011-01-20 00:00:00]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2008-6184 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-6184
Description
SQL injection vulnerability in the OwnBiblio (com_ownbiblio) component 1.5.3 for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter in a catalogue action to index.php.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploits
Milw0rm 6730 (site down: refer to www.exploit-db.org 6730) - [Search]
References
BID 31725 - [Search]
CWE CWE-89 - [Search]
SECUNIA 32235 - [Search]
XFDB 45814 - [Search]

Dates
Initial Date Seen [2009-02-19 13:30:00]
Last Date Updated [2009-02-24 00:00:00]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2008-6221 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-6221
Description
PHP remote file inclusion vulnerability in config.dadamail.php in the Dada Mail Manager (com_dadamail) component 2.6 for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[mosConfig_absolute_path] parameter.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploits
Milw0rm 7002 (site down: refer to www.exploit-db.org 7002) - [Search]
References
BID 32135 - [Search]
CWE CWE-94 - [Search]
SECUNIA 32551 - [Search]
VUPEN ADV-2008-3021 - [Search]
XFDB 46378 - [Search]

Dates
Initial Date Seen [2009-02-20 16:30:01]
Last Date Updated [2011-03-07 22:15:55]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2008-6222 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-6222
Description
Directory traversal vulnerability in the Pro Desk Support Center (com_pro_desk) component 1.0 and 1.2 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the include_file parameter to index.php.

CVSS
(5) AV:N/AC:L/Au:N/C:P/I:N/A:N
Exploits
Milw0rm 6980 (site down: refer to www.exploit-db.org 6980) - [Search]
References
BID 32113 - [Search]
CWE CWE-22 - [Search]
SECUNIA 32523 - [Search]
XFDB 46356 - [Search]

Dates
Initial Date Seen [2009-02-20 16:30:01]
Last Date Updated [2009-02-23 00:00:00]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2008-6234 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-6234
Description
SQL injection vulnerability in the com_musica module in Joomla! and Mambo allows remote attackers to execute arbitrary SQL commands via the id parameter to index.php.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploits
Milw0rm 5207 (site down: refer to www.exploit-db.org 5207) - [Search]
References
BID 28061 - [Search]
CWE CWE-89 - [Search]

Dates
Initial Date Seen [2009-02-20 20:30:00]
Last Date Updated [2009-02-24 00:00:00]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2008-6299 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-6299
Description
Multiple cross-site scripting (XSS) vulnerabilities in Joomla! 1.5.7 and earlier allow remote authenticated users with certain privileges to inject arbitrary web script or HTML via (1) the title and description parameters to the com_weblinks module and (2) unspecified vectors in the com_content module related to "article submission."

CVSS
(2.1) AV:N/AC:H/Au:S/C:N/I:P/A:N
References
BID 32263 - [Search]
CWE CWE-79 - [Search]
SECUNIA 32622 - [Search]
VUPEN ADV-2008-3104 - [Search]
XFDB 46523 - [Search]

Dates
Initial Date Seen [2009-02-26 11:17:19]
Last Date Updated [2009-08-13 01:29:44]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2008-6337 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-6337
Description
SQL injection vulnerability in the Volunteer Management System (com_volunteer) module 2.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the job_id parameter in a jobshow action to index.php.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploits
Milw0rm 7546 (site down: refer to www.exploit-db.org 7546) - [Search]
References
BID 32973 - [Search]
CWE CWE-89 - [Search]
SECUNIA 33271 - [Search]

Dates
Initial Date Seen [2009-02-27 12:30:09]
Last Date Updated [2009-03-02 00:00:00]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2008-6347 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-6347
Description
PHP remote file inclusion vulnerability in lib/onguma.class.php in the Onguma Time Sheet (com_ongumatimesheet20) 2.0 4b component for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploits
Milw0rm 6976 (site down: refer to www.exploit-db.org 6976) - [Search]
References
BID 32095 - [Search]
CWE CWE-94 - [Search]

Dates
Initial Date Seen [2009-03-02 00:00:00]
Last Date Updated [2009-03-02 11:30:00]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2008-6429 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-6429
Description
SQL injection vulnerability in the PrayerCenter (com_prayercenter) component 1.4.9 and earlier for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a view_request action to index2.php.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploits
Milw0rm 5708 (site down: refer to www.exploit-db.org 5708) - [Search]
References
CWE CWE-89 - [Search]
OSVDB 45856 - [Search]
SECUNIA 30493 - [Search]
XFDB 42772 - [Search]

Dates
Initial Date Seen [2009-03-06 13:30:00]
Last Date Updated [2009-04-02 01:43:28]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2008-6430 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-6430
Description
SQL injection vulnerability in the MyContent (com_mycontent) component 1.1.13 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a view action to index.php.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploits
Milw0rm 5714 (site down: refer to www.exploit-db.org 5714) - [Search]
References
BID 29468 - [Search]
CWE CWE-89 - [Search]
OSVDB 45852 - [Search]
SECUNIA 30490 - [Search]
XFDB 42783 - [Search]

Dates
Initial Date Seen [2009-03-06 13:30:00]
Last Date Updated [2009-04-14 01:40:43]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2008-6481 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-6481
Description
SQL injection vulnerability in the Versioning component (com_versioning) 1.0.2 in Joomla! and Mambo allows remote attackers to execute arbitrary SQL commands via the id parameter in an edit task to index.php.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploits
Milw0rm 5989 (site down: refer to www.exploit-db.org 5989) - [Search]
References
BID 30050 - [Search]
CWE CWE-89 - [Search]
XFDB 43526 - [Search]

Dates
Initial Date Seen [2009-03-17 15:30:00]
Last Date Updated [2009-03-19 00:00:00]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2008-6482 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-6482
Description
PHP remote file inclusion vulnerability in admin.treeg.php in the Flash Tree Gallery (com_treeg) component 1.0 for Joomla!, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via the mosConfig_live_site parameter.

CVSS
(5.1) AV:N/AC:H/Au:N/C:P/I:P/A:P
Exploits
Milw0rm 6928 (site down: refer to www.exploit-db.org 6928) - [Search]
References
BID 32041 - [Search]
CWE CWE-94 - [Search]
OSVDB 49499 - [Search]
SECUNIA 32520 - [Search]
XFDB 46260 - [Search]

Dates
Initial Date Seen [2009-03-18 00:00:00]
Last Date Updated [2009-03-18 11:30:00]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2008-6483 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-6483
Description
PHP remote file inclusion vulnerability in admin.googlebase.php in the Ecom Solutions VirtueMart Google Base (aka com_googlebase or Froogle) component 1.1 for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploits
Milw0rm 6975 (site down: refer to www.exploit-db.org 6975) - [Search]
References
BID 32098 - [Search]
CWE CWE-94 - [Search]
OSVDB 49529 - [Search]
SECUNIA 32533 - [Search]

Dates
Initial Date Seen [2009-03-18 11:30:00]
Last Date Updated [2009-03-19 00:00:00]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2008-6489 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-6489
Description
SQL injection vulnerability in MyAlbum component (com_myalbum) 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the album parameter to index.php.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploits
Milw0rm 5318 (site down: refer to www.exploit-db.org 5318) - [Search]
References
BID 28496 - [Search]
CWE CWE-89 - [Search]
XFDB 41510 - [Search]

Dates
Initial Date Seen [2009-03-19 00:00:00]
Last Date Updated [2009-03-19 06:30:00]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2008-6653 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-6653
Description
SQL injection vulnerability in webhosting.php in the Webhosting Component (com_webhosting) module before 1.1 RC7 for Joomla! and Mambo allows remote attackers to execute arbitrary SQL commands via the catid parameter to index.php.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploits
Milw0rm 5527 (site down: refer to www.exploit-db.org 5527) - [Search]
References
BID 29000 - [Search]
CWE CWE-89 - [Search]
OSVDB 50423 - [Search]
XFDB 42124 - [Search]

Dates
Initial Date Seen [2009-04-07 10:17:18]
Last Date Updated [2009-08-19 01:24:13]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2008-6841 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-6841
Description
PHP remote file inclusion vulnerability in the Green Mountain Information Technology and Consulting Database Query (com_dbquery) component 1.4.1.1 and earlier for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter to classes/DBQ/admin/common.class.php.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploits
Milw0rm 6003 (site down: refer to www.exploit-db.org 6003) - [Search]
References
BID 30093 - [Search]
CWE CWE-94 - [Search]
XFDB 43615 - [Search]

Dates
Initial Date Seen [2009-07-01 00:00:00]
Last Date Updated [2009-07-01 09:00:01]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2008-6852 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-6852
Description
SQL injection vulnerability in the Ice Gallery (com_ice) component 0.5 beta 2 for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter to index.php.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploits
Milw0rm 7572 (site down: refer to www.exploit-db.org 7572) - [Search]
References
BID 33008 - [Search]
CWE CWE-89 - [Search]
XFDB 47604 - [Search]

Dates
Initial Date Seen [2009-07-07 00:00:00]
Last Date Updated [2009-07-07 15:00:00]

Copyright
© 2012 The MITRE Corporation

NESSUS 25840 match rank: 100%

Source
http://www.nessus.org/plugins/index.php?view=single&id=25840
Title
FreeBSD : joomla -- multiple vulnerabilities (4872d9a7-4128-11dc-bdb0-0016179b2dd5)
Description
The remote FreeBSD host is missing a security-related update.

CVSS
(9.3) AV:N/AC:M/Au:N/C:C/I:C/A:C
References
CPE cpe:/o:freebsd:freebsd - [Search]
CVE-2007-4188 - [Search]
CVE-2007-4189 - [Search]
CVE-2007-4190 - [Search]
CVE-2007-5577 - [Search]
CWE 79 - [Search]
SECUNIA 26239 - [Search]
Tools
NESSUS 25840 - [Search]

Dates
Initial Date Seen [2007-08-03 00:00:00]
Last Date Updated [2011-11-18 00:00:00]

Copyright
© 2012 Tenable Network Security@

NVD CVE-2008-6881 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-6881
Description
Multiple SQL injection vulnerabilities in the Live Chat (com_livechat) component 1.0 for Joomla! allow remote attackers to execute arbitrary SQL commands via the last parameter to (1) getChat.php, (2) getChatRoom.php, and (3) getSavedChatRooms.php.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploits
Milw0rm 7441 (site down: refer to www.exploit-db.org 7441) - [Search]
References
BID 32803 - [Search]
CWE CWE-89 - [Search]
SECUNIA 33122 - [Search]
XFDB 47304 - [Search]

Dates
Initial Date Seen [2009-07-30 15:30:00]
Last Date Updated [2009-08-27 00:00:00]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2008-6882 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-6882
Description
Live Chat (com_livechat) component 1.0 for Joomla! allows remote attackers to use the xmlhttp.php script as an open HTTP proxy to hide network scanning activities or scan internal networks via a GET request with a full URL in the query string.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploits
Milw0rm 7441 (site down: refer to www.exploit-db.org 7441) - [Search]
References
BID 32803 - [Search]
CWE CWE-20 - [Search]
XFDB 47305 - [Search]

Dates
Initial Date Seen [2009-07-30 15:30:00]
Last Date Updated [2009-09-01 00:00:00]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2008-6883 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-6883
Description
SQL injection vulnerability in the Live Chat (com_livechat) component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the last parameter to getChatRoom.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploits
Milw0rm 7441 (site down: refer to www.exploit-db.org 7441) - [Search]
References
BID 32803 - [Search]
CWE CWE-89 - [Search]
SECUNIA 33122 - [Search]
XFDB 47304 - [Search]
XFDB 52442 - [Search]

Dates
Initial Date Seen [2009-07-30 16:00:00]
Last Date Updated [2009-08-19 01:24:40]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2008-6923 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-6923
Description
SQL injection vulnerability in the content component (com_content) 1.0.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the Itemid parameter in a blogcategory action to index.php.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploits
Milw0rm 6025 (site down: refer to www.exploit-db.org 6025) - [Search]
References
CWE CWE-89 - [Search]
XFDB 52455 - [Search]

Dates
Initial Date Seen [2009-08-10 14:30:00]
Last Date Updated [2009-08-19 01:24:44]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2008-7033 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-7033
Description
SQL injection vulnerability in the Simple Shop Galore (com_simpleshop) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the section parameter in a section action to index.php, a different vulnerability than CVE-2008-2568. NOTE: this issue was disclosed by an unreliable researcher, so the details might be incorrect.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
References
BID 27977 - [Search]
CWE CWE-89 - [Search]
OSVDB 52094 - [Search]
XFDB 40802 - [Search]

Dates
Initial Date Seen [2009-08-24 00:00:00]
Last Date Updated [2009-08-24 06:30:01]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2008-7169 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-7169
Description
SQL injection vulnerability in Jabode horoscope extension (com_jabode) for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a sign task to index.php.

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploits
Milw0rm 5963 (site down: refer to www.exploit-db.org 5963) - [Search]
References
BID 29994 - [Search]
CWE CWE-89 - [Search]

Dates
Initial Date Seen [2009-09-08 00:00:00]
Last Date Updated [2009-09-08 06:30:01]

Copyright
© 2012 The MITRE Corporation

NVD CVE-2008-7302 match rank: 100%

Source
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-7302
Description
SQL injection vulnerability in netinvoice.php in the nBill (com_netinvoice) component 1.2.0 SP1 for Joomla! allows remote attackers to execute arbitrary SQL commands via unspecified vectors involving "knowledge of ... the contents of an encrypted file."

CVSS
(7.5) AV:N/AC:L/Au:N/C:P/I:P/A:P
References
CWE CWE-89 - [Search]

Dates
Initial Date Seen [2011-10-04 22:56:24]
Last Date Updated [2012-05-14 00:00:00]

Copyright
© 2012 The MITRE Corporation
PREV 100NEXT 100

Do you want to buy or sell exploits? 1337DAY Inj3ct0r Exploits Database