Vulnerability index

Browse CVEs

480 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Joomla MEDIUM 6.8
CVE-2006-4474

Multiple cross-site scripting (XSS) vulnerabilities in Joomla! before 1.0.11 allow remote attackers to inject arbitrary web script or HTML via unspec…

Fix: after 1.0.10
Fix from $1,600 2006-08-31
Joomla\! MEDIUM 6.5
CVE-2006-4471

The Admin Upload Image functionality in Joomla! before 1.0.11 allows remote authenticated users to upload files outside of the /images/stories/ direc…

Fix: 1.0.11+
Fix from $1,600 2006-08-31
Joomla MEDIUM 5.1
CVE-2006-4473

Unspecified vulnerability in com_content in Joomla! before 1.0.11, when $mosConfig_hideEmail is set, allows attackers to perform the emailform and em…

Fix: after 1.0.10
Fix from $1,600 2006-08-31
Joomla MEDIUM 5.0
CVE-2006-4466

Joomla! before 1.0.11 does not properly unset variables when the input data includes a numeric parameter with a value matching an alphanumeric parame…

Fix: after 1.0.10
Fix from $1,600 2006-08-31
Rssxt Component HIGH 7.5
CVE-2006-4378

Multiple PHP remote file inclusion vulnerabilities in the Rssxt component for Joomla! (com_rssxt), possibly 2.0 Beta 1 or 1.0 and earlier, allow remo…

Fix: after 2.0_beta_1
Fix from $1,950 2006-08-26
X Shop Component HIGH 7.5
CVE-2006-4269

PHP remote file inclusion vulnerability in admin.x-shop.php in the x-shop component (com_x-shop) 1.7 and earlier for Mambo and Joomla! allows remote …

Fix: after 1.7
Fix from $1,950 2006-08-21
Jim Instant Messaging Component MEDIUM 5.1
CVE-2006-4242

PHP remote file inclusion vulnerability in install.jim.php in the JIM 1.0.1 component for Joomla or Mambo allows remote attackers to execute arbitrar…

No fix yet
Fix from $1,600 2006-08-21
Moslistmessenger Component HIGH 7.5
CVE-2006-4229

PHP remote file inclusion vulnerability in archive.php in the mosListMessenger Component (com_lm) before 20060719 for Mambo and Joomla! allows remote…

Mitigation only
Fix from $1,950 2006-08-18
Webring Component HIGH 7.5
CVE-2006-4129

PHP remote file inclusion vulnerability in admin.webring.docs.php in the Webring Component (com_webring) 1.0 and earlier for Joomla! allows remote at…

No fix yet
Fix from $1,950 2006-08-14
Jd Wiki MEDIUM 6.8
CVE-2006-4074EPSS 6%

PHP remote file inclusion vulnerability in lib/tpl/default/main.php in the JD-Wiki Component (com_jd-wiki) 1.0.2 and earlier for Joomla!, when regist…

Fix: after 1.0.2
Fix from $1,600 2006-08-11
Colophon HIGH 7.5
CVE-2006-3969

PHP remote file inclusion vulnerability in administrator/components/com_colophon/admin.colophon.php in Colophon 1.2 and earlier for Joomla! allows re…

Fix: after 1.2
Fix from $1,950 2006-08-01
Lmo HIGH 7.5
CVE-2006-3970EPSS 8%

PHP remote file inclusion vulnerability in lmo.php in the LMO Component (com_lmo) 1.0b2 and earlier for Joomla! allows remote attackers to execute ar…

Fix: after 1.0b2
Fix from $1,950 2006-08-01
Performs Component MEDIUM 6.8
CVE-2006-3774EPSS 6%

PHP remote file inclusion vulnerability in performs.php in the perForms component (com_performs) 1.0 and earlier for Joomla! allows remote attackers …

Fix: after 1.0
Fix from $1,600 2006-07-24
Pc Cookbook MEDIUM 6.8
CVE-2006-3530EPSS 6%

PHP remote file inclusion vulnerability in com_pccookbook/pccookbook.php in the PccookBook Component for Mambo and Joomla 0.3 and possibly up to 1.3.…

No fix yet
Fix from $1,600 2006-07-12
Joomla HIGH 7.5
CVE-2006-3481

Multiple SQL injection vulnerabilities in Joomla! before 1.0.10 allow remote attackers to execute arbitrary SQL commands via unspecified parameters i…

Patch available
Fix from $1,950 2006-07-10
Joomla MEDIUM 5.8
CVE-2006-3480

Multiple cross-site scripting (XSS) vulnerabilities in Joomla! before 1.0.10 allow remote attackers to inject arbitrary web script or HTML via unspec…

Patch available
Fix from $1,600 2006-07-10
Joomla HIGH 7.5
CVE-2006-2960

PHP remote file inclusion vulnerability in includes/joomla.php in Joomla! 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the …

Mitigation only
Fix from $1,950 2006-06-12
Joomla MEDIUM 5.0
CVE-2006-1956

The com_rss option (rss.php) in (1) Mambo and (2) Joomla! allows remote attackers to obtain sensitive information via an invalid feed parameter, whic…

No fix yet
Fix from $1,600 2006-04-21
Joomla\! MEDIUM 5.0
CVE-2006-1957

The com_rss option (rss.php) in (1) Mambo and (2) Joomla! allows remote attackers to cause a denial of service (disk consumption and possibly web-ser…

No fix yet
Fix from $1,600 2006-04-21
Joomla HIGH 10.0
CVE-2006-1047

Unspecified vulnerability in the "Remember Me login functionality" in Joomla! 1.0.7 and earlier has unknown impact and attack vectors.

No fix yet
Fix from $1,950 2006-03-07
Joomla HIGH 7.5
CVE-2006-1049

Multiple SQL injection vulnerabilities in the Admin functionality in Joomla! 1.0.7 and earlier allow remote authenticated administrators to execute a…

Fix: after 1.0.7
Fix from $1,950 2006-03-07
Joomla MEDIUM 5.0
CVE-2006-1048

Joomla! 1.0.7 and earlier allows attackers to bypass intended access restrictions and gain certain privileges via certain attack vectors related to t…

Patch available
Fix from $1,600 2006-03-07
Joomla HIGH 7.8
CVE-2006-1028

feedcreator.class.php (aka the syndication component) in Joomla! 1.0.7 allows remote attackers to cause a denial of service (stressed file cache) by …

Patch available
Fix from $1,950 2006-03-07
Joomla MEDIUM 5.0
CVE-2006-1027

feedcreator.class.php (aka the syndication component) in Joomla! 1.0.7 allows remote attackers to obtain sensitive information via a "/" (slash) in t…

Patch available
Fix from $1,600 2006-03-07
Joomla MEDIUM 5.0
CVE-2006-1030

Unspecified vulnerability in mod_templatechooser in Joomla! 1.0.7 allows remote attackers to obtain sensitive information via an unspecified attack v…

Patch available
Fix from $1,600 2006-03-07
Joomla HIGH 10.0
CVE-2006-0303

Multiple unspecified vulnerabilities in the (1) publishing component, (2) Contact Component, (3) TinyMCE Compressor, and (4) other components in Joom…

Patch available
Fix from $1,950 2006-01-19
Joomla MEDIUM 5.0
CVE-2006-0114

The vCard functions in Joomla! 1.0.5 use predictable sequential IDs for vcards and do not restrict access to them, which allows remote attackers to o…

Mitigation only
Fix from $1,600 2006-01-09
Joomla\! MEDIUM 5.3
CVE-2005-4650

Joomla! 1.03 does not restrict the number of "Search" Mambots, which allows remote attackers to cause a denial of service (resource consumption) via …

Patch available
Fix from $1,600 2005-12-31
Joomla HIGH 10.0
CVE-2005-3773

Unspecified vulnerability in Joomla! before 1.0.4 has unknown impact and attack vectors, related to "Potential misuse of Media component file managem…

Patch available
Fix from $1,950 2005-11-23
Joomla HIGH 7.5
CVE-2005-3772

Multiple SQL injection vulnerabilities in Joomla! before 1.0.4 allow remote attackers to execute arbitrary SQL commands via the (1) Itemid variable i…

Patch available
Fix from $1,950 2005-11-23