7.5

CVE-2008-3227

Unspecified vulnerability in Joomla! before 1.5.4 has unknown impact and attack vectors related to a "User Redirect Spam fix," possibly an open redirect vulnerability.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Joomla ≫ Joomla Version <= 1.5.3
Joomla ≫ Joomla Version 1.0
Joomla ≫ Joomla Version 1.0.0
Joomla ≫ Joomla Version 1.0.1
Joomla ≫ Joomla Version 1.0.2
Joomla ≫ Joomla Version 1.0.3
Joomla ≫ Joomla Version 1.0.4
Joomla ≫ Joomla Version 1.0.5
Joomla ≫ Joomla Version 1.0.6
Joomla ≫ Joomla Version 1.0.7
Joomla ≫ Joomla Version 1.0.8
Joomla ≫ Joomla Version 1.0.9
Joomla ≫ Joomla Version 1.0.10
Joomla ≫ Joomla Version 1.0.11
Joomla ≫ Joomla Version 1.0.12
Joomla ≫ Joomla Version 1.0.13
Joomla ≫ Joomla Version 1.03
Joomla ≫ Joomla Version 1.5
Joomla ≫ Joomla Version 1.5.0_beta
Joomla ≫ Joomla Version 1.5.0_beta1
Joomla ≫ Joomla Version 1.5.0_beta2
Joomla ≫ Joomla Version 1.5.0_rc1
Joomla ≫ Joomla Version 1.5.1
Joomla ≫ Joomla Version 1.5.2
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.14% 0.624
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
CWE-59 Improper Link Resolution Before File Access ('Link Following')

The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.

http://www.joomla.org/content/view/5180/1/
http://www.openwall.com/lists/oss-security/2008/07/12/2
https://exchange.xforce.ibmcloud.com/vulnerabilities/44205