3.5

CVE-2008-6299

Multiple cross-site scripting (XSS) vulnerabilities in Joomla! 1.5.7 and earlier allow remote authenticated users with certain privileges to inject arbitrary web script or HTML via (1) the title and description parameters to the com_weblinks module and (2) unspecified vectors in the com_content module related to "article submission."

Data is provided by the National Vulnerability Database (NVD)
JoomlaJoomla Version <= 1.5.7
JoomlaJoomla Version1.0
JoomlaJoomla Version1.0.0
JoomlaJoomla Version1.0.1
JoomlaJoomla Version1.0.2
JoomlaJoomla Version1.0.3
JoomlaJoomla Version1.0.4
JoomlaJoomla Version1.0.5
JoomlaJoomla Version1.0.6
JoomlaJoomla Version1.0.7
JoomlaJoomla Version1.0.8
JoomlaJoomla Version1.0.9
JoomlaJoomla Version1.0.10
JoomlaJoomla Version1.0.11
JoomlaJoomla Version1.0.12
JoomlaJoomla Version1.0.13
JoomlaJoomla Version1.0.14
JoomlaJoomla Version1.03
JoomlaJoomla Version1.5
JoomlaJoomla Version1.5.0 Updatebeta
JoomlaJoomla Version1.5.0 Updatebeta1
JoomlaJoomla Version1.5.0 Updatebeta2
JoomlaJoomla Version1.5.0 Updaterc1
JoomlaJoomla Version1.5.0_beta
JoomlaJoomla Version1.5.0_beta1
JoomlaJoomla Version1.5.0_beta2
JoomlaJoomla Version1.5.0_rc1
JoomlaJoomla Version1.5.1
JoomlaJoomla Version1.5.2
JoomlaJoomla Version1.5.3
JoomlaJoomla Version1.5.4
JoomlaJoomla Version1.5.5
JoomlaJoomla Version1.5.6
JoomlaJoomla Version1.5rc3
JoomlaJoomla Version1.5rc4
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.01% 0.004
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 3.5 6.8 2.9
AV:N/AC:M/Au:S/C:N/I:P/A:N
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.