6.8

CVE-2009-1280

Multiple cross-site request forgery (CSRF) vulnerabilities in the com_media component for Joomla! 1.5.x through 1.5.9 allow remote attackers to hijack the authentication of unspecified victims via unknown vectors.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Joomla ≫ Joomla Version 1.5
Joomla ≫ Joomla Version 1.5.0 Update beta
Joomla ≫ Joomla Version 1.5.0 Update beta1
Joomla ≫ Joomla Version 1.5.0 Update beta2
Joomla ≫ Joomla Version 1.5.0 Update rc1
Joomla ≫ Joomla Version 1.5.1
Joomla ≫ Joomla Version 1.5.2
Joomla ≫ Joomla Version 1.5.3
Joomla ≫ Joomla Version 1.5.4
Joomla ≫ Joomla Version 1.5.5
Joomla ≫ Joomla Version 1.5.6
Joomla ≫ Joomla Version 1.5.7
Joomla ≫ Joomla Version 1.5.8
Joomla ≫ Joomla Version 1.5.9
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.6% 0.441
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.8 8.6 6.4
AV:N/AC:M/Au:N/C:P/I:P/A:P
CWE-352 Cross-Site Request Forgery (CSRF)

The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

http://developer.joomla.org/security/news/293-20090301-core-multiple-xsscsrf.html
Vendor Advisory
http://secunia.com/advisories/34551
Vendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/49656