Multiple cross-site scripting (XSS) vulnerabilities in Joomla! before 1.0.13 (aka Sunglow) allow remote attackers to inject arbitrary web script or HTML via the (1) Title or (2) Section Name form fields in the Section Manager component, or (3) multiple unspecified fields in New Menu Item.
References
Link | Resource |
---|---|
http://joomlacode.org/gf/project/joomla/tracker/?action=TrackerItemEdit&tracker_item_id=5654 | Patch Vendor Advisory |
http://osvdb.org/37173 | Broken Link |
http://secunia.com/advisories/25804 | Patch Vendor Advisory |
http://www.joomla.org/content/view/3670/78/ | Release Notes Vendor Advisory |
http://www.joomla.org/content/view/3677/1/ | Vendor Advisory |
http://www.securityfocus.com/bid/24663 | Third Party Advisory VDB Entry |
https://exchange.xforce.ibmcloud.com/vulnerabilities/35119 | Third Party Advisory VDB Entry |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: mitre
Published: 2007-10-18T21:00:00
Updated: 2017-07-28T12:57:01
Reserved: 2007-10-18T00:00:00
Link: CVE-2007-5577
JSON object: View
NVD Information
Status : Analyzed
Published: 2007-10-18T21:17:00.000
Modified: 2021-10-01T15:03:54.470
Link: CVE-2007-5577
JSON object: View
Redhat Information
No data.
CWE