Description
Multiple cross-site scripting (XSS) vulnerabilities in Joomla! before 1.7.0 allow remote attackers to inject arbitrary web script or HTML via (1) the URI to includes/application.php, reachable through index.php; and, when Internet Explorer or Konqueror is used, (2) allow remote attackers to inject arbitrary web script or HTML via the searchword parameter in a search action to index.php in the com_search component. NOTE: vector 2 exists because of an incomplete fix for CVE-2011-2509.5.
Remediation
References
Related Vulnerabilities
Oracle Database Server CVE-2018-2875 Vulnerability (CVE-2018-2875)
Drupal Incorrect Authorization Vulnerability (CVE-2020-13676)
Mailman Other Vulnerability (CVE-2002-0855)
phpMyFAQ Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2017-15731)
Oracle Database Server CVE-2024-21251 Vulnerability (CVE-2024-21251)