CVE-2006-3480 Information

Description

Multiple cross-site scripting (XSS) vulnerabilities in Joomla! before 1.0.10 allow remote attackers to inject arbitrary web script or HTML via unspecified parameters involving the (1) getUserStateFromRequest function and the (2) SEF and (3) com_messages modules.

Reference

http://secunia.com/advisories/20874 http://www.joomla.org/content/view/1510/74/ http://www.joomla.org/content/view/1511/78/ http://www.osvdb.org/26913 http://www.osvdb.org/26917 http://www.osvdb.org/26918 http://www.securityfocus.com/bid/18742 http://www.vupen.com/english/advisories/2006/2608 https://exchange.xforce.ibmcloud.com/vulnerabilities/27521

Share on: