CVE-2009-4157

Joomla! com_proofreader <1.0 RC9 - XSS

Title source: llm
STIX 2.1

Description

Multiple cross-site scripting (XSS) vulnerabilities in index.php in the ProofReader (com_proofreader) component 1.0 RC9 and earlier for Joomla! allow remote attackers to inject arbitrary web script or HTML via the URI, which is not properly handled in (1) 404 or (2) error pages.

Exploits (1)

exploitdb WORKING POC
by MustLive · textwebappsphp
https://www.exploit-db.com/exploits/10291

References (2)

Core 2
Core References
Various Sources x_refsource_misc
http://websecurity.com.ua/3482/
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/37145

Scores

EPSS 0.0032
EPSS Percentile 54.6%

Details

CWE
CWE-79
Status published
Products (2)
joomlatune/com_proofreader 1.0 rc6
joomlatune/com_proofreader < 1.0
Published Dec 02, 2009
Tracked Since Feb 18, 2026