CVE-2010-3712

Joomla! 1.5.x < 1.5.21 and 1.6.x < 1.6.1 - Cross-Site Scripting via Multiple Encoded Entities

Title source: llm
STIX 2.1

Description

Cross-site scripting (XSS) vulnerability in Joomla! 1.5.x before 1.5.21 and 1.6.x before 1.6.1 allows remote attackers to inject arbitrary web script or HTML via vectors involving "multiple encoded entities," as demonstrated by the query string to index.php in the com_weblinks or com_content component.

Scores

EPSS 0.0004
EPSS Percentile 12.0%

Details

CWE
CWE-79
Status published
Products (21)
joomla/joomla\! 1.5.0
joomla/joomla\! 1.5.1
joomla/joomla\! 1.5.2
joomla/joomla\! 1.5.3
joomla/joomla\! 1.5.4
joomla/joomla\! 1.5.5
joomla/joomla\! 1.5.6
joomla/joomla\! 1.5.7
joomla/joomla\! 1.5.8
joomla/joomla\! 1.5.9
... and 11 more
Published Oct 28, 2010
Tracked Since Feb 18, 2026