CVE-2011-0005
Joomla! <1.0.16 - XSS
Title source: llmDescription
Cross-site scripting (XSS) vulnerability in the com_search module for Joomla! 1.0.x through 1.0.15 allows remote attackers to inject arbitrary web script or HTML via the ordering parameter to index.php.
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by Aung Khant · textwebappsphp
https://www.exploit-db.com/exploits/35167
References (7)
Scores
EPSS
0.0005
EPSS Percentile
15.6%
Classification
CWE
CWE-79
Status
published
Affected Products (2)
joomla/com_search
n/a/n/a
Timeline
Published
Jan 11, 2011
Tracked Since
Feb 18, 2026