CVE-2011-2509

Joomla! < 1.6.4 - Cross-Site Scripting via Multiple Query Parameters

Title source: llm
STIX 2.1

Description

Multiple cross-site scripting (XSS) vulnerabilities in Joomla! before 1.6.4 allow remote attackers to inject arbitrary web script or HTML via (1) the query string to the com_contact component, as demonstrated by the Itemid parameter to index.php; (2) the query string to the com_content component, as demonstrated by the filter_order parameter to index.php; (3) the query string to the com_newsfeeds component, as demonstrated by an arbitrary parameter to index.php; or (4) the option parameter in a reset.request action to index.php; and, when Internet Explorer or Konqueror is used, (5) allow remote attackers to inject arbitrary web script or HTML via the searchword parameter in a search action to index.php in the com_search component.

References (4)

Core 4

Scores

EPSS 0.0003
EPSS Percentile 10.0%

Details

CWE
CWE-79
Status published
Products (29)
joomla/joomla-cms 0 - 1.6.4Packagist
joomla/joomla\! 1.5.0
joomla/joomla\! 1.5.1
joomla/joomla\! 1.5.2
joomla/joomla\! 1.5.3
joomla/joomla\! 1.5.4
joomla/joomla\! 1.5.5
joomla/joomla\! 1.5.6
joomla/joomla\! 1.5.7
joomla/joomla\! 1.5.8
... and 19 more
Published Jul 27, 2011
Tracked Since Feb 18, 2026