CVE-2011-4909

Joomla! < 1.5.12 - Cross-Site Scripting via HTTP_REFERER Header

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2011-4909. PoCs published by Juan Galiana Lara.

AI-analyzed exploit summary This exploit demonstrates a cross-site scripting (XSS) vulnerability in Joomla! versions prior to 1.5.12. It uses a cURL-based approach to inject and execute arbitrary JavaScript code in the context of the affected site.

Description

Multiple cross-site scripting (XSS) vulnerabilities in Joomla! before 1.5.12 allow remote attackers to inject arbitrary web script or HTML via the HTTP_REFERER header to (1) components/com_content/views/article/tmpl/form.php, (2) components/com_user/controller.php, (3) plugins/system/legacy/html.php, or (4) templates/beez/html/com_content/article/form.php.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Juan Galiana Lara · phpwebappsphp
https://www.exploit-db.com/exploits/33061

This exploit demonstrates a cross-site scripting (XSS) vulnerability in Joomla! versions prior to 1.5.12. It uses a cURL-based approach to inject and execute arbitrary JavaScript code in the context of the affected site.

Classification
Working Poc 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: Joomla! < 1.5.12
No auth needed
Prerequisites: Access to a vulnerable Joomla! instance
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (7)

Core 7
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/55589
Exploit mailing-list x_refsource_bugtraq
http://archives.neohapsis.com/archives/bugtraq/2009-07/0012.html
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/35668
Mailing List mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2011/12/25/8
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/35544
Mailing List mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2011/12/25/3

Scores

EPSS 0.0012
EPSS Percentile 31.0%

Details

CWE
CWE-79
Status published
Products (12)
joomla/joomla\! 1.5.0
joomla/joomla\! 1.5.1
joomla/joomla\! 1.5.2
joomla/joomla\! 1.5.3
joomla/joomla\! 1.5.4
joomla/joomla\! 1.5.5
joomla/joomla\! 1.5.6
joomla/joomla\! 1.5.7
joomla/joomla\! 1.5.8
joomla/joomla\! 1.5.9
... and 2 more
Published Oct 07, 2012
Tracked Since Feb 18, 2026