CVE-2011-4909
Joomla! < 1.5.11 - XSS
Title source: ruleDescription
Multiple cross-site scripting (XSS) vulnerabilities in Joomla! before 1.5.12 allow remote attackers to inject arbitrary web script or HTML via the HTTP_REFERER header to (1) components/com_content/views/article/tmpl/form.php, (2) components/com_user/controller.php, (3) plugins/system/legacy/html.php, or (4) templates/beez/html/com_content/article/form.php.
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by Juan Galiana Lara · phpwebappsphp
https://www.exploit-db.com/exploits/33061
References (7)
Scores
EPSS
0.0012
EPSS Percentile
31.3%
Classification
CWE
CWE-79
Status
published
Affected Products (13)
joomla/joomla\!
< 1.5.11
joomla/joomla\!
joomla/joomla\!
joomla/joomla\!
joomla/joomla\!
joomla/joomla\!
joomla/joomla\!
joomla/joomla\!
joomla/joomla\!
joomla/joomla\!
joomla/joomla\!
joomla/joomla\!
n/a/n/a
Timeline
Published
Oct 07, 2012
Tracked Since
Feb 18, 2026