CVE-2011-4909

Joomla! < 1.5.11 - XSS

Title source: rule

Description

Multiple cross-site scripting (XSS) vulnerabilities in Joomla! before 1.5.12 allow remote attackers to inject arbitrary web script or HTML via the HTTP_REFERER header to (1) components/com_content/views/article/tmpl/form.php, (2) components/com_user/controller.php, (3) plugins/system/legacy/html.php, or (4) templates/beez/html/com_content/article/form.php.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Juan Galiana Lara · phpwebappsphp
https://www.exploit-db.com/exploits/33061

Scores

EPSS 0.0012
EPSS Percentile 31.3%

Classification

CWE
CWE-79
Status published

Affected Products (13)

joomla/joomla\! < 1.5.11
joomla/joomla\!
joomla/joomla\!
joomla/joomla\!
joomla/joomla\!
joomla/joomla\!
joomla/joomla\!
joomla/joomla\!
joomla/joomla\!
joomla/joomla\!
joomla/joomla\!
joomla/joomla\!
n/a/n/a

Timeline

Published Oct 07, 2012
Tracked Since Feb 18, 2026