CVE-2011-2710
Summary
| CVE | CVE-2011-2710 |
|---|---|
| State | PUBLISHED |
| Assigner | redhat |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2011-07-27 20:55:03 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | Multiple cross-site scripting (XSS) vulnerabilities in Joomla! before 1.7.0 allow remote attackers to inject arbitrary web script or HTML via (1) the URI to includes/application.php, reachable through index.php; and, when Internet Explorer or Konqueror is used, (2) allow remote attackers to inject arbitrary web script or HTML via the searchword parameter in a search action to index.php in the com_search component. NOTE: vector 2 exists because of an incomplete fix for CVE-2011-2509.5. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
NoneIntegrity
PartialAvailability
NoneAV:N/AC:M/Au:N/C:N/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Joomla | Joomla! | 1.5.0 | All | All | All |
| Application | Joomla | Joomla! | 1.5.1 | All | All | All |
| Application | Joomla | Joomla! | 1.5.10 | All | All | All |
| Application | Joomla | Joomla! | 1.5.11 | All | All | All |
| Application | Joomla | Joomla! | 1.5.12 | All | All | All |
| Application | Joomla | Joomla! | 1.5.13 | All | All | All |
| Application | Joomla | Joomla! | 1.5.14 | All | All | All |
| Application | Joomla | Joomla! | 1.5.15 | All | All | All |
| Application | Joomla | Joomla! | 1.5.15 | rc | All | All |
| Application | Joomla | Joomla! | 1.5.16 | All | All | All |
| Application | Joomla | Joomla! | 1.5.17 | All | All | All |
| Application | Joomla | Joomla! | 1.5.18 | All | All | All |
| Application | Joomla | Joomla! | 1.5.19 | All | All | All |
| Application | Joomla | Joomla! | 1.5.2 | All | All | All |
| Application | Joomla | Joomla! | 1.5.20 | All | All | All |
| Application | Joomla | Joomla! | 1.5.21 | All | All | All |
| Application | Joomla | Joomla! | 1.5.22 | All | All | All |
| Application | Joomla | Joomla! | 1.5.23 | All | All | All |
| Application | Joomla | Joomla! | 1.5.3 | All | All | All |
| Application | Joomla | Joomla! | 1.5.4 | All | All | All |
| Application | Joomla | Joomla! | 1.5.5 | All | All | All |
| Application | Joomla | Joomla! | 1.5.6 | All | All | All |
| Application | Joomla | Joomla! | 1.5.7 | All | All | All |
| Application | Joomla | Joomla! | 1.5.8 | All | All | All |
| Application | Joomla | Joomla! | 1.5.9 | All | All | All |
| Application | Joomla | Joomla! | 1.6 | alpha | All | All |
| Application | Joomla | Joomla! | 1.6 | alpha2 | All | All |
| Application | Joomla | Joomla! | 1.6 | beta1 | All | All |
| Application | Joomla | Joomla! | 1.6 | beta10 | All | All |
| Application | Joomla | Joomla! | 1.6 | beta11 | All | All |
| Application | Joomla | Joomla! | 1.6 | beta12 | All | All |
| Application | Joomla | Joomla! | 1.6 | beta13 | All | All |
| Application | Joomla | Joomla! | 1.6 | beta14 | All | All |
| Application | Joomla | Joomla! | 1.6 | beta15 | All | All |
| Application | Joomla | Joomla! | 1.6 | beta2 | All | All |
| Application | Joomla | Joomla! | 1.6 | beta3 | All | All |
| Application | Joomla | Joomla! | 1.6 | beta4 | All | All |
| Application | Joomla | Joomla! | 1.6 | beta5 | All | All |
| Application | Joomla | Joomla! | 1.6 | beta6 | All | All |
| Application | Joomla | Joomla! | 1.6 | beta7 | All | All |
| Application | Joomla | Joomla! | 1.6 | beta8 | All | All |
| Application | Joomla | Joomla! | 1.6 | beta9 | All | All |
| Application | Joomla | Joomla! | 1.6 | rc1 | All | All |
| Application | Joomla | Joomla! | 1.6.0 | All | All | All |
| Application | Joomla | Joomla! | 1.6.1 | All | All | All |
| Application | Joomla | Joomla! | 1.6.3 | All | All | All |
| Application | Joomla | Joomla! | 1.6.4 | All | All | All |
| Application | Joomla | Joomla! | 1.6.5 | All | All | All |
| Application | Joomla | Joomla! | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| oss-security - Duplicate CVE assigned: CVE-2011-2708 CVE-2011-2710 | af854a3a-2127-422b-91ae-364da2661108 | www.openwall.com | |
| oss-security - CVE Request: Joomla! 1.7.0-RC and lower | Cross Site Scripting Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.openwall.com | Exploit |
| Joomla! Developer Network - [20110701] - XSS Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | developer.joomla.org | |
| oss-security - Re: Fwd: XSS vulnerability in Joomla 1.6.3 - CVE-2011-2710 / CVE-2011-2708 issue | af854a3a-2127-422b-91ae-364da2661108 | www.openwall.com | |
| oss-security - Re: CVE Request: Joomla! 1.7.0-RC and lower | Cross Site Scripting Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.openwall.com | Exploit |
| yehg.net/lab/pr0js/advisories/joomla/core/%5Bjoomla_1.7.0-rc%5D_cross_... | af854a3a-2127-422b-91ae-364da2661108 | yehg.net | |
| MISC:http://yehg.net/lab/pr0js/advisories/joomla/core/[joomla_1.7.0-rc]_cross_site_scripting(XSS) | MITRE | yehg.net | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.