{"api_version":"1","generated_at":"2026-07-23T10:25:17+00:00","cve":"CVE-2006-4468","urls":{"html":"https://cve.report/CVE-2006-4468","api":"https://cve.report/api/cve/CVE-2006-4468.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2006-4468","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2006-4468"},"summary":{"title":"CVE-2006-4468","description":"Multiple unspecified vulnerabilities in Joomla! before 1.0.11, related to unvalidated input, allow attackers to have an unknown impact via unspecified vectors involving the (1) mosMail, (2) JosIsValidEmail, and (3) josSpoofValue functions; (4) the lack of inclusion of globals.php in administrator/index.php; (5) the Admin User Manager; and (6) the poll module.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2006-08-31 20:04:00","updated_at":"2021-10-01 15:05:00"},"problem_types":["CWE-20"],"metrics":[],"references":[{"url":"http://www.joomla.org/content/view/1843/74/","name":"http://www.joomla.org/content/view/1843/74/","refsource":"CONFIRM","tags":[],"title":"Joomla! - Upgrade immediately to Joomla! 1.0.11","mime":"text/xml","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/28628","name":"joomla-email-errors(28628)","refsource":"XF","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/21666","name":"21666","refsource":"SECUNIA","tags":["Vendor Advisory"],"title":"Joomla! Multiple Vulnerabilities - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.joomla.org/content/view/1841/78/","name":"http://www.joomla.org/content/view/1841/78/","refsource":"CONFIRM","tags":[],"title":"Joomla!","mime":"text/xml","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2006/3408","name":"ADV-2006-3408","refsource":"VUPEN","tags":[],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2006-4468","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2006-4468","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2006","cve_id":"4468","vulnerable":"1","versionEndIncluding":"1.0.10","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"joomla","cpe5":"joomla","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2006","cve_id":"4468","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"joomla","cpe5":"joomla\\!","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2006-4468","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Multiple unspecified vulnerabilities in Joomla! before 1.0.11, related to unvalidated input, allow attackers to have an unknown impact via unspecified vectors involving the (1) mosMail, (2) JosIsValidEmail, and (3) josSpoofValue functions; (4) the lack of inclusion of globals.php in administrator/index.php; (5) the Admin User Manager; and (6) the poll module."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"ADV-2006-3408","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2006/3408"},{"name":"http://www.joomla.org/content/view/1841/78/","refsource":"CONFIRM","url":"http://www.joomla.org/content/view/1841/78/"},{"name":"21666","refsource":"SECUNIA","url":"http://secunia.com/advisories/21666"},{"name":"joomla-email-errors(28628)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/28628"},{"name":"http://www.joomla.org/content/view/1843/74/","refsource":"CONFIRM","url":"http://www.joomla.org/content/view/1843/74/"}]}},"nvd":{"publishedDate":"2006-08-31 20:04:00","lastModifiedDate":"2021-10-01 15:05:00","problem_types":["CWE-20"],"metrics":{"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:P/A:P","accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL","baseScore":6.8},"severity":"MEDIUM","exploitabilityScore":8.6,"impactScore":6.4,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:joomla:joomla\\!:*:*:*:*:*:*:*:*","versionEndExcluding":"1.0.11","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2006","CveId":"4468","Ordinal":"19803","Title":"CVE-2006-4468","CVE":"CVE-2006-4468","Year":"2006"},"notes":[{"CveYear":"2006","CveId":"4468","Ordinal":"1","NoteData":"Multiple unspecified vulnerabilities in Joomla! before 1.0.11, related to unvalidated input, allow attackers to have an unknown impact via unspecified vectors involving the (1) mosMail, (2) JosIsValidEmail, and (3) josSpoofValue functions; (4) the lack of inclusion of globals.php in administrator/index.php; (5) the Admin User Manager; and (6) the poll module.","Type":"Description","Title":null},{"CveYear":"2006","CveId":"4468","Ordinal":"2","NoteData":"2006-08-31","Type":"Other","Title":"Published"},{"CveYear":"2006","CveId":"4468","Ordinal":"3","NoteData":"2017-07-19","Type":"Other","Title":"Modified"}]}}}