VDB
CVE-2011-4909
CVE-2011-4909
PUBLISHED
CVSS 4.300000190734863 MEDIUM
Multiple cross-site scripting (XSS) vulnerabilities in Joomla! before 1.5.12 allow remote attackers to inject arbitrary web script or HTML via the HTTP_REFERER header to (1) components/com_content/views/article/tmpl/form.php, (2) components/com_user/controller.php, (3) plugins/system/legacy/html.php, or (4) templates/beez/html/com_content/article/form.php.
EPSS 1.88% · 77.9th percentile
Risk Scores
CVSS 2.0
4.300000190734863
EPSS Score
1.88%
77.9th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | n/a |
| joomla | joomla\! | 0, 1.5.0, 1.5.1 |
Timeline
- Oct 7, 2012 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 17, 2022 CVE Updated
- May 21, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Oct 27, 2022 EPSS Score
- Dec 19, 2022 EPSS Score
- Feb 10, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 4, 2023 EPSS Score
- May 26, 2023 EPSS Score
References
- 35668 third-party-advisory
- [oss-security] 20111225 Re: CVE-request for three 2009 Joomla issues (second part) mailing-list
- 55589 vdb
- http://developer.joomla.org/security/news/298-20090604-core-frontend-xss-httpreferer-not-properly-filtered.html technical
- http://www.securityfocus.com/bid/35544 technical
- https://nvd.nist.gov/vuln/detail/CVE-2011-4909 advisory
- http://archives.neohapsis.com/archives/bugtraq/2009-07/0012.html url
- http://www.openwall.com/lists/oss-security/2011/12/25/3 url