Security Advisory

CVE-2006-4476

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2006-08-31 20:00:00
Last updated 2024-08-07 19:14:46
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

Multiple unspecified vulnerabilities in Joomla! before 1.0.11, related to "Injection Flaws," allow attackers to have an unknown impact via (1) globals.php, which uses include_once() instead of require(); (2) the $options variable; (3) Admin Upload Image; (4) ->load(); (5) content submissions when frontpage is selected; (6) the mosPageNav constructor; (7) saveOrder functions; (8) the absence of "exploit blocking rules" in htaccess; and (9) the ACL.