Каталог CVE

Разработчик: secunia

Каталог

Все известные уязвимости

Статус «активна» означает, что запись опубликована в 2026 году. Он не заменяет проверку версии и официального исправления.

Сбросить

Найдено: 154

Разработчик: secunia
Высокая CVSS 7.5

CVE-2010-0972

РасширениеG4j.laoneo Com Gcalendar
Разработчикsecunia

Directory traversal vulnerability in the GCalendar (com_gcalendar) component 2.1.5 for Joomla! allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the…

16.03.2010
Высокая CVSS 7.5

CVE-2009-4679

РасширениеInertialfate Com If Nexus
Разработчикsecunia

Directory traversal vulnerability in the inertialFATE iF Portfolio Nexus (com_if_nexus) component 1.5 for Joomla! allows remote attackers to include and execute arbitrary local files via a…

08.03.2010
Средняя CVSS 6.8

CVE-2010-0760

Разработчикsecunia

Multiple directory traversal vulnerabilities in the Core Design Scriptegrator plugin 1.4.1 for Joomla! allow remote attackers to include and execute arbitrary local files via directory trav…

27.02.2010
Высокая CVSS 7.5

CVE-2010-0692

РасширениеIptechinside Com Jquarks
Разработчикsecunia

SQL injection vulnerability in the IP-Tech JQuarks (com_jquarks) Component 0.2.3, and possibly earlier, for Joomla! allows remote attackers to execute arbitrary SQL commands via the id para…

23.02.2010
Высокая CVSS 7.5

CVE-2010-0635

РасширениеJevents Jevents Search Plugin
Разработчикsecunia

SQL injection vulnerability in the plgSearchEventsearch::onSearch method in eventsearch.php in the JEvents Search plugin 1.5 through 1.5.3 for Joomla! allows remote attackers to execute arb…

12.02.2010
Средняя CVSS 5.8

CVE-2010-0467

Разработчикsecunia

Directory traversal vulnerability in the ccNewsletter (com_ccnewsletter) component 1.0.5 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller par…

02.02.2010
Средняя CVSS 4.3

CVE-2009-4575

РасширениеJoomla Joomla\!
Разработчикsecunia

Cross-site scripting (XSS) vulnerability in the Q-Personel (com_qpersonel) component 1.0.2 RC2 for Joomla! allows remote attackers to inject arbitrary web script or HTML via the personel_si…

06.01.2010
Средняя CVSS 4.3

CVE-2009-4573

РасширениеJoomlabear Mod Joomulus
Разработчикsecunia

Multiple cross-site scripting (XSS) vulnerabilities in the Joomulus (mod_joomulus) module 2.0 for Joomla! allow remote attackers to inject arbitrary web script or HTML via the tagcloud para…

06.01.2010
Высокая CVSS 7.5

CVE-2009-4550

РасширениеJoomla Joomla\!
Разработчикsecunia

SQL injection vulnerability in the Kunena Forum (com_kunena) component 1.5.3 and 1.5.4 for Joomla! allows remote attackers to execute arbitrary SQL commands via the func parameter to index.…

04.01.2010
Средняя CVSS 4.3

CVE-2009-4255

РасширениеJoomla Joomla\!
Разработчикsecunia

Cross-site scripting (XSS) vulnerability in the You!Hostit! template 1.0.1 for Joomla! allows remote attackers to inject arbitrary web script or HTML via the created_by_alias parameter in i…

10.12.2009
Средняя CVSS 4.3

CVE-2009-4233

РасширениеJoomla Joomla\!
Разработчикsecunia

Cross-site scripting (XSS) vulnerability in modules/mod_yj_whois.php in the YJ Whois component 1.0x and 1.5.x for Joomla! allows remote attackers to inject arbitrary web script or HTML via…

08.12.2009
Средняя CVSS 5.0

CVE-2009-4232

РасширениеJonijnm Com Kide
Разработчикsecunia

The Kide Shoutbox (com_kide) component 0.4.6 for Joomla! does not properly perform authentication, which allows remote attackers to post messages with an arbitrary account name via an inser…

08.12.2009
Высокая CVSS 7.5

CVE-2009-3822

РасширениеJoomla Joomla\!
Разработчикsecunia

PHP remote file inclusion vulnerability in Fiji Web Design Ajax Chat (com_ajaxchat) component 1.0 for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[…

28.10.2009
Средняя CVSS 6.8

CVE-2009-3661

Разработчикsecunia

Multiple SQL injection vulnerabilities in the DJ-Catalog (com_djcatalog) component for Joomla! allow remote attackers to execute arbitrary SQL commands via the (1) id parameter in a showIte…

11.10.2009
Высокая CVSS 7.5

CVE-2009-3481

РасширениеIsygen Com Icrmbasic
Разработчикsecunia

A certain interface in the iCRM Basic (com_icrmbasic) component 1.4.2.31 for Joomla! does not require administrative authentication, which has unspecified impact and remote attack vectors.…

30.09.2009
Высокая CVSS 7.5

CVE-2009-3417

РасширениеIdojoomla Com Idoblog
Разработчикsecunia

SQL injection vulnerability in the IDoBlog (com_idoblog) component 1.1 build 30 for Joomla! allows remote attackers to execute arbitrary SQL commands via the userid parameter in a profile a…

25.09.2009
Высокая CVSS 7.5

CVE-2009-3215

РасширениеPhp-shop-system Ixxo Cart
Разработчикsecunia

SQL injection vulnerability in IXXO Cart Standalone before 3.9.6.1, and the IXXO Cart component for Joomla! 1.0.x, allows remote attackers to execute arbitrary SQL commands via the parent p…

16.09.2009
Средняя CVSS 4.3

CVE-2009-3155

РасширениеJoomla Joomla
Разработчикsecunia

Cross-site scripting (XSS) vulnerability in gmap.php in the Almond Classifieds (com_aclassf) component 7.5 for Joomla! allows remote attackers to inject arbitrary web script or HTML via the…

10.09.2009