Каталог CVE

Разработчик: secunia

Каталог

Все известные уязвимости

Статус «активна» означает, что запись опубликована в 2026 году. Он не заменяет проверку версии и официального исправления.

Сбросить

Найдено: 154

Разработчик: secunia
Высокая CVSS 7.5

CVE-2008-0754

РасширениеJoomla Com Rapidrecipe
Разработчикsecunia

Multiple SQL injection vulnerabilities in index.php in the Rapid Recipe (com_rapidrecipe) 1.6.5 component for Joomla! allow remote attackers to execute arbitrary SQL commands via (1) the us…

13.02.2008
Высокая CVSS 7.5

CVE-2008-0686

РасширениеJoomla Com Neoreferences
Разработчикsecunia

SQL injection vulnerability in index.php in the NeoReferences (com_neoreferences) 1.3.1 and 1.3.3 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the cat…

12.02.2008
Средняя CVSS 6.8

CVE-2007-4954

РасширениеJoomla Joom12pic Component
Разработчикsecunia

PHP remote file inclusion vulnerability in admin.joom12pic.php in the joom12Pic (com_joom12pic) 1.0 component for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in…

18.09.2007
Средняя CVSS 6.8

CVE-2007-4955

РасширениеJoomla Flash Fun Component
Разработчикsecunia

PHP remote file inclusion vulnerability in admin.joomlaflashfun.php in the Flash Fun! (com_joomlaflashfun) 1.0 component for Joomla! allows remote attackers to execute arbitrary PHP code vi…

18.09.2007
Средняя CVSS 6.8

CVE-2007-4923

РасширениеJoomla Joomla Radio
Разработчикsecunia

PHP remote file inclusion vulnerability in admin.joomlaradiov5.php in the Joomla Radio 5 (com_joomlaradiov5) component for Joomla! allows remote attackers to execute arbitrary PHP code via…

17.09.2007
Высокая CVSS 7.5

CVE-2007-4817

Разработчикsecunia

Unrestricted file upload vulnerability in the Restaurante (com_restaurante) component for Joomla! allows remote attackers to upload and execute arbitrary PHP code via an upload action speci…

11.09.2007
Высокая CVSS 7.5

CVE-2007-4503

РасширениеJoomla Nice Talk
Разработчикsecunia

SQL injection vulnerability in index.php in the Nice Talk component (com_nicetalk) 0.9.3 and earlier for Joomla! allows remote attackers to execute arbitrary SQL commands via the tagid para…

23.08.2007
Высокая CVSS 7.5

CVE-2007-4456

РасширениеMambo Mambo
Разработчикsecunia

SQL injection vulnerability in index.php in the SimpleFAQ (com_simplefaq) 2.11 component for Mambo allows remote attackers to execute arbitrary SQL commands via the aid parameter. NOTE: it…

21.08.2007
Высокая CVSS 9.3

CVE-2007-4188

РасширениеJoomla Joomla\!
Разработчикsecunia

Session fixation vulnerability in Joomla! before 1.0.13 (aka Sunglow) allows remote attackers to hijack administrative web sessions via unspecified vectors.

08.08.2007
Средняя CVSS 6.8

CVE-2006-7122

РасширениеJoomla Bsq Sitestats
Разработчикsecunia

Cross-site scripting (XSS) vulnerability in the IP Address Lookup functionality in BSQ Sitestats (component for Joomla) 1.8.0, and possibly other versions before 2.2.1, allows remote attack…

06.03.2007
Высокая CVSS 7.5

CVE-2006-7123

РасширениеJoomla Bsq Sitestats
Разработчикsecunia

Multiple SQL injection vulnerabilities in BSQ Sitestats (component for Joomla) 1.8.0, and possibly other versions before 2.2.1, allow remote attackers to execute arbitrary SQL commands via…

06.03.2007
Средняя CVSS 6.8

CVE-2006-7125

РасширениеJoomla Bsq Sitestats
Разработчикsecunia

Cross-site scripting (XSS) vulnerability in Joomla BSQ Sitestats 1.8.0 and 2.2.1 allows remote attackers to inject arbitrary web script or HTML via the HTTP Referer header, which is not pro…

06.03.2007
Высокая CVSS 7.5

CVE-2006-7008

РасширениеJoomla Joomla
Разработчикsecunia

Unspecified vulnerability in Joomla! before 1.0.10 has unknown impact and attack vectors, related to "securing mosmsg from misuse." NOTE: it is possible that this issue overlaps CVE-2006-10…

12.02.2007
Высокая CVSS 7.5

CVE-2006-7009

РасширениеJoomla Joomla
Разработчикsecunia

Joomla! before 1.0.10 allows remote attackers to spoof the frontend submission forms, which has unknown impact and attack vectors.

12.02.2007
Высокая CVSS 7.5

CVE-2006-7010

РасширениеJoomla Joomla
Разработчикsecunia

The mosgetparam implementation in Joomla! before 1.0.10, does not set a variable's data type to integer when the variable's default value is numeric, which has unspecified impact and attack…

12.02.2007
Высокая CVSS 7.5

CVE-2006-6419

Разработчикsecunia

jce.php in the JCE Admin Component in Ryan Demmer Joomla Content Editor (JCE) 1.1.0 beta 2 and earlier for Joomla! (com_jce) allows remote attackers to include and possibly execute arbitrar…

10.12.2006
Средняя CVSS 6.8

CVE-2006-6420

Разработчикsecunia

Multiple cross-site scripting (XSS) vulnerabilities in jce.php in the JCE Admin Component in Ryan Demmer Joomla Content Editor (JCE) 1.1.0 beta 2 and earlier for Joomla! (com_jce) allow rem…

10.12.2006
Средняя CVSS 5.1

CVE-2006-5106

РасширениеFacileforms Facileforms
Разработчикsecunia

Cross-site scripting (XSS) vulnerability in FacileForms before 1.4.7 for Mambo and Joomla!, when either register_globals or RG_EMULATION is enabled, allows remote attackers to inject arbitr…

03.10.2006