CVE-2006-4468
Multiple unspecified vulnerabilities in Joomla! before 1.0.11, related to unvalidated input, allow attackers to have an unknown impact via unspecified vectors involving the (1) mosMail, (2) JosIsValidEmail, and (3) josSpoofValue functions; (4) the lack…
Does this matter?
Lower severity and a low EPSS score (1.97%). Track it; it rarely justifies an emergency change on its own.
Description
Multiple unspecified vulnerabilities in Joomla! before 1.0.11, related to unvalidated input, allow attackers to have an unknown impact via unspecified vectors involving the (1) mosMail, (2) JosIsValidEmail, and (3) josSpoofValue functions; (4) the lack of inclusion of globals.php in administrator/index.php; (5) the Admin User Manager; and (6) the poll module.
- CVSS 2.0
- 6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
- EPSS
- 1.97% probability · 79th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- joomla/joomla\!
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/21666Vendor Advisory
- http://www.joomla.org/content/view/1841/78/Vendor Advisory
- http://www.joomla.org/content/view/1843/74/Vendor Advisory
- http://www.vupen.com/english/advisories/2006/3408Third Party Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/28628Third Party Advisory, VDB Entry
- http://secunia.com/advisories/21666Vendor Advisory
- http://www.joomla.org/content/view/1841/78/Vendor Advisory
- http://www.joomla.org/content/view/1843/74/Vendor Advisory
- http://www.vupen.com/english/advisories/2006/3408Third Party Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/28628Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.