MEDIUM
Joomla! before 1.5.15 allows remote attackers to read an extension's XML file, and thereby obtain the extension's version number, via a direct request
Published Nov 16, 2009
5.0
MEDIUMCVSS 2.0
EPSS 1.22%
Description
Joomla! before 1.5.15 allows remote attackers to read an extension's XML file, and thereby obtain the extension's version number, via a direct request.
Affected products
No data.
OR
- ≤ 1.5.14
- 1.5.0
- 1.5.1
- 1.5.2
- 1.5.3
- 1.5.4
- 1.5.5
- 1.5.6
- 1.5.7
- 1.5.8
- 1.5.9
- 1.5.10
- 1.5.11
- 1.5.12
- 1.5.13
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (5)
- http://developer.joomla.org/security/news/306-20091103-core-xml-file-read-issue.html x_refsource_CONFIRMVendor Advisory
- http://secunia.com/advisories/37262 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://www.osvdb.org/59800 vdb-entryx_refsource_OSVDB
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2009-3917 Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/54160 vdb-entryx_refsource_XF
| Link | Providers | Tags |
|---|---|---|
| http://developer.joomla.org/security/news/306-20091103-core-xml-file-read-issue.html | x_refsource_CONFIRMVendor Advisory | |
| http://secunia.com/advisories/37262 | third-party-advisoryx_refsource_SECUNIAVendor Advisory | |
| http://www.osvdb.org/59800 | vdb-entryx_refsource_OSVDB | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2009-3917 | Advisory | |
| https://exchange.xforce.ibmcloud.com/vulnerabilities/54160 | vdb-entryx_refsource_XF |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Nov 16, 2009
Updated Aug 7, 2024
Reserved Nov 16, 2009
Link CVE-2009-3946
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2009-3917 Assigner mitre
Published Nov 16, 2009
Updated Aug 7, 2024
Exploited since n/a
Link EUVD-2009-3917