Описание
JRequest in Joomla! 1.5 before 1.5.7 does not sanitize variables that were set with JRequest::setVar, which allows remote attackers to conduct "variable injection" attacks and have unspecified other impact.
JRequest in Joomla! 1.5 before 1.5.7 does not sanitize variables that were set with JRequest::setVar, which allows remote attackers to conduct "variable injection" attacks and have unspecified other impact.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2008-4105
- https://exchange.xforce.ibmcloud.com/vulnerabilities/45069
- http://developer.joomla.org/security/news/271-20080901-core-jrequest-variable-injection.html
- http://marc.info/?l=oss-security&m=122115344915232&w=2
- http://marc.info/?l=oss-security&m=122118210029084&w=2
- http://marc.info/?l=oss-security&m=122152798516853&w=2
- http://secunia.com/advisories/31789
- http://securityreason.com/securityalert/4275
- http://securitytracker.com/id?1020843
Связанные уязвимости
nvd
больше 17 лет назад
JRequest in Joomla! 1.5 before 1.5.7 does not sanitize variables that were set with JRequest::setVar, which allows remote attackers to conduct "variable injection" attacks and have unspecified other impact.