Vulnerability Database

296,746

Total vulnerabilities in the database

CVE-2011-2509

Multiple cross-site scripting (XSS) vulnerabilities in Joomla! before 1.6.4 allow remote attackers to inject arbitrary web script or HTML via (1) the query string to the com_contact component, as demonstrated by the Itemid parameter to index.php; (2) the query string to the com_content component, as demonstrated by the filter_order parameter to index.php; (3) the query string to the com_newsfeeds component, as demonstrated by an arbitrary parameter to index.php; or (4) the option parameter in a reset.request action to index.php; and, when Internet Explorer or Konqueror is used, (5) allow remote attackers to inject arbitrary web script or HTML via the searchword parameter in a search action to index.php in the com_search component.

  • Published: Jul 27, 2011
  • Updated: Apr 13, 2023
  • CVE: CVE-2011-2509
  • Severity: Low
  • Exploit:

CVSS v2:

  • Severity: Low
  • Score: 4.3
  • AV:N/AC:M/Au:N/C:N/I:P/A:N
Software From Fixed in
Joomla / joomla 1.6-beta15 1.6-beta15.x
Joomla / joomla 1.6-beta12 1.6-beta12.x
Joomla / joomla 1.6-beta3 1.6-beta3.x
Joomla / joomla 1.5.11 1.5.11.x
Joomla / joomla 1.5.13 1.5.13.x
Joomla / joomla 1.5.3 1.5.3.x
Joomla / joomla 1.6-beta13 1.6-beta13.x
Joomla / joomla 1.5.2 1.5.2.x
Joomla / joomla 1.5.22 1.5.22.x
Joomla / joomla 1.5.9 1.5.9.x
Joomla / joomla 1.5.18 1.5.18.x
Joomla / joomla 1.6.1 1.6.1.x
Joomla / joomla 1.6-beta8 1.6-beta8.x
Joomla / joomla 1.6-beta5 1.6-beta5.x
Joomla / joomla 1.5.16 1.5.16.x
Joomla / joomla 1.5.4 1.5.4.x
Joomla / joomla 1.6.0 1.6.0.x
Joomla / joomla 1.5.10 1.5.10.x
Joomla / joomla 1.6-beta1 1.6-beta1.x
Joomla / joomla 1.6-beta6 1.6-beta6.x
Joomla / joomla 1.5.7 1.5.7.x
Joomla / joomla 1.5.0 1.5.0.x
Joomla / joomla - 1.6.3.x
Joomla / joomla 1.6-beta7 1.6-beta7.x
Joomla / joomla 1.6-beta14 1.6-beta14.x
Joomla / joomla 1.5.15 1.5.15.x
Joomla / joomla 1.5.6 1.5.6.x
Joomla / joomla 1.5.1 1.5.1.x
Joomla / joomla 1.6-beta11 1.6-beta11.x
Joomla / joomla 1.5.23 1.5.23.x
Joomla / joomla 1.5.17 1.5.17.x
Joomla / joomla 1.5.8 1.5.8.x
Joomla / joomla 1.6-beta2 1.6-beta2.x
Joomla / joomla 1.6-alpha2 1.6-alpha2.x
Joomla / joomla 1.5.19 1.5.19.x
Joomla / joomla 1.6-alpha 1.6-alpha.x
Joomla / joomla 1.6-beta4 1.6-beta4.x
Joomla / joomla 1.6-rc1 1.6-rc1.x
Joomla / joomla 1.6-beta9 1.6-beta9.x
Joomla / joomla 1.5.21 1.5.21.x
Joomla / joomla 1.6-beta10 1.6-beta10.x
Joomla / joomla 1.5.12 1.5.12.x
Joomla / joomla 1.5.5 1.5.5.x
Joomla / joomla 1.5.20 1.5.20.x
Joomla / joomla 1.5.15-rc 1.5.15-rc.x
Joomla / joomla 1.5.14 1.5.14.x