2 results (0.005 seconds)

CVSS: 4.3EPSS: 0%CPEs: 2EXPL: 2

Cross-site scripting (XSS) vulnerability in the joomlaXplorer (com_joomlaxplorer) Mambo/Joomla! component 1.6.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the error parameter in a show_error action to index.php. Vulnerabilidad de secuencias de comandos en sitios cruzados (XSS) en el componente joomlaXplorer (com_joomlaxplorer) Mambo/Joomla! 1.6.2 y anteriores; permite a atacantes remotos inyectar secuencias de comandos Web o HTML de su elección a través del parámetro de error en una acción show_error de index.php. • https://www.exploit-db.com/exploits/5431 http://www.securityfocus.com/bid/28746 https://exchange.xforce.ibmcloud.com/vulnerabilities/41779 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 5.0EPSS: 0%CPEs: 3EXPL: 2

Directory traversal vulnerability in index.php in the joomlaXplorer (com_joomlaxplorer) Mambo/Joomla! component 1.6.2 and earlier allows remote attackers to list arbitrary directories via a .. (dot dot) in the dir parameter in a show_error action. Vulnerabilidad de salto de directorio en index.php del componente joomlaXplorer 1.6.2 y anteriores (com_joomlaxplorer) para Mambo/Joomla!, permite a atacantes remotos listar directorios de su elección a través del parámetro "dir" .. • https://www.exploit-db.com/exploits/5431 http://www.securityfocus.com/bid/28746 https://exchange.xforce.ibmcloud.com/vulnerabilities/41778 • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •