Page 8 of 37 results (0.003 seconds)

CVSS: 10.0EPSS: 0%CPEs: 6EXPL: 0

Multiple unspecified vulnerabilities in the (1) publishing component, (2) Contact Component, (3) TinyMCE Compressor, and (4) other components in Joomla! 1.0.5 and earlier have unknown impact and attack vectors. • http://secunia.com/advisories/18513 http://www.joomla.org/content/view/738/66 •

CVSS: 5.0EPSS: 1%CPEs: 1EXPL: 0

The vCard functions in Joomla! 1.0.5 use predictable sequential IDs for vcards and do not restrict access to them, which allows remote attackers to obtain valid e-mail addresses to conduct spam attacks by modifying the contact_id parameter to index2.php. • http://forge.joomla.org/sf/go/artf2950 http://forum.joomla.org/index.php/topic%2C29031.0.html http://secunia.com/advisories/18361 http://www.listerit.com/content/view/116/84 http://www.securityfocus.com/bid/16185 http://www.vupen.com/english/advisories/2006/0097 https://exchange.xforce.ibmcloud.com/vulnerabilities/24042 • CWE-264: Permissions, Privileges, and Access Controls •