CVE-2009-3946

Joomla! before 1.5.15 allows remote attackers to read an extension's XML file, and thereby obtain the extension's version number, via a direct request.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:joomla:joomla\!:*:*:*:*:*:*:*:*
cpe:2.3:a:joomla:joomla\!:1.5.0:*:*:*:*:*:*:*
cpe:2.3:a:joomla:joomla\!:1.5.1:*:*:*:*:*:*:*
cpe:2.3:a:joomla:joomla\!:1.5.2:*:*:*:*:*:*:*
cpe:2.3:a:joomla:joomla\!:1.5.3:*:*:*:*:*:*:*
cpe:2.3:a:joomla:joomla\!:1.5.4:*:*:*:*:*:*:*
cpe:2.3:a:joomla:joomla\!:1.5.5:*:*:*:*:*:*:*
cpe:2.3:a:joomla:joomla\!:1.5.6:*:*:*:*:*:*:*
cpe:2.3:a:joomla:joomla\!:1.5.7:*:*:*:*:*:*:*
cpe:2.3:a:joomla:joomla\!:1.5.8:*:*:*:*:*:*:*
cpe:2.3:a:joomla:joomla\!:1.5.9:*:*:*:*:*:*:*
cpe:2.3:a:joomla:joomla\!:1.5.10:*:*:*:*:*:*:*
cpe:2.3:a:joomla:joomla\!:1.5.11:*:*:*:*:*:*:*
cpe:2.3:a:joomla:joomla\!:1.5.12:*:*:*:*:*:*:*
cpe:2.3:a:joomla:joomla\!:1.5.13:*:*:*:*:*:*:*

History

21 Nov 2024, 01:08

Type Values Removed Values Added
References () http://developer.joomla.org/security/news/306-20091103-core-xml-file-read-issue.html - Vendor Advisory () http://developer.joomla.org/security/news/306-20091103-core-xml-file-read-issue.html - Vendor Advisory
References () http://secunia.com/advisories/37262 - Vendor Advisory () http://secunia.com/advisories/37262 - Vendor Advisory
References () http://www.osvdb.org/59800 - () http://www.osvdb.org/59800 -
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/54160 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/54160 -

Information

Published : 2009-11-16 20:30

Updated : 2024-11-21 01:08


NVD link : CVE-2009-3946

Mitre link : CVE-2009-3946

CVE.ORG link : CVE-2009-3946


JSON object : View

Products Affected

joomla

  • joomla\!
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor