CVE

CVE-2009-4233

Severity:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
08/12/2009
Last modified:
09/12/2009

Description

Cross-site scripting (XSS) vulnerability in modules/mod_yj_whois.php in the YJ Whois component 1.0x and 1.5.x for Joomla! allows remote attackers to inject arbitrary web script or HTML via the domain parameter to index.php. NOTE: some of these details are obtained from third party information.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:joomla:joomla\!:*:*:*:*:*:*:*:*
cpe:2.3:a:youjoomla:yj_whois:1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:youjoomla:yj_whois:1.5.0:*:*:*:*:*:*:*