OSVDB ID: 37709

Title: Joomla! index.php searchword Parameter XSS

Info

Disclosure

Oct 10, 2007

Discovery

Unknown

Dates

Exploit

Oct 10, 2007

Solution

Unknown

Description

Joomla! contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate the 'searchword' parameter in upon submission to the index.php script when "option" is set to "com_search". This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server. Successful exploitation requires that the victim changes the number of search results in a drop-down box, after having clicked on the malicious link.

Classification

Location: Remote / Network Access
Attack Type: Input Manipulation
Impact: Loss of Integrity
Exploit: Exploit Unknown
OSVDB: Web Related

Solution

Products

Unknown or Incomplete

References

Credit

Unknown or Incomplete



Direct URL: http://osvdb.org/37709