The Googlemaps plugin 3.2 and earlier for Joomla! allows remote attackers with control of a sub-domain belonging to a victim domain to cause a denial of service via the 'url' parameter to plugin_googlemap3_kmlprxy.php. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-7428.
oryginał ENCVSS Vector
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:HMapsplugin Googlemaps
APPMapsplugin≤ 3.2
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
Tagi
DoS
CWE
Powiązane podatności
CVE-2013-7429CRITICAL9.8PL ✓ten sam produkt
XML injection w Googlemaps plugin dla Joomla! (przed wersją 3.1)
CVE-2013-7428HIGH7.5ten sam produkt
The Googlemaps plugin before 3.1 for Joomla! allows remote attackers to cause a denial of service via the url ...
CVE-2013-7432HIGH7.5ten sam produkt
The Googlemaps plugin before 3.1 for Joomla! allows remote attackers to bypass an intended protection mechanis...
CVE-2013-7431MEDIUM5.3ten sam produkt
Full path disclosure in the Googlemaps plugin before 3.1 for Joomla!.
CVE-2013-7433MEDIUM6.1ten sam produkt
Cross-site scripting (XSS) vulnerability in the Googlemaps plugin before 3.1 for Joomla!.