The Googlemaps plugin 3.2 and earlier for Joomla! allows remote attackers with control of a sub-domain belonging to a victim domain to cause a denial of service via the 'url' parameter to plugin_googlemap3_kmlprxy.php. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-7428.
CVSS Vector
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:HMapsplugin Googlemaps
APPMapsplugin≤ 3.2
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
DoS
CWE
Related vulnerabilities
CVE-2013-7429CRITICAL9.8PL ✓same product
XML injection w Googlemaps plugin dla Joomla! (przed wersją 3.1)
CVE-2013-7428HIGH7.5same product
The Googlemaps plugin before 3.1 for Joomla! allows remote attackers to cause a denial of service via the url ...
CVE-2013-7432HIGH7.5same product
The Googlemaps plugin before 3.1 for Joomla! allows remote attackers to bypass an intended protection mechanis...
CVE-2013-7431MEDIUM5.3same product
Full path disclosure in the Googlemaps plugin before 3.1 for Joomla!.
CVE-2013-7433MEDIUM6.1same product
Cross-site scripting (XSS) vulnerability in the Googlemaps plugin before 3.1 for Joomla!.