Vulnerabilities > CVE-2017-14595 - Unspecified vulnerability in Joomla Joomla!
Attack vector
NETWORK Attack complexity
HIGH Privileges required
NONE Confidentiality impact
LOW Integrity impact
NONE Availability impact
NONE Summary
In Joomla! before 3.8.0, a logic bug in a SQL query could lead to the disclosure of article intro texts when these articles are in the archived state.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 6 |
Nessus
NASL family | CGI abuses |
NASL id | JOOMLA_380.NASL |
description | According to its self-reported version number, the Joomla! installation running on the remote web server is 1.5.0 or later but prior to 3.8.0. It is, therefore, affected by the following vulnerabilities : - A flaw exists related to SQL query handling that allows disclosure of article introduction text when such articles are in the archived state. Note that only versions 3.7.0 through 3.7.5 are affected by this flaw. (CVE-2017-14595) - An input-validation flaw exists in the LDAP authentication plugin that allows disclosure of usernames and passwords. Note that Joomla! must be configured for LDAP authentication to be affected. (CVE-2017-14596) Note that Nessus has not attempted to exploit these issues but has instead relied only on the application |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 103383 |
published | 2017-09-21 |
reporter | This script is Copyright (C) 2017-2019 and is owned by Tenable, Inc. or an Affiliate thereof. |
source | https://www.tenable.com/plugins/nessus/103383 |
title | Joomla! 1.5.0 < 3.8.0 Multiple Vulnerabilities |
code |
|
References
- http://www.securityfocus.com/bid/100900
- http://www.securityfocus.com/bid/100900
- http://www.securitytracker.com/id/1039407
- http://www.securitytracker.com/id/1039407
- https://developer.joomla.org/security-centre/710-20170901-core-information-disclosure
- https://developer.joomla.org/security-centre/710-20170901-core-information-disclosure