CVE-2007-6642

Multiple cross-site request forgery (CSRF) vulnerabilities in Joomla! before 1.5 RC4 allow remote attackers to (1) add a Super Admin, (2) upload an extension containing arbitrary PHP code, and (3) modify the configuration as administrators via unspecified vectors.


We have discovered 123,696 live websites that are affected by CVE-2007-6642.

Run a Free Instant Scan




Affected Software

Product  Joomla
Category Content Management System
Vulnerable Domains123,696 live websites (93% of Joomla install base)
Vulnerable Versions
  • from 0 through 1.5
Vulnerable Versions Count1 versions ( 0.77% of all versions)



Details

  • Published - Jan 4, 2008
  • Updated - Aug 7, 2024

Website Distribution by Country

Number of websites using CVE-2007-6642
United States6,482 websites



Italy36,211 websites
Russia10,328 websites
Kazakhstan6,998 websites
Germany6,431 websites
GB5,121 websites
Netherlands4,966 websites
South Africa4,604 websites
Serbia4,265 websites
Sweden3,713 websites

Website Distribution by TLD

Number of websites using CVE-2007-6642
.com26,729 websites
.it24,075 websites
.ru8,600 websites
.nl3,865 websites
.de3,292 websites
.se3,126 websites
.org2,922 websites
.cz2,860 websites
.co.uk2,717 websites
.net2,437 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2007-6642

Top websites that are affected by CVE-2007-6642. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*****.com Italy**,***
************.com Germany**,***
*********************.com United States**,***
*****.org United States**,***
********.com Slovakia**,***
*****.it Italy**,***
*********.com United States**,***
******.cz Czech Republic**,***
*******.ru Russia**,***
*******.com Italy**,***
See full domain list

FAQ

A total of 123,696 websites have been identified as vulnerable to CVE-2007-6642, based on global website indexing conducted by WebTechSurvey.
The Joomla is affected by the CVE-2007-6642 vulnerability.
Joomla versions up to and including 1.5 are vulnerable to CVE-2007-6642.