components/com_user/models/reset.php in Joomla! 1.5 through 1.5.5 does not properly validate reset tokens, which allows remote attackers to reset the "first enabled user (lowest id)" password, typically for the administrator.
We have discovered 212,893 live websites that are affected by CVE-2008-3681.
| Product | |
| Category | Content Management System |
| Vulnerable Domains | 212,893 live websites (96% of Joomla install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 1 versions ( 0.97% of all versions) |
| 13,290 websites | |
| 54,270 websites | |
| 14,917 websites | |
| 13,629 websites | |
| 13,427 websites | |
| 12,457 websites | |
| 8,807 websites | |
| 7,628 websites | |
| 7,008 websites | |
| 6,647 websites |
| .com | 51,834 websites |
| .it | 35,370 websites |
| .ru | 12,580 websites |
| .pl | 9,601 websites |
| .co.uk | 6,594 websites |
| .org | 6,187 websites |
| .de | 4,980 websites |
| .nl | 4,863 websites |
| .net | 4,637 websites |
| .se | 3,393 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| *****************.de | *,*** | ||
| *******.**.ca | *,*** | ||
| *****.com | **,*** | ||
| ***********.**.za | **,*** | ||
| **************.se | **,*** | ||
| ***************.com | **,*** | ||
| *********.com | **,*** | ||
| ************.com | **,*** | ||
| *********************.com | **,*** | ||
| *****************.co | **,*** |