Multiple cross-site scripting (XSS) vulnerabilities in Joomla! before 1.6.4 allow remote attackers to inject arbitrary web script or HTML via (1) the query string to the com_contact component, as demonstrated by the Itemid parameter to index.php; (2) the query string to the com_content component, as demonstrated by the filter_order parameter to index.php; (3) the query string to the com_newsfeeds component, as demonstrated by an arbitrary parameter to index.php; or (4) the option parameter in a reset.request action to index.php; and, when Internet Explorer or Konqueror is used, (5) allow remote attackers to inject arbitrary web script or HTML via the searchword parameter in a search action to index.php in the com_search component.
We have discovered 195,642 live websites that are affected by CVE-2011-2509.
| Product | |
| Category | Content Management System |
| Vulnerable Domains | 195,642 live websites (95% of Joomla install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 1 versions ( 0.97% of all versions) |
| 14,486 websites | |
| 51,181 websites | |
| 13,611 websites | |
| 12,086 websites | |
| 11,933 websites | |
| 10,934 websites | |
| 8,337 websites | |
| 6,542 websites | |
| 6,336 websites | |
| 4,738 websites |
| .com | 48,426 websites |
| .it | 33,475 websites |
| .ru | 11,465 websites |
| .pl | 8,465 websites |
| .org | 6,193 websites |
| .co.uk | 5,791 websites |
| .nl | 5,728 websites |
| .de | 5,403 websites |
| .com.au | 4,672 websites |
| .net | 4,423 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| *****************.de | *,*** | ||
| *******.**.ca | *,*** | ||
| ***********.**.za | **,*** | ||
| **************.se | **,*** | ||
| ***************.com | **,*** | ||
| *********.com | **,*** | ||
| *****.**.uk | **,*** | ||
| ************.com | **,*** | ||
| *********************.com | **,*** | ||
| ****.pl | **,*** |