Multiple cross-site scripting (XSS) vulnerabilities in Joomla! before 1.7.0 allow remote attackers to inject arbitrary web script or HTML via (1) the URI to includes/application.php, reachable through index.php; and, when Internet Explorer or Konqueror is used, (2) allow remote attackers to inject arbitrary web script or HTML via the searchword parameter in a search action to index.php in the com_search component. NOTE: vector 2 exists because of an incomplete fix for CVE-2011-2509.5.
We have discovered 118,612 live websites that are affected by CVE-2011-2710.
| Product | |
| Category | Content Management System |
| Vulnerable Domains | 118,612 live websites (92% of Joomla install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 1 versions ( 0.78% of all versions) |
| 6,411 websites | |
| 31,620 websites | |
| 11,935 websites | |
| 6,518 websites | |
| 6,433 websites | |
| 5,069 websites | |
| 4,616 websites | |
| 4,538 websites | |
| 3,860 websites | |
| 3,587 websites |
| .com | 25,861 websites |
| .it | 21,080 websites |
| .ru | 9,867 websites |
| .nl | 3,484 websites |
| .de | 3,155 websites |
| .se | 2,967 websites |
| .org | 2,877 websites |
| .co.uk | 2,654 websites |
| .net | 2,302 websites |
| .cz | 2,115 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| *****************.de | *,*** | ||
| *******.**.ca | *,*** | ||
| *****.com | **,*** | ||
| ***********.com | **,*** | ||
| ***********.**.za | **,*** | ||
| ***************.com | **,*** | ||
| *********.kz | **,*** | ||
| *********.com | **,*** | ||
| ************.com | **,*** | ||
| *********************.com | **,*** |