Multiple cross-site scripting (XSS) vulnerabilities in Joomla! before 1.7.0 allow remote attackers to inject arbitrary web script or HTML via (1) the URI to includes/application.php, reachable through index.php; and, when Internet Explorer or Konqueror is used, (2) allow remote attackers to inject arbitrary web script or HTML via the searchword parameter in a search action to index.php in the com_search component. NOTE: vector 2 exists because of an incomplete fix for CVE-2011-2509.5.
We have discovered 269,324 live websites that are affected by CVE-2011-2710.
Product | |
Category | Content Management System |
Vulnerable Domains | 269,324 live websites (96.96% of Joomla install base) |
Vulnerable Versions |
|
Vulnerable Versions Count | 5 versions ( 2.98% of all versions) |
![]() | 15,650 websites |
![]() | 66,475 websites |
![]() | 24,778 websites |
![]() | 16,650 websites |
![]() | 13,922 websites |
![]() | 13,653 websites |
![]() | 12,647 websites |
![]() | 11,490 websites |
![]() | 9,178 websites |
![]() | 8,919 websites |
.com | 65,530 websites |
.it | 43,653 websites |
.com.au | 17,023 websites |
.ru | 11,702 websites |
.pl | 9,044 websites |
.co.uk | 8,967 websites |
.org | 7,412 websites |
.nl | 6,830 websites |
.de | 6,636 websites |
.net | 5,799 websites |
Domain | Country | Rank | Contacts |
---|---|---|---|
*****************.de | ![]() | *,*** | |
*******.**.ca | ![]() | *,*** | |
**************.********.com | ![]() | **,*** | |
***********.com | ![]() | **,*** | |
***********.**.za | ![]() | **,*** | |
********.com | ![]() | **,*** | |
***************.com | ![]() | **,*** | |
********.com | ![]() | **,*** | |
*********.com | ![]() | **,*** | |
*****.**.uk | ![]() | **,*** |