7.5
CVSSv2

CVE-2013-1453

Published: 13/02/2013 Updated: 29/08/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

plugins/system/highlight/highlight.php in Joomla! 3.0.x up to and including 3.0.2 and 2.5.x up to and including 2.5.8 allows malicious users to unserialize arbitrary PHP objects to obtain sensitive information, delete arbitrary directories, conduct SQL injection attacks, and possibly have other impacts via the highlight parameter. Note: it was originally reported that this issue only allowed malicious users to obtain sensitive information, but later analysis demonstrated that other attacks exist.

Vulnerable Product Search on Vulmon Subscribe to Product

joomla joomla\\! 3.0.1

joomla joomla\\! 3.0.2

joomla joomla\\! 2.5.6

joomla joomla\\! 2.5.7

joomla joomla\\! 2.5.0

joomla joomla\\! 2.5.1

joomla joomla\\! 2.5.8

joomla joomla\\! 3.0.0

joomla joomla\\! 2.5.4

joomla joomla\\! 2.5.5

joomla joomla\\! 2.5.2

joomla joomla\\! 2.5.3

Exploits

------------------------------------------------------------------- Joomla! <= 302 (highlightphp) PHP Object Injection Vulnerability ------------------------------------------------------------------- [-] Software Link: wwwjoomlaorg/ [-] Affected Versions: Version 302 and earlier 30x versions Version 258 and earlier 25 ...
Joomla! versions 302 and below suffer from a PHP object injection vulnerability in highlightphp ...