CVE Reference: CVE-2010-2046

NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2010-2046

Description:
Multiple cross-site scripting (XSS) vulnerabilities in the ActiveHelper LiveHelp (com_activehelper_livehelp) component 2.0.3 for Joomla! allow remote attackers to inject arbitrary web script or HTML via (1) the DOMAINID parameter to server/cookies.php or (2) the SERVER parameter to server/index.php.

CVE Status:
Candidate

References:

SAID
  Secunia Advisory: SA39870

MISC
  http://packetstormsecurity.org/1005-exploits/joomlaactivehelper-xss.txt
  http://www.xenuser.org/2010/05/19/joomla-component-activehelper-livehelp-xss-vulnerabilities/
  http://xenuser.org/documents/security/joomla_com_activehelper_livehelp_xss.txt

BID
  40278


Return to the previous page.