Incapsula Component for Joomla! 'token' Parameter Multiple XSS

This script is Copyright (C) 2013-2017 Tenable Network Security, Inc.


Synopsis :

The remote web server contains a PHP application that is affected by
multiple cross-site scripting vulnerabilities.

Description :

The version of the Incapsula component for Joomla! running on the
remote host is affected by multiple cross-site scripting (XSS)
vulnerabilities in the Security.php and Performance.php scripts due to
improper sanitization of user-supplied input to the 'token' parameter
before using it to generate dynamic HTML content. An unauthenticated,
remote attacker can exploit this to inject arbitrary HTML and script
code into the user's browser session.

See also :

http://www.zeroscience.mk/en/vulnerabilities/ZSL-2013-5121.php

Solution :

Upgrade to Joomla! version 1.4.6_c or later.

Risk factor :

Medium / CVSS Base Score : 4.3
(CVSS2#AV:N/AC:M/Au:N/C:N/I:P/A:N)
CVSS Temporal Score : 3.6
(CVSS2#E:F/RL:OF/RC:ND)
Public Exploit Available : true

Family: CGI abuses : XSS

Nessus Plugin ID: 64484 ()

Bugtraq ID: 57190

CVE ID:

Ready to Amp Up Your Nessus Experience?

Get Nessus Professional to scan unlimited IPs, run compliance checks & more

Buy Nessus Professional Now