Incapsula Component for Joomla! 'token' Parameter Multiple XSS
Medium Nessus Plugin ID 64484
SynopsisThe remote web server contains a PHP application that is affected by multiple cross-site scripting vulnerabilities.
DescriptionThe version of the Incapsula component for Joomla! running on the remote host is affected by multiple cross-site scripting (XSS) vulnerabilities in the Security.php and Performance.php scripts due to improper sanitization of user-supplied input to the 'token' parameter before using it to generate dynamic HTML content. An unauthenticated, remote attacker can exploit this to inject arbitrary HTML and script code into the user's browser session.
SolutionUpgrade to Joomla! version 1.4.6_c or later.