Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2019-6264

Quick assessment

Affected
n/a n/a
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Joomla! CMS是美国Open Source Matters团队开发的一套开源的内容管理系统(CMS)。该系统提供RSS馈送、网站搜索等功能。 Joomla! CMS 2.5.0版本至3.9.1版本中的mod_banners存在跨站脚本漏洞,该漏洞源于程序没有进行适当地转义。远程攻击者可利用该漏洞注入任意的Web脚本或HTML。

AI Predicted 6.1 Difficulty: Easy EPSS 0.96% · P58
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2019-6264

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: CVE Program / CVE List V5
Vulnerability Description
An issue was discovered in Joomla! before 3.9.2. Inadequate escaping in mod_banners leads to a stored XSS vulnerability.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Joomla! CMS 跨站脚本漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Joomla! CMS是美国Open Source Matters团队开发的一套开源的内容管理系统(CMS)。该系统提供RSS馈送、网站搜索等功能。 Joomla! CMS 2.5.0版本至3.9.1版本中的mod_banners存在跨站脚本漏洞,该漏洞源于程序没有进行适当地转义。远程攻击者可利用该漏洞注入任意的Web脚本或HTML。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
- n/a n/a -

II. Public POCs for CVE-2019-6264

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2019-6264

登录查看更多情报信息。

Vendor Advisories for CVE-2019-6264 (1)

Other References for CVE-2019-6264 (1)

Same Patch Batch · n/a · 2019-01-16 · 35 CVEs total

CVE-2019-6457 GNU Recutils 资源管理错误漏洞
CVE-2015-9279 MailEnable 跨站脚本漏洞
CVE-2015-9280 MailEnable 代码问题漏洞
CVE-2018-20723 Cacti 跨站脚本漏洞
CVE-2018-20724 Cacti 跨站脚本漏洞
CVE-2018-20725 Cacti 跨站脚本漏洞
CVE-2018-20726 Cacti 跨站脚本漏洞
CVE-2019-6455 GNU Recutils 安全漏洞
CVE-2019-6456 GNU Recutils 安全漏洞
CVE-2015-9278 MailEnable 信任管理漏洞
CVE-2019-6458 GNU Recutils 资源管理错误漏洞
CVE-2019-6459 GNU Recutils 资源管理错误漏洞
CVE-2019-6460 GNU Recutils 安全漏洞
CVE-2019-6461 Cairo 输入验证错误漏洞
CVE-2019-6462 Cairo 安全漏洞
CVE-2019-2413 Oracle Fusion Middleware Reports Developer 跨站脚本漏洞
CVE-2018-5736 ISC BIND 安全漏洞
CVE-2019-6446 NumPy 代码问题漏洞
CVE-2019-6439 wolfSSL benchmark工具缓冲区错误漏洞
CVE-2016-10737 Serendipity 跨站脚本漏洞

Showing top 20 of 35 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2019-6264

No comments yet


Leave a comment