GHSA-mxr8-pcpg-m23j

Suggest an improvement
Source
https://github.com/advisories/GHSA-mxr8-pcpg-m23j
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-mxr8-pcpg-m23j/GHSA-mxr8-pcpg-m23j.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-mxr8-pcpg-m23j
Aliases
  • CVE-2008-3228
Published
2022-05-01T23:57:57Z
Modified
2025-04-09T21:27:09.173272Z
Summary
Joomla! doesn't configure .htaccess to apply certain security checks that "block common exploits" to SEF URLs
Details

Joomla! before 1.5.4 does not configure .htaccess to apply certain security checks that "block common exploits" to SEF URLs, which has unknown impact and remote attack vectors.

Database specific
{
    "github_reviewed": true,
    "github_reviewed_at": "2025-04-09T20:50:33Z",
    "nvd_published_at": "2008-07-18T16:41:00Z",
    "severity": "MODERATE",
    "cwe_ids": []
}
References

Affected packages

Packagist / joomla/joomla-platform

Package

Name
joomla/joomla-platform
Purl
pkg:composer/joomla/joomla-platform

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.5.4

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-mxr8-pcpg-m23j/GHSA-mxr8-pcpg-m23j.json"