GHSA-mxr8-pcpg-m23j
Dashboard / Vulnerabilities / GHSA-mxr8-pcpg-m23j
Summary: Joomla! doesn't configure .htaccess to apply certain security checks that "block common exploits" to SEF URLs
Details: Joomla! before 1.5.4 does not configure .htaccess to apply certain security checks that "block common exploits" to SEF URLs, which has unknown impact and remote attack vectors.
References: https://nvd.nist.gov/vuln/detail/CVE-2008-3228, https://exchange.xforce.ibmcloud.com/vulnerabilities/44206, https://github.com/joomla/joomla-platform, https://web.archive.org/web/20080730154423/http://www.joomla.org/content/view/5180/1, http://www.joomla.org/content/view/5180/1/1/1/#htaccess, http://www.openwall.com/lists/oss-security/2008/07/12/2
Affected packages
Package
Name: joomla/joomla-platform
Purl: pkg:composer/joomla/joomla-platform
Affected ranges
Type: ECOSYSTEM
Events:
