Cross-site scripting (XSS) vulnerability in the Restaurant Guide (com_restaurantguide) component 1.0.0 for Joomla! allows remote attackers to inject arbitrary web script or HTML by placing it after a > (greater than) character.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
http://packetstormsecurity.org/1009-exploits/joomlarestaurantguide-sqlxsslfi.txt | exploit |
http://www.exploit-db.com/exploits/15040 | exploit |
http://securityreason.com/securityalert/8458 | third party advisory |