Cross-site scripting (XSS) vulnerability in index.php in the beamospetition (com_beamospetition) 1.0.12 component for Joomla! allows remote attackers to inject arbitrary web script or HTML via the pet parameter in a sign action.
📦
com_beamospetition
Vendor: joomla
Actively Exploited
0
CISA KEV List
PoC / Exploits
3
Code Available
Total RCEs
0
Remote Access
Total CVEs
3
Total Indexed
Avg. EPSS
0.09%
Exploit Prob.
Security Vulnerability Index
Page 1 / 1
4.3
CVSS
CVE-2009-0378
Exploit Found
Severity: MEDIUM
7.5
CVSS
CVE-2009-0377
Exploit Found
SQL injection vulnerability in the beamospetition (com_beamospetition) 1.0.12 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the mpid parameter in a sign action to index.php, a different vector than CVE-2008-3132.
Severity: HIGH
7.5
CVSS
CVE-2008-3132
Exploit Found
SQL injection vulnerability in the beamospetition (com_beamospetition) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the pet parameter to index.php.
Severity: HIGH