{"id":"GHSA-9qr2-fx2g-pfvh","summary":"Joomla! Open Redirect vulnerability","details":"Multiple open redirect vulnerabilities in Joomla! 1.5 before 1.5.7 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a \"passed in\" URL.","aliases":["CVE-2008-4104"],"modified":"2024-02-09T17:11:39.068300Z","published":"2022-05-02T00:06:48Z","database_specific":{"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2024-02-09T16:54:17Z","nvd_published_at":"2008-09-18T17:59:00Z","cwe_ids":["CWE-601"]},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2008-4104"},{"type":"WEB","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/45071"},{"type":"PACKAGE","url":"https://github.com/joomla/joomla-framework"},{"type":"WEB","url":"https://web.archive.org/web/20081219152017/http://developer.joomla.org/security/news/274-20080904-core-redirect-spam.html"},{"type":"WEB","url":"http://marc.info/?l=oss-security&m=122115344915232&w=2"},{"type":"WEB","url":"http://marc.info/?l=oss-security&m=122118210029084&w=2"},{"type":"WEB","url":"http://marc.info/?l=oss-security&m=122152798516853&w=2"},{"type":"WEB","url":"http://securityreason.com/securityalert/4275"}],"affected":[{"package":{"name":"joomla/framework","ecosystem":"Packagist","purl":"pkg:composer/joomla/framework"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"1.5.0"},{"fixed":"1.5.7"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-9qr2-fx2g-pfvh/GHSA-9qr2-fx2g-pfvh.json"}}],"schema_version":"1.9.0"}