CVE-2007-4187 describes multiple eval injection vulnerabilities in the com_search component of Joomla! 1.5 beta versions prior to RC1 (Mapya). Remote attackers can exploit this by injecting arbitrary PHP code via the searchword parameter, specifically affecting default_results.php within the search component's templates. With a CVSS score of 7.5, this vulnerability is considered highly severe, allowing for complete compromise of confidentiality, integrity, and availability with low attack complexity and no authentication required. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.5.0_betaCPE matchmatch criteria | cpe:2.3:a:joomla:joomla:1.5.0_beta:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:P/A:P
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.