CVE-2008-6882

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
30/07/2009
Last modified:
09/04/2025

Description

Live Chat (com_livechat) component 1.0 for Joomla! allows remote attackers to use the xmlhttp.php script as an open HTTP proxy to hide network scanning activities or scan internal networks via a GET request with a full URL in the query string.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:joomla:joomla:*:*:*:*:*:*:*:*
cpe:2.3:a:joompolitan:com_livechat:1.0:*:*:*:*:*:*:*