[原文]The cross-site scripting (XSS) countermeasures in class.inputfilter.php in Joomla! 1.0.7 allow remote attackers to cause a denial of service via a crafted mosmsg parameter to index.php with a malformed sequence of multiple tags, as demonstrated using "<<>AAA<><>", possibly due to nested or empty tags.
Joomla! Poll System mosmsg Variable Malformed HTML Tag DoS
Remote / Network Access
Denial of Service,
Loss of Availability
Joomla! contains a flaw that may allow a remote denial of service. The issue is triggered when a remote attacker provides malformed HTML tags to the 'mosmsg' variable in the poll system. Due to an error in the anti cross site scripting (XSS) code in includes/phpInputFilter/class.inputfilter.php, such a request will cause a denial of service and may result in loss of availability for the system.
Upgrade to version 1.0.8 or higher, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.