Del.icio.us Digg FURL FaceBook Stumble Upon Reddit SlashDot Ask BlinkBits BlinkList Co.mments Delirious Feed Me Links Google Bookmarks Linkagogo Ma.gnolia MSN Live Netscape Netvouz Newsvine RawSugar Rojo Smarking Socializer Sphinn Spurl Squidoo Tailrank Technorati Yahoo My Web
Tags: joomla, security, developer,
Post Reply 
 
Thread Rating:
  • 0 Votes - 0 Average
  • 1
  • 2
  • 3
  • 4
  • 5
Joomla! Developer Network - Security News
09-03-2011, 11:01 AM
Post: #1
Joomla! Developer Network - Security News

Joomla! Developer Network - Security News


Joomla! - the dynamic portal engine and content management system
  • [20120307] - Core - Information Disclosure

    Posted on: 3 April 2012, 1:21 am
    • Project: Joomla!
    • SubProject: All
    • Severity: Low
    • Versions: 2.5.3 and all earlier 2.5.x versions
    • Exploit type: Information Disclosure
    • Reported Date: 2012-January-7
    • Fixed Date: 2012-April-2

    Description


    Inadequate permission checking allows unauthorised viewing of some administrative back end information.

    Affected Installs


    Joomla! versions 2.5.3 and all earlier 2.5.x versions

    Solution


    Upgrade to version 2.5.4

    Reported by Cyrille Barthelemy

    Contact


    The JSST at the Joomla! Security Center.


  • [20120308] - Core - XSS Vulnerability

    Posted on: 3 April 2012, 1:21 am
    • Project: Joomla!
    • SubProject: All
    • Severity: Low
    • Versions: 2.5.3 and all earlier 2.5.x versions
    • Exploit type: XSS Vulnerability
    • Reported Date: 2012-February-3
    • Fixed Date: 2012-April-2

    Description


    Inadequate filtering in update manager leads to XSS vulnerability.

    Affected Installs


    Joomla! versions 2.5.3 and all earlier 2.5.x versions

    Solution


    Upgrade to version 2.5.4

    Reported by Alex Andreae

    Contact


    The JSST at the Joomla! Security Center.


  • [20120305] - Core - Password Change

    Posted on: 28 March 2012, 1:21 am
    • Project: Joomla!
    • SubProject: All
    • Severity: High
    • Versions: 1.5.25 and all earlier 1.5.x versions
    • Exploit type: Password Change
    • Reported Date: 2012-March-8
    • Fixed Date: 2012-March-27

    Description


    Insufficient randomness leads to password reset vulnerability.

    Affected Installs


    Joomla! versions 1.5.25 and all earlier 1.5.x versions

    Solution


    Upgrade to version 1.5.26

    Reported by George Argyros and Aggelos Kiayias

    Contact


    The JSST at the Joomla! Security Center.


  • [20120306] - Core - Information Disclosure

    Posted on: 28 March 2012, 1:21 am
    • Project: Joomla!
    • SubProject: All
    • Severity: Low
    • Versions: 1.5.25 and all earlier 1.5.x versions
    • Exploit type: Information Disclosure
    • Reported Date: 2012-January-7
    • Fixed Date: 2012-March-27

    Description


    Inadequate permission checking allows unauthorised viewing of administrative back end information.

    Affected Installs


    Joomla! versions 1.5.25 and all earlier 1.5.x versions

    Solution


    Upgrade to version 1.5.26

    Reported by Cyrille Barthelemy

    Contact


    The JSST at the Joomla! Security Center.


  • [20120304] - Core - Password Change

    Posted on: 16 March 2012, 1:21 am
    • Project: Joomla!
    • SubProject: All
    • Severity: High
    • Versions: 2.5.2, 2.5.1, 2.5.0, and all 1.7.x and 1.6.x releases
    • Exploit type: Password Change
    • Reported Date: 2012-March-8
    • Fixed Date: 2012-March-15

    Description


    Insufficient randomness leads to password reset vulnerability.

    Affected Installs


    Joomla! versions 2.5.2, 2.5.1, 2.5.0, and all 1.7.x and 1.6.x versions

    Solution


    Upgrade to version 2.5.3

    Reported by George Argyros and Aggelos Kiayias

    Contact


    The JSST at the Joomla! Security Center.


  • [20120303] - Core - Privilege Escalation

    Posted on: 15 March 2012, 6:00 am
    • Project: Joomla!
    • SubProject: All
    • Severity: High
    • Versions: 2.5.2, 2.5.1, 2.5.0, and all 1.7.x and 1.6.x releases
    • Exploit type: Privilege Escalation
    • Reported Date: 2012-March-12
    • Fixed Date: 2012-March-15

    Description


    Programming error allows privilege escalation in some cases.

    Affected Installs


    Joomla! versions 2.5.2, 2.5.1, 2.5.0, and all 1.7.x and 1.6.x versions

    Solution


    Upgrade to version 2.5.3

    Reported by Jeff Channel

    Contact


    The JSST at the Joomla! Security Center.


  • [20120301] - Core - SQL Injection

    Posted on: 5 March 2012, 7:00 am
    • Project: Joomla!
    • SubProject: All
    • Severity: High
    • Versions: 2.5.1, 2.5.0 and 1.7.0 - 1.7.5
    • Exploit type: SQL Injection
    • Reported Date: 2012-February-29
    • Fixed Date: 2012-March-05

    Description


    Inadequate escaping leads to SQL injection vulnerability.

    Affected Installs


    Joomla! version 2.5.1, 2.5.0, 1.7.4, and all earlier 1.7.x versions

    Solution


    Upgrade to version 2.5.2

    Reported by Ching Shiong Sow, Stratsec

    Contact


    The JSST at the Joomla! Security Center.


  • [20120302] - Core - XSS Vulnerability

    Posted on: 5 March 2012, 7:00 am
    • Project: Joomla!
    • SubProject: All
    • Severity: Moderate
    • Versions: 2.5.1 and 2.5.0
    • Exploit type: XSS Vulnerability
    • Reported Date: 2012-February-29
    • Fixed Date: 2012-March-05

    Description


    Inadequate filtering leads to XSS vulnerability.

    Affected Installs


    Joomla! version 2.5.1 and 2.5.0.

    Solution


    Upgrade to version 2.5.2

    Reported by Phil Purviance

    Contact


    The JSST at the Joomla! Security Center.


  • [20120202] - Core - Information Disclosure

    Posted on: 1 February 2012, 10:25 pm
    • Project: Joomla!
    • SubProject: All
    • Severity: Moderate
    • Versions: 1.7.4 and all earlier 1.7.x versions
    • Exploit type: Information Disclosure
    • Reported Date: 2012-January-06
    • Fixed Date: 2012-February-02

    Description


    On some servers the error log could be read by unauthorised users.

    Affected Installs


    Joomla! version 1.7.4 and all earlier 1.7.x versions

    Solution


    Upgrade to version 2.5.1 or 1.7.5 or higher

    Reported by Alain Rivest

    Contact


    The JSST at the Joomla! Security Center.


  • [20120203] - Core - Information Disclosure

    Posted on: 1 February 2012, 10:25 pm
    • Project: Joomla!
    • SubProject: All
    • Severity: Low
    • Versions: 2.5.0 and 1.7.0 - 1.7.4
    • Exploit type: Information Disclosure
    • Reported Date: 2012-January-29
    • Fixed Date: 2012-February-02

    Description


    Inadequate validation leads to path disclosure in administrator.

    Affected Installs


    Joomla! version 2.5.0, 1.7.4, and all earlier 1.7.x versions

    Solution


    Upgrade to version 2.5.1 or 1.7.5 or higher

    Reported by Jakub Galczyk

    Contact


    The JSST at the Joomla! Security Center.



Xem thêm:

http://docs.joomla.org/Vulnerable_Extensions_List

Support us [Image: btn_donateCC_LG.gif]
Find all posts by this user
Quote this message in a reply
Post Reply 


Possibly Related Threads...
Thread: Author Replies: Views: Last Post
  Web Developer Lists : eConsultant Mr. Nguyen 3 1,125 20-03-2011 12:41 AM
Last Post: koc12hi
  Latest news from Joomla Editor Blog thanhlongx4 2 1,026 18-03-2011 12:24 PM
Last Post: leoanderson1
  Latest Joomla tutorials from howtojoomla.net thanhlongx4 0 535 24-02-2011 08:54 PM
Last Post: thanhlongx4
  Latest Joomla extensions - Joomla 1.6.* thanhlongx4 0 2,265 17-02-2011 09:15 AM
Last Post: thanhlongx4
  Latest Joomla extensions - Joomla 1.5.* thanhlongx4 0 2,076 17-02-2011 09:10 AM
Last Post: thanhlongx4

Forum Jump:


User(s) browsing this thread: 1 Guest(s)

 Quick Theme: