The Joomla! Community Portal ™

JoomlaConnect

JoomlaConnect - Security English

(View All Languages)

Recent Posts

Jnews, 8.0.1

  • Report this


Jnews, 8.0.1 an earlier, XSS (Cross Site Scripting)

Keep reading about: Jnews, 8.0.1...
 

bo:VideoJS, 2.1.1,

  • Report this


bo:VideoJS, 2.1.1,     xss

From developerhttp://www.boeschung.de/en/joomla/bo-videojs/video-js-v320

Keep reading about: bo:VideoJS, 2.1.1,...
 

alfcontact

  • Report this


xss 230413

Keep reading about: alfcontact...
 

[20130407] - Core - XSS Vulnerability

  • Report this


  • Project: Joomla!
  • SubProject: All
  • Severity: Low
  • Versions: 2.5.9 and earlier 2.5.x versions. 3.0.3 and earlier 3.0.x versions.
  • Exploit type: XSS Vulnerability
  • Reported Date: 2013-April-17
  • Fixed Date: 2013-April-24
  • CVE Number: CVE-2013-3267

Description

Inadequate filtering leads to XSS vulnerability in highlighter plugin.

Affected Installs

Joomla! version 2.5.9 and earlier 2.5.x versions; and...

Keep reading about: [20130407] - Core - XSS Vulnerability...
 

[20130401] - Core - Privilege Escalation

  • Report this


  • Project: Joomla!
  • SubProject: All
  • Severity: Low
  • Versions: 2.5.9 and earlier 2.5.x versions. 3.0.3 and earlier 3.0.x versions.
  • Exploit type: Privilege Escalation
  • Reported Date: 2013-March-29
  • Fixed Date: 2013-April-24
  • CVE Number: CVE-2013-3056

Description

Inadequate permission checking allows unauthorised user to delete private messages.

Affected Installs

Joomla! version 2.5.9 and earlier...

Keep reading about: [20130401] - Core - Privilege Escalation...
 

[20130403] - Core - XSS Vulnerability

  • Report this


  • Project: Joomla!
  • SubProject: All
  • Severity: Moderate
  • Versions: 2.5.9 and earlier 2.5.x versions. 3.0.3 and earlier 3.0.x versions.
  • Exploit type: XSS Vulnerability
  • Reported Date: 2013-March-9
  • Fixed Date: 2013-April-24
  • CVE Number: CVE-2013-3058

Description

Inadequate filtering allows possibility of XSS exploit in some circumstances.

Affected Installs

Joomla! version 2.5.9 and earlier 2.5.x...

Keep reading about: [20130403] - Core - XSS Vulnerability...
 

[20130405] - Core - XSS Vulnerability

  • Report this


  • Project: Joomla!
  • SubProject: All
  • Severity: Low
  • Versions: 2.5.9 and earlier 2.5.x versions. 3.0.3 and earlier 3.0.x versions.
  • Exploit type: XSS Vulnerability
  • Reported Date: 2013-February-26
  • Fixed Date: 2013-April-24
  • CVE Number: CVE-2013-3059

Description

Inadequate filtering leads to XSS vulnerability in Voting plugin.

Affected Installs

Joomla! version 2.5.9 and earlier 2.5.x versions; and...

Keep reading about: [20130405] - Core - XSS Vulnerability...
 

[20130402] - Core - Information Disclosure

  • Report this


  • Project: Joomla!
  • SubProject: All
  • Severity: Low
  • Versions: 2.5.9 and earlier 2.5.x versions. 3.0.3 and earlier 3.0.x versions.
  • Exploit type: Information Disclosure
  • Reported Date: 2013-March-29
  • Fixed Date: 2013-April-24
  • CVE Number: CVE-2013-3057

Description

Inadequate permission checking allows unauthorised user to see permission settings in some circumstances.

Affected Installs

Joomla!...

Keep reading about: [20130402] - Core - Information Disclosure...
 

[20130406] - Core - DOS Vulnerability

  • Report this


  • Project: Joomla!
  • SubProject: All
  • Severity: Moderate
  • Versions: 2.5.9 and earlier 2.5.x versions. 3.0.3 and earlier 3.0.x versions.
  • Exploit type: Denial of service vulnerability
  • Reported Date: 2013-February-18
  • Fixed Date: 2013-April-24
  • CVE Number: CVE-2013-3242

Description

Object unserialize method leads to possible denial of service vulnerability.

Affected Installs

Joomla! version 2.5.9 and...

Keep reading about: [20130406] - Core - DOS Vulnerability...
 

[20130404] - Core - XSS Vulnerability

  • Report this


  • Project: Joomla!
  • SubProject: All
  • Severity: Low
  • Versions: 2.5.9 and earlier 2.5.x versions. 3.0.3 and earlier 3.0.x versions.
  • Exploit type: XSS Vulnerability
  • Reported Date: 2013-February-15
  • Fixed Date: 2013-April-24
  • CVE Number: None

Description

Use of old version of Flash-based file uploader leads to XSS vulnerability.

Affected Installs

Joomla! version 2.5.9 and earlier 2.5.x versions; and...

Keep reading about: [20130404] - Core - XSS Vulnerability...
 


To get your feed included in JoomlaConnect, see our page on getting connected.