The Joomla! Community Portal ™

JoomlaConnect

JoomlaConnect - Security English

(View All Languages)

Recent Posts

[20120307] - Core - Information Disclosure

  • Report this


  • Project: Joomla!
  • SubProject: All
  • Severity: Low
  • Versions: 2.5.3 and all earlier 2.5.x versions
  • Exploit type: Information Disclosure
  • Reported Date: 2012-January-7
  • Fixed Date: 2012-April-2

Description

Inadequate permission checking allows unauthorised viewing of some administrative back end information.

Affected Installs

Joomla! versions 2.5.3 and all earlier 2.5.x versions

Solution

Upgrade to...

Keep reading about: [20120307] - Core - Information Disclosure...
 

[20120308] - Core - XSS Vulnerability

  • Report this


  • Project: Joomla!
  • SubProject: All
  • Severity: Low
  • Versions: 2.5.3 and all earlier 2.5.x versions
  • Exploit type: XSS Vulnerability
  • Reported Date: 2012-February-3
  • Fixed Date: 2012-April-2

Description

Inadequate filtering in update manager leads to XSS vulnerability.

Affected Installs

Joomla! versions 2.5.3 and all earlier 2.5.x versions

Solution

Upgrade to version 2.5.4

Reported by Alex...

Keep reading about: [20120308] - Core - XSS Vulnerability...
 

[20120305] - Core - Password Change

  • Report this


  • Project: Joomla!
  • SubProject: All
  • Severity: High
  • Versions: 1.5.25 and all earlier 1.5.x versions
  • Exploit type: Password Change
  • Reported Date: 2012-March-8
  • Fixed Date: 2012-March-27

Description

Insufficient randomness leads to password reset vulnerability.

Affected Installs

Joomla! versions 1.5.25 and all earlier 1.5.x versions

Solution

Upgrade to version 1.5.26

Reported by George Argyros and...

Keep reading about: [20120305] - Core - Password Change...
 

[20120306] - Core - Information Disclosure

  • Report this


  • Project: Joomla!
  • SubProject: All
  • Severity: Low
  • Versions: 1.5.25 and all earlier 1.5.x versions
  • Exploit type: Information Disclosure
  • Reported Date: 2012-January-7
  • Fixed Date: 2012-March-27

Description

Inadequate permission checking allows unauthorised viewing of administrative back end information.

Affected Installs

Joomla! versions 1.5.25 and all earlier 1.5.x versions

Solution

Upgrade to...

Keep reading about: [20120306] - Core - Information Disclosure...
 

[20120304] - Core - Password Change

  • Report this


  • Project: Joomla!
  • SubProject: All
  • Severity: High
  • Versions: 2.5.2, 2.5.1, 2.5.0, and all 1.7.x and 1.6.x releases
  • Exploit type: Password Change
  • Reported Date: 2012-March-8
  • Fixed Date: 2012-March-15

Description

Insufficient randomness leads to password reset vulnerability.

Affected Installs

Joomla! versions 2.5.2, 2.5.1, 2.5.0, and all 1.7.x and 1.6.x versions

Solution

Upgrade to version...

Keep reading about: [20120304] - Core - Password Change...
 

[20120303] - Core - Privilege Escalation

  • Report this


  • Project: Joomla!
  • SubProject: All
  • Severity: High
  • Versions: 2.5.2, 2.5.1, 2.5.0, and all 1.7.x and 1.6.x releases
  • Exploit type: Privilege Escalation
  • Reported Date: 2012-March-12
  • Fixed Date: 2012-March-15

Description

Programming error allows privilege escalation in some cases.

Affected Installs

Joomla! versions 2.5.2, 2.5.1, 2.5.0, and all 1.7.x and 1.6.x versions

Solution

Upgrade to version...

Keep reading about: [20120303] - Core - Privilege Escalation...
 

[20120302] - Core - XSS Vulnerability

  • Report this


  • Project: Joomla!
  • SubProject: All
  • Severity: Moderate
  • Versions: 2.5.1 and 2.5.0
  • Exploit type: XSS Vulnerability
  • Reported Date: 2012-February-29
  • Fixed Date: 2012-March-05

Description

Inadequate filtering leads to XSS vulnerability.

Affected Installs

Joomla! version 2.5.1 and 2.5.0.

Solution

Upgrade to version 2.5.2

Reported by Michael Babker

Contact

The JSST at the Joomla! Security Center.

Keep reading about: [20120302] - Core - XSS Vulnerability...
 

[20120301] - Core - SQL Injection

  • Report this


  • Project: Joomla!
  • SubProject: All
  • Severity: High
  • Versions: 2.5.1, 2.5.0 and 1.7.0 - 1.7.4
  • Exploit type: SQL Injection
  • Reported Date: 2012-February-29
  • Fixed Date: 2012-March-05

Description

Inadequate escaping leads to SQL injection vulnerability.

Affected Installs

Joomla! version 2.5.1, 2.5.0, 1.7.4, and all earlier 1.7.x versions

Solution

Upgrade to version 2.5.2

Reported by Colin...

Keep reading about: [20120301] - Core - SQL Injection...
 

[20120202] - Core - Information Disclosure

  • Report this


  • Project: Joomla!
  • SubProject: All
  • Severity: Moderate
  • Versions: 1.7.4 and all earlier 1.7.x versions
  • Exploit type: Information Disclosure
  • Reported Date: 2012-January-06
  • Fixed Date: 2012-February-02

Description

On some servers the error log could be read by unauthorised users.

Affected Installs

Joomla! version 1.7.4 and all earlier 1.7.x versions

Solution

Upgrade to version 2.5.1 or 1.7.5 or...

Keep reading about: [20120202] - Core - Information Disclosure...
 

[20120203] - Core - Information Disclosure

  • Report this


  • Project: Joomla!
  • SubProject: All
  • Severity: Low
  • Versions: 2.5.0 and 1.7.0 - 1.7.4
  • Exploit type: Information Disclosure
  • Reported Date: 2012-January-29
  • Fixed Date: 2012-February-02

Description

Inadequate validation leads to path disclosure in administrator.

Affected Installs

Joomla! version 2.5.0, 1.7.4, and all earlier 1.7.x versions

Solution

Upgrade to version 2.5.1 or 1.7.5 or...

Keep reading about: [20120203] - Core - Information Disclosure...
 


To get your feed included in JoomlaConnect, see our page on getting connected.