HomeMINISTERIOSExpresionesJoomla! Security News

Newsfeeds Joomla! Developer Network - Security News

Joomla! - the dynamic portal engine and content management system
  • [20120307] - Core - Information Disclosure
    • Project: Joomla!
    • SubProject: All
    • Severity: Low
    • Versions: 2.5.3 and all earlier 2.5.x versions
    • Exploit type: Information Disclosure
    • Reported Date: 2012-January-7
    • Fixed Date: 2012-April-2

    Description

    Inadequate permission checking allows unauthorised viewing of some administrative back end information.

    Affected Installs

    Joomla! versions 2.5.3 and all earlier 2.5.x versions

    Solution

    Upgrade to version 2.5.4

    Reported by Cyrille Barthelemy

    Contact

    The JSST at the Joomla! Security Center.



  • [20120308] - Core - XSS Vulnerability
    • Project: Joomla!
    • SubProject: All
    • Severity: Low
    • Versions: 2.5.3 and all earlier 2.5.x versions
    • Exploit type: XSS Vulnerability
    • Reported Date: 2012-February-3
    • Fixed Date: 2012-April-2

    Description

    Inadequate filtering in update manager leads to XSS vulnerability.

    Affected Installs

    Joomla! versions 2.5.3 and all earlier 2.5.x versions

    Solution

    Upgrade to version 2.5.4

    Reported by Alex Andreae

    Contact

    The JSST at the Joomla! Security Center.



  • [20120305] - Core - Password Change
    • Project: Joomla!
    • SubProject: All
    • Severity: High
    • Versions: 1.5.25 and all earlier 1.5.x versions
    • Exploit type: Password Change
    • Reported Date: 2012-March-8
    • Fixed Date: 2012-March-27

    Description

    Insufficient randomness leads to password reset vulnerability.

    Affected Installs

    Joomla! versions 1.5.25 and all earlier 1.5.x versions

    Solution

    Upgrade to version 1.5.26

    Reported by George Argyros and Aggelos Kiayias

    Contact

    The JSST at the Joomla! Security Center.



  • [20120306] - Core - Information Disclosure
    • Project: Joomla!
    • SubProject: All
    • Severity: Low
    • Versions: 1.5.25 and all earlier 1.5.x versions
    • Exploit type: Information Disclosure
    • Reported Date: 2012-January-7
    • Fixed Date: 2012-March-27

    Description

    Inadequate permission checking allows unauthorised viewing of administrative back end information.

    Affected Installs

    Joomla! versions 1.5.25 and all earlier 1.5.x versions

    Solution

    Upgrade to version 1.5.26

    Reported by Cyrille Barthelemy

    Contact

    The JSST at the Joomla! Security Center.



  • [20120304] - Core - Password Change
    • Project: Joomla!
    • SubProject: All
    • Severity: High
    • Versions: 2.5.2, 2.5.1, 2.5.0, and all 1.7.x and 1.6.x releases
    • Exploit type: Password Change
    • Reported Date: 2012-March-8
    • Fixed Date: 2012-March-15

    Description

    Insufficient randomness leads to password reset vulnerability.

    Affected Installs

    Joomla! versions 2.5.2, 2.5.1, 2.5.0, and all 1.7.x and 1.6.x versions

    Solution

    Upgrade to version 2.5.3

    Reported by George Argyros and Aggelos Kiayias

    Contact

    The JSST at the Joomla! Security Center.



Go to top

Escúchanos En Línea

Ultimate Browsers SupportUna gran variedad de enseñanzas bíblicas están disponibles en línea para tu crecimiento. Es tiempo de ser transformados mediante la Palabra de Dios.

Download Now...

Mensaje De Nuetro Pastor

Native RTL SupportReciban un gran saludo y mucha bendición en el nombre de Jesús. Sé que por la Gracia de nuestro Dios, todos los recursos que ponemos a su alcance serán de mucha utilidad y ayudaran a su transformación.

Read more...