Joomla Security News
RSS-News aus dem Joomla-Security-Center.
RSS-News aus dem Joomla-Security-Center.
Back-end user can inject Javascript in various administrator screens.
All 1.5.x installs prior to and including 1.5.19 are affected.
Upgrade to the latest Joomla! version (1.5.20 or later)
Reported by Mesut Timur.
The JSST at the Joomla! Security Center.
Back-end user can inject Javascript in various administrator screens.
All 1.5.x installs prior to and including 1.5.19 are affected.
Upgrade to the latest Joomla! version (1.5.20 or later)
Reported by José Antonio Vázquez González
The JSST at the Joomla! Security Center.
Back-end user can inject Javascript in various administrator screens.
All 1.5.x installs prior to and including 1.5.19 are affected.
Upgrade to the latest Joomla! version (1.5.20 or later)
Reported by José Antonio Vázquez González
The JSST at the Joomla! Security Center.
Back-end user can create MySQL error which shows internal path information in the error message.
All 1.5.x installs prior to and including 1.5.19 are affected.
Upgrade to the latest Joomla! version (1.5.20 or later)
Reported by Andy Gorges
The JSST at the Joomla! Security Center.
Back-end user can inject javascript in various administrator screens.
All 1.5.x installs prior to and including 1.5.17 are affected.
Upgrade to the latest Joomla! version (1.5.18 or later)
Reported by Riyaz Ahemed
The JSST at the Joomla! Security Center.
If a user entered a URL with a negative query limit or offset, a PHP notice would display revealing information about the system.
All 1.5.x installs prior to and including 1.5.15 are affected.
Upgrade to the latest Joomla! version (1.5.16 or later)
Reported by Security List
The JSST at the Joomla! Security Center.
The migration script in the Joomla! installer does not check the file type being uploaded. If the installation application is present, an attacker could use it to upload malicious files to a server.
All 1.5.x installs prior to and including 1.5.15 are affected.
Upgrade to the latest Joomla! version (1.5.16 or later)
Reported by Nicola Bettini
The JSST at the Joomla! Security Center.
Session id doesn’t get modified when user logs in. A remote site may be able to forward a visitor to the Joomla! site and set a specific cookie. If the user then logs in, the remote site can use that cookie to authenticate as that user.
All 1.5.x installs prior to and including 1.5.15 are affected.
Upgrade to the latest Joomla! version (1.5.16 or later)
Reported by Raúl Siles and Steven Pignataro
The JSST at the Joomla! Security Center.[20100423] – Core – Password Reset Tokens
When a user requests a password reset, the reset tokens were stored in plain text in the database. While this is not a vulnerability in itself, it allows user accounts to be compromised if there is an extension on the site with an SQL injection vulnerability.
All 1.5.x installs prior to and including 1.5.15 are affected.
Upgrade to the latest Joomla! version (1.5.16 or later)
Reported by Madis Abel
The JSST at the Joomla! Security Center.
When logged into the front end with Author access, it was possible to replace an article written by another user.
All 1.5.x installs prior to and including 1.5.14 are affected.
Upgrade to latest Joomla! version (1.5.15 or newer).
Reported by Hannes Papenberg
The JSST at the Joomla! Security Center.