|
Joomla! Developer Network - Security News
|
Joomla! - the dynamic portal engine and content management system
|
-
[20120202] - Core - Information Disclosure
ul
listrongProject:/strong Joomla!/li
listrongSubProject:/strong All/li
listrong Severity:/strong Moderate/li
listrongVersions:/strong 1.7.4 and all earlier 1.7.x versions/li
listrongExploit type:/strong Information Disclosure/li
listrongReported Date:/strong 2012-January-06/li
listrongFixed Date:/strong 2012-February-02/li
/ul
h2Description/h2
pOn some servers the error log could be read by unauthorised users./p
h2Affected Installs/h2
pJoomla! version 1.7.4 and all earlier 1.7.x versions/p
h2Solution/h2
pUpgrade to version 2.5.1 or 1.7.5 or higher/p
pReported by Alain Rivest/p
h2Contact/h2
pThe JSST at the Joomla! Security Center./pdiv
a href="http://feeds.joomla.org/~ff/JoomlaSecurityNews?a=MFhhodAeXho:TcD6ohzsuCc:yIl2AUoC8zA"img src="http://feeds.feedburner.com/~ff/JoomlaSecurityNews?d=yIl2AUoC8zA" border="0"/img/a
/divimg src="http://feeds.feedburner.com/~r/JoomlaSecurityNews/~4/MFhhodAeXho" height="1" width="1"/
-
[20120203] - Core - Information Disclosure
ul
listrongProject:/strong Joomla!/li
listrongSubProject:/strong All/li
listrong Severity:/strong Low/li
listrongVersions:/strong 2.5.0 and 1.7.0 - 1.7.4/li
listrongExploit type:/strong Information Disclosure/li
listrongReported Date:/strong 2012-January-29/li
listrongFixed Date:/strong 2012-February-02/li
/ul
h2Description/h2
pInadequate validation leads to path disclosure in administrator./p
h2Affected Installs/h2
pJoomla! version 2.5.0, 1.7.4, and all earlier 1.7.x versions/p
h2Solution/h2
pUpgrade to version 2.5.1 or 1.7.5 or higher/p
pReported by Jakub Galczyk/p
h2Contact/h2
pThe JSST at the Joomla! Security Center./pdiv
a href="http://feeds.joomla.org/~ff/JoomlaSecurityNews?a=LY07jV4Rnvs:YgvDxlGAUzQ:yIl2AUoC8zA"img src="http://feeds.feedburner.com/~ff/JoomlaSecurityNews?d=yIl2AUoC8zA" border="0"/img/a
/divimg src="http://feeds.feedburner.com/~r/JoomlaSecurityNews/~4/LY07jV4Rnvs" height="1" width="1"/
-
[20120201] - Core - Information Disclosure
ul
listrongProject:/strong Joomla!/li
listrongSubProject:/strong All/li
listrong Severity:/strong Low/li
listrongVersions:/strong 2.5.0 and 1.7.0 - 1.7.4/li
listrongExploit type:/strong Information Disclosure/li
listrongReported Date:/strong 2012-January-29/li
listrongFixed Date:/strong 2012-February-02/li
/ul
h2Description/h2
pInadequate validation leads to information disclosure in administrator./p
h2Affected Installs/h2
pJoomla! version 2.5.0, 1.7.4, and all earlier 1.7.x versions/p
h2Solution/h2
pUpgrade to version 1.7.5 or 2.5.1 or higher/p
pReported by Jakub Galczyk/p
h2Contact/h2
pThe JSST at the Joomla! Security Center./pdiv
a href="http://feeds.joomla.org/~ff/JoomlaSecurityNews?a=PkBR45UJQxo:tozT3WXEdn0:yIl2AUoC8zA"img src="http://feeds.feedburner.com/~ff/JoomlaSecurityNews?d=yIl2AUoC8zA" border="0"/img/a
/divimg src="http://feeds.feedburner.com/~r/JoomlaSecurityNews/~4/PkBR45UJQxo" height="1" width="1"/
-
[20120103] - Core - Information Disclosure
ul
listrongProject:/strong Joomla!/li
listrongSubProject:/strong All/li
listrongSeverity:/strong Low/li
listrongVersions:/strong 1.7.3 and all earlier 1.7 and 1.6 versions/li
listrongExploit type:/strong Information Disclosure/li
listrongReported Date:/strong 2011-December-19/li
listrongFixed Date:/strong 2012-January-24/li
/ul
h2Description/h2
pInadequate filtering leads to information disclosure./p
h2Affected Installs/h2
pJoomla! version 1.7.3 and all earlier versions/p
h2Solution/h2
pUpgrade to version 1.7.4 or 2.5.0 or higher/p
pReported by Jean-Marie Simonet/p
h2Contact/h2
pThe JSST at the Joomla! Security Center./pdiv
a href="http://feeds.joomla.org/~ff/JoomlaSecurityNews?a=Ed0TMAvyQ4g:blmC1ASORQc:yIl2AUoC8zA"img src="http://feeds.feedburner.com/~ff/JoomlaSecurityNews?d=yIl2AUoC8zA" border="0"/img/a
/divimg src="http://feeds.feedburner.com/~r/JoomlaSecurityNews/~4/Ed0TMAvyQ4g" height="1" width="1"/
-
[20120101] - Core - Information Disclosure
ul
listrongProject:/strong Joomla!/li
listrongSubProject:/strong All/li
listrong Severity:/strong Low/li
listrongVersions:/strong 1.7.3 and all earlier 1.7 and 1.6 versions/li
listrongExploit type:/strong Information Disclosure/li
listrongReported Date:/strong 2012-January-07/li
listrongFixed Date:/strong 2012-January-24/li
/ul
h2Description/h2
pInadequate filtering leads to information disclosure./p
h2Affected Installs/h2
pJoomla! version 1.7.3 and all earlier versions/p
h2Solution/h2
pUpgrade to version 1.7.4 or 2.5.0 or higher/p
pReported by Cyrille Barthelemy/p
h2Contact/h2
pThe JSST at the Joomla! Security Center./pdiv
a href="http://feeds.joomla.org/~ff/JoomlaSecurityNews?a=MYKnZ2QJKYE:LuZxJDgem44:yIl2AUoC8zA"img src="http://feeds.feedburner.com/~ff/JoomlaSecurityNews?d=yIl2AUoC8zA" border="0"/img/a
/divimg src="http://feeds.feedburner.com/~r/JoomlaSecurityNews/~4/MYKnZ2QJKYE" height="1" width="1"/
|