PDA

View Full Version : Attention Joomla Users


Highlight_Photography
13th of July 2009 (Mon), 07:35
Hi All,

Thought I'd give all Joomla users a heads up on a current security risk affecting 1.5.11 and below. The latest version 1.5.12 fix's this problem so please update to latest version.

[20090606] - Core - Missing JEXEC Check

* Project: Joomla!
* SubProject: Admin client
* Severity: Moderate
* Versions: 1.5.11 and all previous 1.5 releases
* Exploit type: XSS
* Reported Date: 2009-June-22
* Fixed Date: 2009-June-30

Description

Some files were missing the check for JEXEC.� These scripts will then expose internal path information of the host.
Affected Installs

All 1.5.x installs prior to and including 1.5.11 are affected.
Solution

Upgrade to latest Joomla! version (1.5.12 or newer)

Highlight_Photography
27th of July 2009 (Mon), 00:08
The Joomla Project announces the immediate availability of Joomla 1.5.13 [Wojmamni ama baji]. This is a security release and users are strongly encouraged to upgrade immediately.

This release contains 26 bug fixes, two moderate-level security fixes and one low-level security fix. It has been 3 weeks since Joomla 1.5.12 was released on July 1, 2009. The Development Working Group's goal is to continue to provide regular, frequent updates to the Joomla community.