Subscribe to Joomla! Security Announcements - Click Here

Tue

09

Sep

2008

[20080903] - Core - com_mailto Spam
Tuesday, 09 September 2008 16:09
  • Project: Joomla!
  • SubProject: com_mailto
  • Severity: Low
  • Versions: 1.5.6 and all previous 1.5 releases
  • Exploit type: Email Spam 
  • Reported Date: 2008-August-29 
  • Fixed Date: 2008-September-9

Description

The mailto component does not verify validity of the URL prior to sending.

Affected Installs

All 1.5.x installs prior to and including 1.5.6 are affected.

Solution

Upgrade to latest Joomla! version (1.5.7 or newer).

Reported By Phil Taylor

Contact

The JSST at the Joomla! Security Center.

Last Updated on Tuesday, 09 September 2008 16:24