|
Subscribe to Joomla! Security Announcements - Click Here |
Tue 09 Sep 2008 |
|
DescriptionSeveral components utilize a passed in URL to redirect to after processing. These URLs are not validated prior to the redirect. A crafted URL can cause the system to redirect to a spam or phishing site. 3PD Concerns3pd extensions should validate all redirects (where the URL cannot be trusted) using the new JURI method isInternal($url). JURI::isInternal($url) will return true if the passed in url is a url on the same host as Joomla, or false if it is not. JURI::isInternal($url) was not available prior to 1.5.7. Affected InstallsAll 1.5.x installs prior to and including 1.5.6 are affected. SolutionUpgrade to latest Joomla! version (1.5.7 or newer). Reported By Emanuele Gentili ContactThe JSST at the Joomla! Security Center. |
| Last Updated on Tuesday, 09 September 2008 16:41 |



