|
Subscribe to Joomla! Security Announcements - Click Here |
Wed 25 Mar 2009 |
|
DescriptionA series of XSS and CSRF faults exist in the administrator application. Affected administrator components include com_admin, com_media, com_search. Both com_admin and com_search contain XSS vulnerabilities, and com_media contains 2 CSRF vulnerabilities. Affected InstallsAll 1.5.x installs prior to and including 1.5.9 are affected. The com_search XSS vulnerability requires that "Gather Search Statistics" be enabled to be exploitable (Disabled by default). SolutionUpgrade to latest Joomla! version (1.5.10 or newer). ContactThe JSST at the Joomla! Security Center. |
| Last Updated on Wednesday, 25 March 2009 18:04 |



