There is always a great deal of Joomla! development activity underway and communicating with other developers in the community is essential. This site is a resource for anyone looking to build or maintain software based on the Joomla! platform.
Where to Start
- Project: Joomla!
- SubProject: com_content
- Severity: Low
- Versions: 1.5.9 and all previous 1.5 releases
- Exploit type: XSS
- Reported Date: 2009-March-12
- Fixed Date: 2009-March-27
Description
A XSS vulnerability exists in the category view of com_content.
Affected Installs
All 1.5.x installs prior to and including 1.5.9 are affected.
Solution
Upgrade to latest Joomla! version (1.5.10 or newer).
Contact
The JSST at the Joomla! Security Centre.
- Project: Joomla!
- SubProject: Multiple
- Severity: Moderate
- Versions: 1.5.9 and all previous 1.5 releases
- Exploit type: XSS and CSRV
- Reported Date: 2009-February-15
- Fixed Date: 2009-March-27
Description
A series of XSS and CSRF faults exist in the administrator application. Affected administrator components include com_admin, com_media, com_search. Both com_admin and com_search contain XSS vulnerabilities, and com_media contains 2 CSRF vulnerabilities.
Affected Installs
All 1.5.x installs prior to and including 1.5.9 are affected. The com_search XSS vulnerability requires that "Gather Search Statistics" be enabled to be exploitable (Disabled by default).
Solution
Upgrade to latest Joomla! version (1.5.10 or newer).
Contact
The JSST at the Joomla! Security Centre.
- Project: Joomla!
- SubProject: plg_xstandard
- Severity: High
- Versions: 1.5.8 and all previous 1.5 releases
- Exploit type: Directory Traversal
- Reported Date: 2009-January-7
- Fixed Date: 2009-January-9
Description
A crafted request can cause disclosure of the directory structure on the server (including any directory that php has access to).
Affected Installs
All 1.5.x installs prior to and including 1.5.8 are affected.
Solution
Upgrade to latest Joomla! version (1.5.9 or newer).
Contact
The JSST at the Joomla! Security Centre.