Fwd: Joomla! Security News Joomla 2.5.4

8 views
Skip to first unread message

Ernesto Patarroyo

unread,
Apr 3, 2012, 8:26:18 AM4/3/12
to joomla-en...@googlegroups.com
Ya está disponible Joomla 2.5.4

Ya han usado la función de actualización con un solo clic?

Ernesto Patarroyo



---------- Forwarded message ----------
From: Joomla! Developer Network - Security News <no_r...@joomla.org>
Date: Tue, Apr 3, 2012 at 7:19 AM
Subject: Joomla! Security News
To: in...@openwebsoft.com


Joomla! Security News


[20120307] - Core - Information Disclosure

Posted: 03 Apr 2012 12:21 AM PDT

  • Project: Joomla!
  • SubProject: All
  • Severity: Low
  • Versions: 2.5.3 and all earlier 2.5.x versions
  • Exploit type: Information Disclosure
  • Reported Date: 2012-January-7
  • Fixed Date: 2012-April-2

Description

Inadequate permission checking allows unauthorised viewing of some administrative back end information.

Affected Installs

Joomla! versions 2.5.3 and all earlier 2.5.x versions

Solution

Upgrade to version 2.5.4

Reported by Cyrille Barthelemy

Contact

The JSST at the Joomla! Security Center.

[20120308] - Core - XSS Vulnerability

Posted: 03 Apr 2012 12:21 AM PDT

  • Project: Joomla!
  • SubProject: All
  • Severity: Low
  • Versions: 2.5.3 and all earlier 2.5.x versions
  • Exploit type: XSS Vulnerability
  • Reported Date: 2012-February-3
  • Fixed Date: 2012-April-2

Description

Inadequate filtering in update manager leads to XSS vulnerability.

Affected Installs

Joomla! versions 2.5.3 and all earlier 2.5.x versions

Solution

Upgrade to version 2.5.4

Reported by Alex Andreae

Contact

The JSST at the Joomla! Security Center.

You are subscribed to email updates from Joomla! Developer Network - Security News
To stop receiving these emails, you may unsubscribe now.
Email delivery powered by Google
Google Inc., 20 West Kinzie, Chicago IL USA 60610

Reply all
Reply to author
Forward
0 new messages