Fwd: Joomla! Security News

9 views
Skip to first unread message

edthix

unread,
Nov 9, 2012, 8:25:10 AM11/9/12
to KK-LUG


------- Forwarded message -------
From: "Joomla! Developer Network - Security News" <no_r...@joomla.org>
To: edt...@gmail.com
Cc:
Subject: Joomla! Security News
Date: Fri, 09 Nov 2012 21:22:00 +0800

Joomla! Security News


[20121102] - Core - Clickjacking

Posted: 08 Oct 2012 02:09 PM PDT

  • Project: Joomla!
  • SubProject: All
  • Severity: Moderate
  • Versions: 2.5.7 and all earlier 2.5.x versions
  • Exploit type: Clickjacking vulnerability
  • Reported Date: 2012-October-15
  • Fixed Date: 2012-November-08
  • CVE Number: CVE-2012-5827

Description

Inadequate protection leads to clickjacking vulnerability.

Affected Installs

Joomla! version 2.5.7 and all earlier 2.5.x versions.

Solution

Upgrade to version 2.5.8

Reported by Ajay Singh Negi

Contact

The JSST at the Joomla! Security Center.

You are subscribed to email updates from Joomla! Developer Network - Security News
To stop receiving these emails, you may unsubscribe now.
Email delivery powered by Google
Google Inc., 20 West Kinzie, Chicago IL USA 60610



--
Edham Arief Dawillah
edt...@gmail.com

edthix

unread,
Nov 13, 2012, 12:50:36 PM11/13/12
to KK-LUG


------- Forwarded message -------
From: "Joomla! Developer Network - Security News" <no_r...@joomla.org>
To: edt...@gmail.com
Cc:
Subject: Joomla! Security News
Date: Tue, 13 Nov 2012 21:12:46 +0800

Posted: 08 Oct 2012 02:09 PM PDT

  • Project: Joomla!
  • SubProject: All
  • Severity: Moderate
  • Versions: 3.0.1 and 3.0.0.
  • Exploit type: Clickjacking vulnerability
  • Reported Date: 2012-October-15
  • Fixed Date: 2012-November-08
  • CVE Number: CVE-2012-5827

Description

Inadequate protection leads to clickjacking vulnerability.

Affected Installs

Joomla! version 3.0.1 and 3.0.0.

Solution

Upgrade to version 3.0.2

Reported by Ajay Singh Negi

Contact

The JSST at the Joomla! Security Center.

You are subscribed to email updates from Joomla! Developer Network - Security News
To stop receiving these emails, you may unsubscribe now.
Email delivery powered by Google
Google Inc., 20 West Kinzie, Chicago IL USA 60610
Reply all
Reply to author
Forward
0 new messages