Charlottezweb

General Conversation => Script Chat => Topic started by: Jason on March 06, 2012, 05:23:14 PM

Title: Joomla Security Notice :: March 6, 2012
Post by: Jason on March 06, 2012, 05:23:14 PM
A Joomla security notice was emailed today.

http://developer.joomla.org/security/news.html


Quote
Joomla! Security News
________________________________________
[20120302] - Core - XSS Vulnerability
Posted: 05 Mar 2012 06:00 AM PST
?   Project: Joomla!
?   SubProject: All
?   Severity: Moderate
?   Versions: 2.5.1 and 2.5.0
?   Exploit type: XSS Vulnerability
?   Reported Date: 2012-February-29
?   Fixed Date: 2012-March-05
Description
Inadequate filtering leads to XSS vulnerability.
Affected Installs
Joomla! version 2.5.1 and 2.5.0.
Solution
Upgrade to version 2.5.2
Reported by Phil Purviance
Contact
The JSST at the Joomla! Security Center.


[20120301] - Core - SQL Injection
Posted: 05 Mar 2012 06:00 AM PST
?   Project: Joomla!
?   SubProject: All
?   Severity: High
?   Versions: 2.5.1, 2.5.0 and 1.7.0 - 1.7.4
?   Exploit type: SQL Injection
?   Reported Date: 2012-February-29
?   Fixed Date: 2012-March-05
Description
Inadequate escaping leads to SQL injection vulnerability.
Affected Installs
Joomla! version 2.5.1, 2.5.0, 1.7.4, and all earlier 1.7.x versions
Solution
Upgrade to version 2.5.2