Charlottezweb

General Conversation => Script Chat => Topic started by: Jason on August 02, 2013, 08:54:55 AM

Title: Joomla Security Notice :: August 2, 2013
Post by: Jason on August 02, 2013, 08:54:55 AM
Today's notice from Joomla:

Quote

Joomla! Security News
[20130801] - Core - Unauthorised Uploads
Posted: 01 Aug 2013 11:39 AM PDT
Project: Joomla!
SubProject: All
Severity: Critical
Versions: 2.5.13 and earlier 2.5.x versions. 3.1.4 and earlier 3.x versions.
Exploit type: Unauthorised Uploads
Reported Date: 2013-June-25
Fixed Date: 2013-July-31
CVE Number: Pending
Description

Inadequate filtering leads to the ability to bypass file type upload restrictions.
Affected Installs

Joomla! version 2.5.13 and earlier 2.5.x versions; and version 3.1.4 and earlier 3.x versions.
Solution

Upgrade to version 2.5.14 or 3.1.5.