exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New

Open Source CERT Security Advisory 2010.2

Open Source CERT Security Advisory 2010.2
Posted Jul 21, 2010
Authored by Open Source CERT | Site ocert.org

Joomla versions 1.5.19 and below suffer from cross site scripting vulnerabilities.

tags | advisory, vulnerability, xss
SHA-256 | 3b4fb9c3327b271275a41e8fc47c6c2e117dced54ae4efa6839e9540481a5804

Open Source CERT Security Advisory 2010.2

Change Mirror Download

#2010-002 Joomla input sanitization errors (XSS)

Description:

Joomla, an open source content management system, suffers from a cross-site
scripting (XSS) vulnerability.

Insufficient input sanitization on the parameters passed to pages related to
administration settings leads to arbitrary javascript injection in the context
of the user session, this could be potentially exploited to hijack the session
of the Joomla administrator.

Affected version:

Joomla <= 1.5.19

Fixed version:

Joomla >= 1.5.20

Credit: vulnerability report and PoC received from Mesut Timur <mesut [at]
mavitunasecurity [dot] com>.

CVE: N/A

Timeline:

2010-06-01: vulnerability report received
2010-06-01: contacted Joomla Security Team
2010-07-15: Joomla advisory published
2010-07-20: oCERT advisory published

References:
https://developer.joomla.org/security/news/318-20100704-core-xss-vulnerabilitis-in-back-end.html

Permalink:
https://www.ocert.org/advisories/ocert-2010-002.html

--
Andrea Barisani | Founder & Project Coordinator
oCERT | Open Source Computer Emergency Response Team

<lcars@ocert.org> https://www.ocert.org
0x864C9B9E 0A76 074A 02CD E989 CE7F AC3F DA47 578E 864C 9B9E
"Pluralitas non est ponenda sine necessitate"
Login or Register to add favorites

File Archive:

September 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Sep 1st
    261 Files
  • 2
    Sep 2nd
    17 Files
  • 3
    Sep 3rd
    38 Files
  • 4
    Sep 4th
    52 Files
  • 5
    Sep 5th
    23 Files
  • 6
    Sep 6th
    27 Files
  • 7
    Sep 7th
    0 Files
  • 8
    Sep 8th
    1 Files
  • 9
    Sep 9th
    16 Files
  • 10
    Sep 10th
    38 Files
  • 11
    Sep 11th
    21 Files
  • 12
    Sep 12th
    40 Files
  • 13
    Sep 13th
    18 Files
  • 14
    Sep 14th
    0 Files
  • 15
    Sep 15th
    0 Files
  • 16
    Sep 16th
    21 Files
  • 17
    Sep 17th
    51 Files
  • 18
    Sep 18th
    23 Files
  • 19
    Sep 19th
    48 Files
  • 20
    Sep 20th
    0 Files
  • 21
    Sep 21st
    0 Files
  • 22
    Sep 22nd
    0 Files
  • 23
    Sep 23rd
    0 Files
  • 24
    Sep 24th
    0 Files
  • 25
    Sep 25th
    0 Files
  • 26
    Sep 26th
    0 Files
  • 27
    Sep 27th
    0 Files
  • 28
    Sep 28th
    0 Files
  • 29
    Sep 29th
    0 Files
  • 30
    Sep 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close