You are here
Home > Preporuke > Sigurnosni nedostaci programskog paketa Joomla!

Sigurnosni nedostaci programskog paketa Joomla!

  • Detalji os-a: WN7
  • Važnost: IMP
  • Operativni sustavi: O
  • Kategorije: ALL, W03, WN7, VIS, W08, HPQ, LRH, LDE, LSU, FBS, LFE, LGE, LUB, APL, LMV, WN8, W12

Security

///////////////////////////////////////////
[20140901] – Core – XSS Vulnerability

Posted: 23 Sep 2014 12:00 PM PDT
http://feedproxy.google.com/~r/JoomlaSecurityNews/~3/EiyFsQIjpu4/593-20140901-core-xss-vulnerability.html?utm_source=feedburner&utm_medium=email

Project: Joomla!
SubProject: CMS
Severity: Moderate
Versions: 3.2.0 through 3.2.4, 3.3.0 through 3.3.3
Exploit type: XSS Vulnerability
Reported Date: 2014-August-27
Fixed Date: 2014-September-23
CVE Number: CVE-2014-6631

Description

Inadequate escaping leads to XSS vulnerability in com_media.
Affected Installs

Joomla! CMS versions 3.2.0 through 3.2.4 and 3.3.0 through 3.3.3
Solution

Upgrade to version 3.2.5 or 3.3.4
Contact

The JSST at the Joomla! Security Center.
Reported By: Dingjie (Daniel) Yang

///////////////////////////////////////////
[20140902] – Core – Unauthorised Logins

Posted: 23 Sep 2014 12:00 PM PDT
http://feedproxy.google.com/~r/JoomlaSecurityNews/~3/uFCKpt1YcxU/594-20140902-core-unauthorised-logins.html?utm_source=feedburner&utm_medium=email

Project: Joomla!
SubProject: CMS
Severity: Moderate
Versions: 2.5.24 and earlier 2.5.x versions, 3.2.4 and earlier 3.x
versions, 3.3.0 through 3.3.3
Exploit type: Unauthorised Logins
Reported Date: 2014-September-09
Fixed Date: 2014-September-23
CVE Number: CVE-2014-6632

Description

Inadequate checking allowed unauthorised logins via LDAP authentication.
Affected Installs

Joomla! CMS versions 2.5.24 and earlier 2.5.x versions, 3.2.4 and earlier
3.x versions, 3.3.0 through 3.3.3
Solution

Upgrade to version 2.5.25, 3.2.5, or 3.3.4
Contact

The JSST at the Joomla! Security Center.
Reported By: Matthew Daley


You are subscribed to email updates from “Security.”

AutorMarko Stanec
Cert idNCERT-REF-2014-09-0002-ADV
CveCERT-CVE-DUMMY
ID izvornikaCERT-ORIGID-DUMMY
ProizvodCERT-DUMMY-PRODUCT
Izvorhttp://www.adobe.com/
Top
More in Preporuke
Ranjivosti jezgre operacijskog sustava

Otkrivene su ranjivosti u jezgri operacijskog sustava Ubuntu 10.04 LTS i 12.04 LTS. Dvije ranjivosti zahvaćaju oba sustava, a odnosile...

Close