DESCRIPTION:
A vulnerability has been discovered in the jNews component for
Joomla!, which can be exploited by malicious people to conduct
cross-site scripting attacks.
Input passed via the "get-data" parameter to
/components/com_jnews/includes/openflashchart/open-flash-chart.swf is
not properly sanitised before being returned to the user. This can be
exploited to execute arbitrary HTML and script code in a user's
browser session in context of an affected site.
The vulnerability is confirmed in version 8.0.1. Other versions may
also be affected.
SOLUTION:
No official solution is currently available.
PROVIDED AND/OR DISCOVERED BY:
Deepankar Arora and Rafay Baloch.
ORIGINAL ADVISORY:
http://packetstormsecurity.com/files/121623/Joomla-Jnews-8.0.1-Cross-Site-Scripting.html
DESCRIPTION:
A vulnerability has been discovered a vulnerability in the
Phocagallery component for Joomla!, which can be exploited by
malicious people to conduct cross-site scripting attacks.
Input passed via the "id" parameter to
/components/com_phocagallery/assets/plupload/plupload.flash.swf is
not properly sanitised before being returned to the user. This can be
exploited to execute arbitrary HTML and script code in a user's
browser session in context of an affected site.
The vulnerability is confirmed in version 3.2.3. Other versions may
also be affected.
SOLUTION:
No official solution is currently available.
PROVIDED AND/OR DISCOVERED BY:
Rafay Baloch and Deepankar Arora
ORIGINAL ADVISORY:
http://packetstormsecurity.com/files/121606/Joomla-Phocagallery-3.0.0-4.0.0-Cross-Site-Scripting.htm
DESCRIPTION:
A vulnerability has been reported in the bo:VideoJS component for
Joomla!, which can be exploited by malicious people to conduct
cross-site scripting attacks.
The vulnerability is caused due to a bundled vulnerable version of
VideoJS.
For more information:
SA53323
The vulnerability is reported in version 2.1.1. Prior versions may
also be affected.
SOLUTION:
Update to version 2.1.2.
ORIGINAL ADVISORY:
http://www.boeschung.de/en/joomla/bo-videojs/video-js-v320