Joomla! News

Joomla! XCloner Component "mosmsg" and "option" Cross-Site Scripting Vulnerabilities

SECUNIA ADVISORY ID:
SA43511

VERIFY ADVISORY:
Secunia.com
http://secunia.com/advisories/43511/
Customer Area (Credentials Required)
https://ca.secunia.com/?page=viewadvisory&vuln_id=43511

RELEASE DATE:
2011-03-20

DESCRIPTION:
Two vulnerabilities have been reported in the XCloner component for
Joomla!, which can be exploited by malicious people to conduct
cross-site scripting attacks.

1) Input passed via the "mosmsg" parameter to
administrator/components/com_xcloner-backupandrestore/admin.cloner.php
is not properly sanitised in
administrator/components/com_xcloner-backupandrestore/admin.cloner.html.php
before being returned to the user. This can be exploited to execute
arbitrary HTML and script code in a user's browser session in context
of an affected site.

2) Input passed via the "option" parameter to
administrator/components/com_xcloner-backupandrestore/admin.cloner.php
(when "task" is set to "dologin") is not properly sanitised in
administrator/components/com_xcloner-backupandrestore/cloner.functions.php
before being returned to the user. This can be exploited to execute
arbitrary HTML and script code in a user's browser session in context
of an affected site.

Successful exploitation of this vulnerability requires that
"register_globals" is enabled.

The vulnerabilities are reported in version 2.1. Other versions may
also be affected.

SOLUTION:
Update to version 2.2.

PROVIDED AND/OR DISCOVERED BY:
mr_me

Joomla! XCloner Component "config" Local File Inclusion Vulnerability

SECUNIA ADVISORY ID:
SA43500

VERIFY ADVISORY:
Secunia.com
http://secunia.com/advisories/43500/
Customer Area (Credentials Required)
https://ca.secunia.com/?page=viewadvisory&vuln_id=43500

RELEASE DATE:
2011-03-20

DESCRIPTION:
A vulnerability has been discovered in the XCloner component for
Joomla!, which can be exploited by malicious people to disclose
sensitive information.

Input passed via the "config" parameter to
administrator/components/com_xcloner-backupandrestore/cloner.cron.php
is not properly verified before being used to include files. This can
be exploited to include arbitrary files from local resources via
directory traversal attacks.

The vulnerability is confirmed in versions 3.0.4 and 2.2. Other
versions may also be affected.

SOLUTION:
Edit the source code to ensure that input is properly verified.

PROVIDED AND/OR DISCOVERED BY:
mr_me

Thai Language for Joomla 1.6.1 released

Translation Teamsทีมจูมล่าลายไทย ได้รีลีสต์ไฟล์ภาษาสำหรับใช้งานบนจูมล่า 1.6.1 แล้ว ซึ่งในแพคเกจของไฟล์ภาษา ยังอาจมีข้อบกพร่องบ้าง ซึ่งตอนนี้ขอออกให้ใช้เฉพาะด้านหน้าเว็บก่อน ส่วนด้านหลัง ของตรวจสอบ Bug ให้น่้อยที่สุดแล้วจะออกตามมาครับ

1. th-TH joomla lang site 1.6.1 v1.zip เป็นไฟล์ภาษา ที่ใช้สำหรับเฉพาะด้านหน้าเว็บเท่านั้น

ภาษาไทย joomla 1.6

 

Read more ...

Joomla! Xmap Component Compromised Source Packages Backdoor Security Issue

SECUNIA ADVISORY ID:
SA43504

VERIFY ADVISORY:
Secunia.com
http://secunia.com/advisories/43504/
Customer Area (Credentials Required)
https://ca.secunia.com/?page=viewadvisory&vuln_id=43504

RELEASE DATE:
2011-03-17

DESCRIPTION:
A security issue has been reported in the Xmap component for Joomla!,
which can be exploited by malicious people to compromise a vulnerable
system.

The security issue is caused due to the distribution of compromised
Xmap component source code packages containing a backdoor, which can
be exploited to e.g. execute arbitrary PHP code.

The compromised source files were distributed from February 21st,
2011 to February 23rd, 2011 in version 1.2.10.

SOLUTION:
Updated to a fixed version 1.2.10 or later. Please see the vendor's
advisories for additional details.

PROVIDED AND/OR DISCOVERED BY:
Reported by the vendor.

ORIGINAL ADVISORY:
http://joomla.vargas.co.cr/en/news/4-xmap/95-security-notice

Joomla! Multiple Vulnerabilities

SECUNIA ADVISORY ID:
SA43658

VERIFY ADVISORY:
Secunia.com
http://secunia.com/advisories/43658/
Customer Area (Credentials Required)
https://ca.secunia.com/?page=viewadvisory&vuln_id=43658

RELEASE DATE:
2011-03-10
DESCRIPTION:
Multiple vulnerabilities have been reported in Joomla!, which can be
exploited by malicious users to bypass certain security restrictions
and cause a DoS (Denial of Service) and by malicious people to
disclose sensitive information, conduct cross-site scripting and
request forgery, and SQL injection attacks.

1) Certain unspecified input is not properly sanitised before being
used. This can be exploited to manipulate SQL queries by injecting
arbitrary SQL code.

NOTE: This can further be exploited to disclose the installation path
via SQL error messages.

2) Certain unhandled exceptions can be exploited to disclose the full
installation path.

3) Certain double URL-encoded input is not properly sanitised before
being returned to the user. This can be exploited to execute
arbitrary HTML and script code in a user's browser session in context
of an affected site.

4) Certain unspecified input is not properly sanitised before being
returned to the user. This can be exploited to execute arbitrary HTML
and script code in a user's browser session in context of an affected
site.

5) An error in the checking of access permissions can be exploited to
disclose certain information.

6) Certain unspecified input is not properly verified before being
used to redirect users. This can be exploited to redirect a user to
an arbitrary site e.g. when the user clicks a specially crafted link
to the affected script hosted on a trusted domain.

7) Certain unspecified input is not properly sanitised before being
used. This can be exploited to disclose potentially sensitive
information.

8) An error in the handling of access permissions can be exploited to
edit otherwise restricted files.

9) The application allows users to perform certain actions via HTTP
requests without making proper validity checks to verify the
requests. This can be exploited to perform certain unspecified
actions within the application by tricking a user into visiting a
malicious web site while being logged in to the application.

10) An error within the editor caching facility can be exploited to
use all available disk space.

The vulnerabilities are reported in versions prior to 1.6.1.

SOLUTION:
Update to version 1.6.1.

PROVIDED AND/OR DISCOVERED BY:
4) Reported by vendor and Jeff Channell

The vendor credits:
1, 2) YGN Ethical Hacker Group
3) Hoyt LLC Research
5, 6, 7, 8, 10) Jeff Channell
9) Marius Van Rijnsoever

ORIGINAL ADVISORY:
Joomla!:
http://www.joomla.org/announcements/release-news/5350-joomla-161-released.html
http://developer.joomla.org/security/news/328-20110201-core-sql-injection-path-disclosure
http://developer.joomla.org/security/news/329-20110202-core-path-disclosure
http://developer.joomla.org/security/news/330-20110203-core-xss-vulnerabilities
http://developer.joomla.org/security/news/331-20110204-core-xss-vulnerabilities
http://developer.joomla.org/security/news/332-20110301-core-information-disclosure
http://developer.joomla.org/security/news/333-20110302-core-redirect-vulnerabilities
http://developer.joomla.org/security/news/334-20110303-core-information-disclosure
http://developer.joomla.org/security/news/335-20110304-core-unauthorised-access
http://developer.joomla.org/security/news/336-20110305-core-csrf-vulnerability
http://developer.joomla.org/security/news/337-20110306-core-dos-vulnerabilities
http://developer.joomla.org/security/news/338-20110307-core-xss-vulnerabilities
http://developer.joomla.org/security/news/339-20110308-core-csrf-vulnerability

Joomla 1.6.1 ออกแล้ว

Joomla 1.6.1 Released

Joomla! Project ได้ประกาศออก Joomla 1.6.1 [Onward] เป็นการเร่งด่วน. โดยในเวอร์ชั่นนี้เป็นการแก้ไขในเรื่องของการรักษาความปลอดภัย

เป้าหมายที่ยิ่งใหญ่ของทีมผ่ายผลิต คือการให้ความช่วยเหลือต่อไปอย่างสม่ำเสมอ เพื่อชุมชน Joomla. ท่านสามารถเรียนรู้เพิ่มเติมเกี่ยวกับ Joomla! Developement ที่เว็บไซต์นักพัฒนา.

 

Read more ...

RECENT ARTICLE