joomla_112.png
Montano Designs Logo
  • Home
  • Services
    • ProductsMontano Designs is a full service Joomla web development company.
      • Complete Joomla Website
      • Recession Buster Special
      • Custom Joomla Template
      • Joomla Training
      • Website Hosting
      • Move Your Joomla Site
      • Upgrade Your Joomla Site
      • Modify Existing Template
  • The Low Down
    • About UsThe skinny on Montano Designs
    • Joomla BlogWe are all Joomla all the time
      • Extension Reviews
      • Tip of The Week
    • TestimonialsWhat our clients are saying about our Joomla services
  • Portfolio
    • Portfolio
      • Original Designs
      • Template Modifications
      • Logos
  • Articles
    • ArticlesWe've been collecting useful information to share with our visitors.
      • SEO
      • Tips and Tricks
      • Website Fonts
      • Website Standards
      • Website Principles
      • Website Graphics
      • Color Schemes
  • Joomla!
    • JoomlaContent Management System
      • Extension Reviews
      • Joomla User Manual
      • Tip of The Week
      • What is a CMS
      • Joomla News
  • Contact
    • ContactWe'd Like to Hear From You.
      • Contact
      • Support Ticket
      • Request a Quote
    • Search
  • Login

Joomla! Developer - Vulnerability News

Not only is Joomla! easy to use, but it is easy to add extra functionality through a flexible and powerful developer framework. The Joomla! Framework allows you to build exceptional extensions for Joomla! including components, modules, plugins, templates and language packs.
  • [20100704] - Core - XSS Vulnerabillitis in Back End
    • Project: Joomla!
    • SubProject: All
    • Severity: Medium
    • Versions: 1.5.19 and all previous 1.5 releases
    • Exploit type: XSS Injection
    • Reported Date: 2010-June-1
    • Fixed Date: 2010-July-15

    Description

    Back-end user can inject Javascript in various administrator screens.

    Affected Installs

    All 1.5.x installs prior to and including 1.5.19 are affected.

    Solution

    Upgrade to the latest Joomla! version (1.5.20 or later)

    Reported by Mesut Timur.

    Contact

    The JSST at the Joomla! Security Center.



  • [20100703] - Core - XSS Vulnerabillitis in Back End
    • Project: Joomla!
    • SubProject: All
    • Severity: Medium
    • Versions: 1.5.19 and all previous 1.5 releases
    • Exploit type: XSS Injection
    • Reported Date: 2010-June-8
    • Fixed Date: 2010-July-15

    Description

    Back-end user can inject Javascript in various administrator screens.

    Affected Installs

    All 1.5.x installs prior to and including 1.5.19 are affected.

    Solution

    Upgrade to the latest Joomla! version (1.5.20 or later)

    Reported by José Antonio Vázquez González

    Contact

    The JSST at the Joomla! Security Center.



  • [20100702] - Core - XSS Vulnerabillitis in Back End
    • Project: Joomla!
    • SubProject: All
    • Severity: Medium
    • Versions: 1.5.19 and all previous 1.5 releases
    • Exploit type: XSS Injection
    • Reported Date: 2010-June-8
    • Fixed Date: 2010-July-15

    Description

    Back-end user can inject Javascript in various administrator screens.

    Affected Installs

    All 1.5.x installs prior to and including 1.5.19 are affected.

    Solution

    Upgrade to the latest Joomla! version (1.5.20 or later)

    Reported by José Antonio Vázquez González

    Contact

    The JSST at the Joomla! Security Center.



  • [20100701] - Core - SQL Injection / Internal Path Exposure
    • Project: Joomla!
    • SubProject: All
    • Severity: Low
    • Versions: 1.5.19 and all previous 1.5 releases
    • Exploit type: Internal Path Exposure
    • Reported Date: 2010-June-10
    • Fixed Date: 2010-July-15

    Description

    Back-end user can create MySQL error which shows internal path information in the error message.

    Affected Installs

    All 1.5.x installs prior to and including 1.5.19 are affected.

    Solution

    Upgrade to the latest Joomla! version (1.5.20 or later)

    Reported by Andy Gorges

    Contact

    The JSST at the Joomla! Security Center.



  • [20100501] - Core - XSS Vulnerabilities in Back End
    • Project: Joomla!
    • SubProject: All
    • Severity: High
    • Versions: 1.5.17 and all previous 1.5 releases
    • Exploit type: XSS Injection
    • Reported Date: 2010-May-13
    • Fixed Date: 2010-May-28

    Description

    Back-end user can inject javascript in various administrator screens.

    Affected Installs

    All 1.5.x installs prior to and including 1.5.17 are affected.

    Solution

    Upgrade to the latest Joomla! version (1.5.18 or later)

    Reported by Riyaz Ahemed

    Contact

    The JSST at the Joomla! Security Center.



Read All About It!

  • Joomla Blog
    • Joomla Extension Reviews
    • Joomla Tip of The Week
  • Website Design Articles
    • Search Engine Optimization (SEO)
    • Website Color Schemes
    • Website Fonts
    • Website Graphics
    • Website Principles
    • Website Standards
    • Website Tips and Tricks

Newsletter Sign Up

We will occasionally send out a newsletter updating our subscribers about new Joomla features, security upgrades and items of note.

Subscribe

Name:

Email:

  • If you build it, will they come?

    Getting a new website found is increasingly difficult. Competition is fierce. It's…




    Read more...
  • A Good Web Host is Hard to Find

    A reliable web host is as elusive as the Loch Ness monster.…




    Read more...
  • Plagiarism

    I recently found 18 websites who's owners had blatantly plagiarized my site.…




    Read more...
  • To Upgrade or Not to Upgrade

    That is the question!  Not necessarily an original title, but it sums…




    Read more...
  • Moovur

    Let's talk about my latest favorite Joomla extension Moovur. Moovur is an…




    Read more...
  • MTW Migrator

    Let me tell you how much I LOVE this component.  I was…




    Read more...
  • JCal Pro Calendar

    This is one of my favorite components.  There are so many types…




    Read more...
  • JCE

    One of my favorite WSYWIG editors is JCE. The first thing I…




    Read more...
  • Joomla Home
    Home
  • Request A Quote for a Joomla Site
    Price
  • Joomla Blog
    Blog
  • Our Joomla Portfolio
    Portfolio
  • testimonials from Joomla clients
    Testimonials
  • Joomla News
    News
  • Contact Us About Your Joomla Site
    Contact
  • Go To Top
    Top