2006-02-21 - Joomla! 1.0.x is not affected by recent Mambo Vulnerability
There is some concern in the community about the recent Vunerability that affects the Mambo codebase as announced on the Mambo homepage and here:
http://forum.mamboserver.com/showthread ... post335532
Our internal testing and direct contact with GulfTech Research And Development - the discoverer of the Mambo vunerability - has confirmed that the vunerability does NOT affect the Joomla! 1.0.x codebase. This security weakness was addressed in Joomla! 1.0.0
However, you need to ensure that you are at least be running Joomla! 1.0.4, as 1.0.3 and below are vulnerable to an unrelated Critical Level security threat as explained in the 1.0.4 release article:
http://www.joomla.org/content/view/498/74/
Critical is Joomla! highest security rating and represents a security vulnerability that can lead to a site loss.
1.0.8 will be out very shortly and all Joomla! users should upgrade to this version.
This is a direct copy of my blog post here:
http://dev.joomla.org/component/option, ... d,33/p,35/

