Last edited by rliskey on Fri Jul 06, 2007 5:03 pm, edited 1 time in total.
Rob Schley - Joomla! Development Working Group - Open Source Matters Board WebImagery - http://www.webimagery.net/ - Professional Consulting Services JXtended - http://www.jxtended.com/ - Free and Commercial Joomla! Extensions
Updated. Added A6MamboHelpDesk to the list of vulnerable components and also updated the information for LoudMouth as it has reportedly been fixed now.
Last updated July 29, 2006 @ 12:06 PM PDT.
Rob Schley - Joomla! Development Working Group - Open Source Matters Board WebImagery - http://www.webimagery.net/ - Professional Consulting Services JXtended - http://www.jxtended.com/ - Free and Commercial Joomla! Extensions
Updated again. Added 7 components to the naughty list.
PC Cook Book User Home Pages 1 and 2 Mambo Gallery Manager JD-WordPress Colophon LMO Bayesian Naive Filter
That brings this list to 34 components. Last updated on July 31, 2006 @ 11:34 PM PDT.
Rob Schley - Joomla! Development Working Group - Open Source Matters Board WebImagery - http://www.webimagery.net/ - Professional Consulting Services JXtended - http://www.jxtended.com/ - Free and Commercial Joomla! Extensions
Added JD-Wiki Community Builder (com_profiler) ((Thank you JM!)) Updated status for LMO Updated link for SMF Bridge (for SMF 1.1RC2 only)
Last updated on August 10th, 2006 at 1:45 AM PDT (GMT-7)
Rob Schley - Joomla! Development Working Group - Open Source Matters Board WebImagery - http://www.webimagery.net/ - Professional Consulting Services JXtended - http://www.jxtended.com/ - Free and Commercial Joomla! Extensions
Last updated on August 10th, 2006 at 2:15 AM PDT (GMT-7)
Rob Schley - Joomla! Development Working Group - Open Source Matters Board WebImagery - http://www.webimagery.net/ - Professional Consulting Services JXtended - http://www.jxtended.com/ - Free and Commercial Joomla! Extensions
Added Blogg-X Mambot. - Removed Blogg-X. It does not appear to be vulnerable upon further investigation. Updated information about Security Images.
That brings the number of insecure 3rd party extensions up to 40 extensions.
Last updated on August 12th, 2006 at 11:16 AM PDT (GMT-7)
Last edited by RobS on Sat Aug 12, 2006 6:17 pm, edited 1 time in total.
Rob Schley - Joomla! Development Working Group - Open Source Matters Board WebImagery - http://www.webimagery.net/ - Professional Consulting Services JXtended - http://www.jxtended.com/ - Free and Commercial Joomla! Extensions
Removed Blogg-X. Upon further investigation Blogg-X does not appear to be vulnerable.
Rob Schley - Joomla! Development Working Group - Open Source Matters Board WebImagery - http://www.webimagery.net/ - Professional Consulting Services JXtended - http://www.jxtended.com/ - Free and Commercial Joomla! Extensions
Update has come in about Mosets Hot Property, there 0.98 release should fix the security issues. Still need to verify before we change the current listing.
Regards Robin
Regards Robin - Sites & Infrastructure
Spilling the Beans on Open Source - Case studies, Reviews, Interviews and more @ http://robink.nl What nature designs is amazing. Designing amazing is our business @ http://alvaana.com
I have received a reply from the developer of Mosets Tree and Hot Property. Mosets Tree 1.5.9 and Hot Property 0.98 are now solving the security issues. The list will be changed accordingly.
Regards Robin - Sites & Infrastructure
Spilling the Beans on Open Source - Case studies, Reviews, Interviews and more @ http://robink.nl What nature designs is amazing. Designing amazing is our business @ http://alvaana.com
Thanks JM, added as a note/reference to the listing.
Regards Robin - Sites & Infrastructure
Spilling the Beans on Open Source - Case studies, Reviews, Interviews and more @ http://robink.nl What nature designs is amazing. Designing amazing is our business @ http://alvaana.com
Spilling the Beans on Open Source - Case studies, Reviews, Interviews and more @ http://robink.nl What nature designs is amazing. Designing amazing is our business @ http://alvaana.com
Spilling the Beans on Open Source - Case studies, Reviews, Interviews and more @ http://robink.nl What nature designs is amazing. Designing amazing is our business @ http://alvaana.com
Rob Schley - Joomla! Development Working Group - Open Source Matters Board WebImagery - http://www.webimagery.net/ - Professional Consulting Services JXtended - http://www.jxtended.com/ - Free and Commercial Joomla! Extensions
The Official List of Vulnerable 3rd Party/Non Joomla! Extensions is the new home for information on vulnerable 3rd party extensions. It contains a table style overview of all known vulnerable extensions with links to detailed information on each one. http://forum.joomla.org/index.php/board,346.0.html
This thread will remain for announcements and discussions related to vulnerable 3rd party extension security issues.
Last edited by rliskey on Thu Oct 05, 2006 7:40 am, edited 1 time in total.
Added a link to the Adobe Reader XSS vulnerability report. This is not a Joomla! or third party issue, but because so many sites use PDF files, I think it's worth noting.