Joomla! Discussion Forums



It is currently Tue Nov 24, 2009 12:07 am (All times are UTC )

 




Post new topic Reply to topic  [ 2 posts ] 
Author Message
Posted: Fri Sep 29, 2006 8:51 pm 
User avatar
Joomla! Explorer
Joomla! Explorer
Offline

Joined: Fri Aug 19, 2005 12:51 pm
Posts: 362
Location: Argentina
Bugtraq ID:  20236
Class: Input Validation Error
CVE:
Remote: Yes
Local: No
Published: Sep 27 2006 12:00AM
Updated: Sep 28 2006 05:26PM
Credit: Adrian Castro is credited with the discovery of these vulnerabilities.
Vulnerable: VirtueMart Joomla eCommerce Edition 1.0.11

VirtueMart Joomla eCommerce Edition is prone to multiple input-validation vulnerabilities because the application fails to properly sanitize user-supplied input.

An attacker can exploit these issues to execute arbitrary HTML and script code in the browser of a victim user in the context of the affected website. This may allow the attacker to steal cookie-based authentication credentials, to control how the site is rendered to the user, and to launch other attacks.

VirtueMart Joomla eCommerce Edition version 1.0.11 is vulnerable; earlier versions may also be vulnerable.

http://www.securityfocus.com/bid/20236/info

_________________
Comunidad Joomla!: Member of the Spanish [es_ES] Joomla Translation Team | http://comunidadjoomla.org

NUEVO! Manual de instalación para Joomla! 1.5.x - Guía de inicio Joomla! 1.5.X en http://joomlacode.org/gf/project/comunidadjoomla/frs/


Top
   
 
Posted: Tue Oct 03, 2006 1:37 pm 
User avatar
Joomla! Explorer
Joomla! Explorer
Offline

Joined: Fri Aug 19, 2005 12:47 pm
Posts: 268
Fixed by author

Have a look here
http://virtuemart.net/index.php?option= ... omment2155

_________________
Demetris Dimarelis
http://www.joomalb.com, Albanian Support site for Joomal | Joomla ne Shqip
http://www.e-orama.com, Web Services & Internet Marketing in Greece & Albania


Top
  E-mail  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 2 posts ] 

Quick reply

 



Who is online

Users browsing this forum: No registered users and 8 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Jump to:  
Powered by phpBB © 2000, 2002, 2005, 2007 phpBB Group