2 new exploit

Discussion regarding Joomla! 1.5 security issues.
Joomla! Vulnerable Extensions: http://feeds.joomla.org/JoomlaSecurityV ... Extensions

Moderator: General Support Moderators

Forum rules
Forum Rules
Absolute Beginner's Guide to Joomla! <-- please read before posting, this means YOU.
Security Checklist
Forum Post Assistant - If you are serious about wanting help, you will use this tool to help you post.
Locked
User avatar
lafrance
Joomla! Ace
Joomla! Ace
Posts: 1116
Joined: Thu Jan 11, 2007 5:02 pm
Location: Alberta,Canada
Contact:

2 new exploit

Post by lafrance » Thu Dec 10, 2009 8:14 pm

Mamboleto Component 2.0 RC3 sqlinjection
and
'corePHP' JPhoto
VEL contributor @ http://docs.joomla.org/Investigation_of_exploits
OSM,Trademark and Licensing Team,jed editor
Please no pm direct contact irc freenode.net #joomla

User avatar
PhilD
Joomla! Hero
Joomla! Hero
Posts: 2737
Joined: Sat Oct 21, 2006 10:20 pm
Location: Wisconsin USA
Contact:

Re: 2 new exploit

Post by PhilD » Fri Dec 11, 2009 12:54 am

Could you provide more information on the issues the extensions have and a link to where the issues were reported to?

This will help in verifying the issues so a determination can be made as to place on the vulnerability list or not.
PhilD

User avatar
lafrance
Joomla! Ace
Joomla! Ace
Posts: 1116
Joined: Thu Jan 11, 2007 5:02 pm
Location: Alberta,Canada
Contact:

Re: 2 new exploit

Post by lafrance » Fri Dec 11, 2009 1:11 am

PhilD wrote:Could you provide more information on the issues the extensions have and a link to where the issues were reported to?

This will help in verifying the issues so a determination can be made as to place on the vulnerability list or not.
hello!

posted them both on our http://docs.joomla.org/Investigation_of ... ation_list
from the list on http://www.exploit-db.com/webapps
VEL contributor @ http://docs.joomla.org/Investigation_of_exploits
OSM,Trademark and Licensing Team,jed editor
Please no pm direct contact irc freenode.net #joomla

User avatar
PhilD
Joomla! Hero
Joomla! Hero
Posts: 2737
Joined: Sat Oct 21, 2006 10:20 pm
Location: Wisconsin USA
Contact:

Re: 2 new exploit

Post by PhilD » Fri Dec 11, 2009 3:37 am

Thanks for the additional information
PhilD

User avatar
spignataro
Joomla! Ace
Joomla! Ace
Posts: 1179
Joined: Thu Aug 18, 2005 3:31 pm
Location: Battle Creek, MI
Contact:

Re: 2 new exploit

Post by spignataro » Sun Dec 13, 2009 2:54 am

Please removed JPhoto - patch has been released.

Kindest regards,
Steven Pignataro
-- http://www.corephp.com

User avatar
mandville
Joomla! Master
Joomla! Master
Posts: 15152
Joined: Mon Mar 20, 2006 1:56 am
Location: The Girly Side of Joomla in Sussex

Re: 2 new exploit

Post by mandville » Sun Dec 13, 2009 4:13 am

The vulnerabilities were moved to the main http://docs.joomla.org/Vulnerable_Extensions_List and have been removed from the investigation list
spignataro wrote:Please removed JPhoto - patch has been released.

Kindest regards,
Hello,
as stated on the list http://docs.joomla.org/Vulnerable_Extensions_List
Items will be removed after a suitable period and not on resolution <snip>
Finally a link to the notice about any update with link or Not Known where none is known.
Can you please provide a link to the update so we can add it to the list?

Having an update does not mean the users are aware of the vulnerability or update, hence we don't automatically remove it on resolution
Thanks
HU2HY- Poor questions = Poor answer
Un requested Help PM's will be reported, added to the foe list and possibly just deleted
{VEL Team Leader}{TM Auditor }{ Showcase & Security forums Moderator}

User avatar
spignataro
Joomla! Ace
Joomla! Ace
Posts: 1179
Joined: Thu Aug 18, 2005 3:31 pm
Location: Battle Creek, MI
Contact:

Re: 2 new exploit

Post by spignataro » Sun Dec 13, 2009 4:46 am

mandville,

http://www.corephp.com/blog/uber-fast-j ... y-release/

Here is the posting for JPhoto. Release is already been made available to our user base.

Kindest regards,
Steven Pignataro
-- http://www.corephp.com

User avatar
lafrance
Joomla! Ace
Joomla! Ace
Posts: 1116
Joined: Thu Jan 11, 2007 5:02 pm
Location: Alberta,Canada
Contact:

Re: 2 new exploit

Post by lafrance » Sun Dec 13, 2009 6:09 am

spignataro wrote:Please removed JPhoto - patch has been released.

Kindest regards,
Hello!

Thank you done,PhilD could you edit main page to reflect this also.

Thank You
VEL contributor @ http://docs.joomla.org/Investigation_of_exploits
OSM,Trademark and Licensing Team,jed editor
Please no pm direct contact irc freenode.net #joomla

User avatar
mandville
Joomla! Master
Joomla! Master
Posts: 15152
Joined: Mon Mar 20, 2006 1:56 am
Location: The Girly Side of Joomla in Sussex

Re: 2 new exploit

Post by mandville » Sun Dec 13, 2009 10:18 am

Link and status updated on the VEL to show the developer update.
HU2HY- Poor questions = Poor answer
Un requested Help PM's will be reported, added to the foe list and possibly just deleted
{VEL Team Leader}{TM Auditor }{ Showcase & Security forums Moderator}

User avatar
PhilD
Joomla! Hero
Joomla! Hero
Posts: 2737
Joined: Sat Oct 21, 2006 10:20 pm
Location: Wisconsin USA
Contact:

Re: 2 new exploit

Post by PhilD » Sun Dec 13, 2009 2:22 pm

Thanks, for making the page edit to the VEL mandville.

VEL - I like that it is easier to spell :D
PhilD

User avatar
mandville
Joomla! Master
Joomla! Master
Posts: 15152
Joined: Mon Mar 20, 2006 1:56 am
Location: The Girly Side of Joomla in Sussex

Re: 2 new exploit

Post by mandville » Sun Dec 13, 2009 2:36 pm

PhilD wrote:Thanks, for making the page edit to the VEL mandville.

VEL - I like that it is easier to spell :D
December even has its own http://[no tiny url]/vel1209
HU2HY- Poor questions = Poor answer
Un requested Help PM's will be reported, added to the foe list and possibly just deleted
{VEL Team Leader}{TM Auditor }{ Showcase & Security forums Moderator}


Locked

Return to “Security in Joomla! 1.5”