mod_spo

Discussion regarding Joomla! 1.5 security issues.
Joomla! Vulnerable Extensions: http://feeds.joomla.org/JoomlaSecurityV ... Extensions

Moderator: General Support Moderators

Forum rules
Forum Rules
Absolute Beginner's Guide to Joomla! <-- please read before posting, this means YOU.
Security Checklist
Forum Post Assistant - If you are serious about wanting help, you will use this tool to help you post.
Locked
SheilaMary
Joomla! Enthusiast
Joomla! Enthusiast
Posts: 100
Joined: Wed Jun 23, 2010 5:46 pm
Location: Marseille, France

mod_spo

Post by SheilaMary » Tue Aug 09, 2011 8:13 am

Simple Page is on the Vulnerable Extensions List - is it this same thing as mod_spo, which is not (as far as I could find)? I had an issue with the latter at the weekend, cleaned out the site and re-installed Joomla (Version 1.5.23) --- which, I see, still has a mod_spo in it, though it appears to be a later version than the one I had before. Is this module safe now or should I get rid of it? (Apologies if this is a really obvious question, but I haven't been able to find anything on it on the forum)

SheilaMary
Joomla! Enthusiast
Joomla! Enthusiast
Posts: 100
Joined: Wed Jun 23, 2010 5:46 pm
Location: Marseille, France

Re: mod_spo

Post by SheilaMary » Tue Aug 09, 2011 7:27 pm

91 views and no comments or answers? Is there anybody out there?

User avatar
mandville
Joomla! Master
Joomla! Master
Posts: 15152
Joined: Mon Mar 20, 2006 1:56 am
Location: The Girly Side of Joomla in Sussex

Re: mod_spo

Post by mandville » Tue Aug 09, 2011 7:49 pm

yes, lots of people , but not many probably know the answer

Simple Page Option still suffers from LFI as far as the vel team are concerned which is why it is on the VEL
If you think that mod_spo is a different item, please let the vel team know
HU2HY- Poor questions = Poor answer
Un requested Help PM's will be reported, added to the foe list and possibly just deleted
{VEL Team Leader}{TM Auditor }{ Showcase & Security forums Moderator}

SheilaMary
Joomla! Enthusiast
Joomla! Enthusiast
Posts: 100
Joined: Wed Jun 23, 2010 5:46 pm
Location: Marseille, France

Re: mod_spo

Post by SheilaMary » Tue Aug 09, 2011 8:25 pm

Thank you for your reply. Per the hosting provider, there was a weakness in "/public_html/modules/mod_spo/email_sender.php" and I wondered if "spo" was the same as Simple Page Option (though I have no idea whether it is) and whether mod_spo was now a safe module in Joomla 1.5.23.

User avatar
PhilD
Joomla! Hero
Joomla! Hero
Posts: 2737
Joined: Sat Oct 21, 2006 10:20 pm
Location: Wisconsin USA
Contact:

Re: mod_spo

Post by PhilD » Wed Aug 10, 2011 12:26 pm

mod_spo is the same as the Simple Page Option. mod_spo is the modules name and also the download name (minus the version number). Info about the extension and the sql injection is all over Google.
PhilD

SheilaMary
Joomla! Enthusiast
Joomla! Enthusiast
Posts: 100
Joined: Wed Jun 23, 2010 5:46 pm
Location: Marseille, France

Re: mod_spo

Post by SheilaMary » Wed Aug 10, 2011 12:50 pm

Many thanks!


Locked

Return to “Security in Joomla! 1.5”