upgrade from 2.5.11 to 2.5.20: remove the security problems

Discussion regarding Joomla! 2.5 security issues.

Moderators: mandville, General Support Moderators

Forum rules
Forum Rules
Absolute Beginner's Guide to Joomla! <-- please read before posting, this means YOU.
Forum Post Assistant / FPA - If you are serious about wanting help, you will use this tool to help you post.
Locked
Zapal
Joomla! Fledgling
Joomla! Fledgling
Posts: 1
Joined: Tue May 20, 2014 11:50 am

upgrade from 2.5.11 to 2.5.20: remove the security problems

Post by Zapal » Tue May 20, 2014 11:53 am

Please answer the question:
Is the upgrade from version 2.5.11 to 2.5.20 remove the following problems:

1 Password form: there is no option autocomplete = off what we risk by caching the user's password in the browser (medium)
2 No protection against CSRF (low)
3 DOM-based XSS vulnerabilities in index.php

User avatar
mandville
Joomla! Master
Joomla! Master
Posts: 15152
Joined: Mon Mar 20, 2006 1:56 am
Location: The Girly Side of Joomla in Sussex

Re: upgrade from 2.5.11 to 2.5.20: remove the security probl

Post by mandville » Tue May 20, 2014 1:59 pm

i have no idea why you are asking those sorts of questions, you should not still be on 2.5.11
if you want a list of why you should have upgraded by now, visit the security center http://developer.joomla.org/security-center.html
you best visit the VEL.joomla.org also as if you are that far behind on security updates for joomla, you are probably very behind on security updates for extensions
HU2HY- Poor questions = Poor answer
Un requested Help PM's will be reported, added to the foe list and possibly just deleted
{VEL Team Leader}{TM Auditor }{ Showcase & Security forums Moderator}


Locked

Return to “Security in Joomla! 2.5”