sexy Contact Form vulnerability

Discussion regarding Joomla! 3.x security issues.

Moderators: mandville, General Support Moderators

Forum rules
Forum Rules
Absolute Beginner's Guide to Joomla! <-- please read before posting, this means YOU.
Forum Post Assistant / FPA - If you are serious about wanting help, you will use this tool to help you post.
Windows Defender SmartScreen Issues <-- please read this if using Windows 10.
Locked
Mormahler
Joomla! Intern
Joomla! Intern
Posts: 87
Joined: Wed Sep 11, 2013 4:06 am

sexy Contact Form vulnerability

Post by Mormahler » Fri Oct 31, 2014 12:20 am

Maybe this item has already been posted. I haven't checked in in awhile. But I was informed this AM that my site was hacked, and sure enough it was, just a big ugly black page claiming the hack.

I went into my Host CPanel and looked around to see if I could find where the vulnerability came from. I noticed several hits from Sexy Contact Form, which I had installed, but did NOT have published.

I ended up having to pay $50 to one of the partners of my hosting company to repair.

Anyway, it is fixed. I did a search about Sexy Contact Form and found that it is vulnerable. I immediately deleted it from my site.
Last edited by mandville on Fri Oct 31, 2014 4:55 am, edited 1 time in total.
Reason: retitled to be more descriptive

User avatar
mandville
Joomla! Master
Joomla! Master
Posts: 15152
Joined: Mon Mar 20, 2006 1:56 am
Location: The Girly Side of Joomla in Sussex

Re: sexy Contact Form vulnerability

Post by mandville » Fri Oct 31, 2014 4:57 am

Yes. Sexy contact changed its name

http://vel.joomla.org/resolved/1581-cre ... 2-0-0.html
if you don't use an extension. Remove it .
HU2HY- Poor questions = Poor answer
Un requested Help PM's will be reported, added to the foe list and possibly just deleted
{VEL Team Leader}{TM Auditor }{ Showcase & Security forums Moderator}


Locked

Return to “Security in Joomla! 3.x”