Joomla! Discussion Forums



It is currently Thu Nov 26, 2009 8:38 am (All times are UTC )

 


Forum rules

Forum Rules
Absolute Beginner's Guide to Joomla! <-- please read before posting, this means YOU.
Security Checklist
Forum Post Assistant - If you are serious about wanting help, you will use this tool to help you post.



Post new topic Reply to topic  [ 4 posts ] 
Author Message
Posted: Tue Jun 20, 2006 7:18 am 
User avatar
Joomla! Enthusiast
Joomla! Enthusiast
Offline

Joined: Sat Aug 20, 2005 4:38 pm
Posts: 106
Location: Iran
My Friend Found 2 XSS Vulnerabilities in Joomla 1.0.9 Stable:
Fronted :
1.[URL removed]">
Backend:
2.in Admin Private Message: Subject:



[MOD noted edited for security reasons]


Last edited by stingrey on Wed Jun 28, 2006 3:48 pm, edited 1 time in total.

Top
   
 
Posted: Wed Jun 21, 2006 6:59 pm 
User avatar
Joomla! Hero
Joomla! Hero
Offline

Joined: Mon Aug 15, 2005 4:36 pm
Posts: 2399
Location: Marikina, Metro Manila, Philippines
Fixed in 1.0.10 SVN



Both these security vulnerabilites are designated as :
[LOW LEVEL] A4 Cross Site Scripting

_________________
God grant me the Serenity to Accept the things I cannot change, the Courage to change the things I can and the Wisdom to know the Difference.


Top
  E-mail  
 
Posted: Thu Jun 22, 2006 6:09 am 
User avatar
Joomla! Enthusiast
Joomla! Enthusiast
Offline

Joined: Sat Aug 20, 2005 4:38 pm
Posts: 106
Location: Iran
thanks


Top
   
 
Posted: Mon Jun 26, 2006 5:12 am 
User avatar
Joomla! Hero
Joomla! Hero
Offline

Joined: Mon Aug 15, 2005 4:36 pm
Posts: 2399
Location: Marikina, Metro Manila, Philippines
Upgrade to Joomla! 1.0.10 Security Release!
http://www.joomla.org/content/view/1510/74/

_________________
God grant me the Serenity to Accept the things I cannot change, the Courage to change the things I can and the Wisdom to know the Difference.


Top
  E-mail  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 4 posts ] 

Quick reply

 



Who is online

Users browsing this forum: No registered users and 18 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Jump to:  
Powered by phpBB © 2000, 2002, 2005, 2007 phpBB Group