Attention: Official List of Vulnerable 3rd Party Add-ons!!!

For all Non-Joomla! security issues. ie 3pd Components etc.

Moderator: General Support Moderators

Forum rules
User avatar
rliskey
Joomla! Guru
Joomla! Guru
Posts: 828
Joined: Tue Jun 06, 2006 7:41 am
Location: California, Germany, Norway
Contact:

Re: Attention: Official List of Vulnerable 3rd Party Add-ons!!!

Post by rliskey » Thu Jun 21, 2007 8:39 pm

Added several recent vulnerability reports, including:
VirtueMart
ZOOM Gallery
TaskHopper

http://help.joomla.org/component/option ... temid,268/

User avatar
rliskey
Joomla! Guru
Joomla! Guru
Posts: 828
Joined: Tue Jun 06, 2006 7:41 am
Location: California, Germany, Norway
Contact:

Re: Attention: Official List of Vulnerable 3rd Party Add-ons!!!

Post by rliskey » Wed Jun 27, 2007 6:02 am

Added RWCards < 2.4.4

From author:
Yesterday (27.0.3.2007) I released an updated version of RwCards (2.4.4) with a fixed "category id" parameter Remote SQL Query Injection Vulnerability
Anyone who uses an earlier version should immediately upgrade!

Ralf Weber

User avatar
rliskey
Joomla! Guru
Joomla! Guru
Posts: 828
Joined: Tue Jun 06, 2006 7:41 am
Location: California, Germany, Norway
Contact:

Re: Attention: Official List of Vulnerable 3rd Party Add-ons!!!

Post by rliskey » Wed Jun 27, 2007 6:39 am

Added entries for the modules Article, AutoStand (and for WordPress, a separate but often used application).

User avatar
rliskey
Joomla! Guru
Joomla! Guru
Posts: 828
Joined: Tue Jun 06, 2006 7:41 am
Location: California, Germany, Norway
Contact:

Re: Attention: Official List of Vulnerable 3rd Party Add-ons!!!

Post by rliskey » Wed Jun 27, 2007 6:44 am

Added Car Manager <= 1.1

User avatar
rliskey
Joomla! Guru
Joomla! Guru
Posts: 828
Joined: Tue Jun 06, 2006 7:41 am
Location: California, Germany, Norway
Contact:

Re: Attention: Official List of Vulnerable 3rd Party Add-ons!!!

Post by rliskey » Sun Jul 01, 2007 7:42 am

Added  Akocomment. SQL injection. All versions

User avatar
rliskey
Joomla! Guru
Joomla! Guru
Posts: 828
Joined: Tue Jun 06, 2006 7:41 am
Location: California, Germany, Norway
Contact:

Re: Attention: Official List of Vulnerable 3rd Party Add-ons!!!

Post by rliskey » Fri Jul 06, 2007 5:01 pm

Updated JD-Wiki entry with link to nuWiki. JD-Wiki is abandoned. nuWiki is the replacement project.
http://help.joomla.org/component/option ... temid,268/
Last edited by rliskey on Fri Jul 06, 2007 5:05 pm, edited 1 time in total.

User avatar
rliskey
Joomla! Guru
Joomla! Guru
Posts: 828
Joined: Tue Jun 06, 2006 7:41 am
Location: California, Germany, Norway
Contact:

Re: Attention: Official List of Vulnerable 3rd Party Add-ons!!!

Post by rliskey » Thu Jul 19, 2007 4:34 am


User avatar
Tonie
Joomla! Master
Joomla! Master
Posts: 16553
Joined: Thu Aug 18, 2005 7:13 am

Re: Attention: Official List of Vulnerable 3rd Party Add-ons!!!

Post by Tonie » Mon Aug 06, 2007 3:32 pm

Gmaps 1.00 added. Fix can be downloaded here.

User avatar
rliskey
Joomla! Guru
Joomla! Guru
Posts: 828
Joined: Tue Jun 06, 2006 7:41 am
Location: California, Germany, Norway
Contact:

Re: Attention: Official List of Vulnerable 3rd Party Add-ons!!!

Post by rliskey » Thu Aug 16, 2007 10:51 pm

J! Reactions Vulnerability

Status: Critical

Versions: <= 1.8.x

Recovery Process:
Option 1: Immediately uninstall the current version, and check that all related files are deleted, and wait for the stable version.

Option 2: Copy the corrected code (listed in the forum discussion) into the vulnerable file.

More information:
http://forum.joomla.org/index.php/topic,202462.0.html

User avatar
rliskey
Joomla! Guru
Joomla! Guru
Posts: 828
Joined: Tue Jun 06, 2006 7:41 am
Location: California, Germany, Norway
Contact:

Re: Attention: Official List of Vulnerable 3rd Party Add-ons!!!

Post by rliskey » Tue Oct 23, 2007 9:07 pm

sh404SEF version t, u, and 2 Vulnerability

Reported by the author here.


Locked

Return to “3rd Party/Non Joomla! Security Issues”