Joomla! Multiple Security Vulnerabilities
BID:19749
Info
Joomla! Multiple Security Vulnerabilities
| Bugtraq ID: | 19749 |
| Class: | Unknown |
| CVE: |
CVE-2006-4470 CVE-2006-4466 CVE-2006-4468 CVE-2006-4469 CVE-2006-4471 CVE-2006-4473 CVE-2006-4472 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 29 2006 12:00AM |
| Updated: | Jul 06 2016 01:25PM |
| Credit: | These issues were disclosed by the vendor. |
| Vulnerable: |
SocialMPN SocialMPN 1.0.5 Joomla Joomla 1.0.10 Joomla Joomla 1.0.9 Joomla Joomla 1.0.8 Joomla Joomla 1.0.7 Joomla Joomla 1.0.4 Joomla Joomla 1.0.3 Joomla Joomla 1.0.2 Joomla Joomla 1.0.1 Joomla Joomla 1.0 |
| Not Vulnerable: |
Joomla Joomla 1.0.11 |
Discussion
Joomla! Multiple Security Vulnerabilities
Joomla! is prone to multiple security vulnerabilities, including varius cross-site scripting, code-injection, input-validation, and access-control-bypass issues. These issues are caused by design and configuration weaknesseses and by a failure in the application to properly sanitize user-supplied input in several cases.
A number of these issues may have already been documented in other BIDs.
A successful exploit of these vulnerabilities could allow an attacker to compromise the application, access or modify data, steal cookie-based authentication credentials, inject arbitrary hostile code, or even exploit vulnerabilities in the underlying system or database implementation. Presumably, some of these issues may facilitate remote unauthorized access. Other attacks are also possible.
All versions of Joomla! prior to version 1.0.11 are vulnerable to these issues. Updates are available.
Joomla! is prone to multiple security vulnerabilities, including varius cross-site scripting, code-injection, input-validation, and access-control-bypass issues. These issues are caused by design and configuration weaknesseses and by a failure in the application to properly sanitize user-supplied input in several cases.
A number of these issues may have already been documented in other BIDs.
A successful exploit of these vulnerabilities could allow an attacker to compromise the application, access or modify data, steal cookie-based authentication credentials, inject arbitrary hostile code, or even exploit vulnerabilities in the underlying system or database implementation. Presumably, some of these issues may facilitate remote unauthorized access. Other attacks are also possible.
All versions of Joomla! prior to version 1.0.11 are vulnerable to these issues. Updates are available.
Exploit / POC
Joomla! Multiple Security Vulnerabilities
To exploit most of these issues, an attacker can use a web client. Exploit code is not required.
To exploit most of these issues, an attacker can use a web client. Exploit code is not required.
Solution / Fix
Joomla! Multiple Security Vulnerabilities
Solution:
The vendor has released version 1.0.11 to address these issues; please see the reference section for details and vendor advisories.
Solution:
The vendor has released version 1.0.11 to address these issues; please see the reference section for details and vendor advisories.
References
Joomla! Multiple Security Vulnerabilities
References:
References:
- ezPortal/ztml Homepage (ezPortal/ztml)
- Ezportal/Ztml v1.0 Multiple vulnerabilities (Hessam-x)