Joomla! Cross Site Scripting and Information Disclosure Vulnerabilities
BID:35544
Info
Joomla! Cross Site Scripting and Information Disclosure Vulnerabilities
| Bugtraq ID: | 35544 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 01 2009 12:00AM |
| Updated: | Jul 02 2009 05:19PM |
| Credit: | Juan Galiana Lara (Internet Security Auditors), Paul Boekholt (Byte Internet) |
| Vulnerable: |
Joomla Joomla 1.5.11 Joomla Joomla 1.5.10 Joomla Joomla 1.5.9 Joomla Joomla 1.5.8 Joomla Joomla 1.5.7 Joomla Joomla 1.5.6 Joomla Joomla 1.5.5 Joomla Joomla 1.5.4 Joomla Joomla 1.5.3 Joomla Joomla 1.5.2 Joomla Joomla 1.5.1 Joomla Joomla 1.5 Joomla Joomla 1.5.0 Beta Joomla Joomla 1.5 RC3 Joomla Joomla 1.5 RC2 Joomla Joomla 1.5 RC1 Joomla Joomla 1.5 Beta 2 |
| Not Vulnerable: |
Joomla Joomla 1.5.12 |
Discussion
Joomla! Cross Site Scripting and Information Disclosure Vulnerabilities
Joomla! is prone to multiple cross-site scripting and information-disclosure vulnerabilities.
An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site, steal cookie-based authentication credentials, and obtain sensitive information.
These issues affect versions prior to 1.5.12.
Joomla! is prone to multiple cross-site scripting and information-disclosure vulnerabilities.
An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site, steal cookie-based authentication credentials, and obtain sensitive information.
These issues affect versions prior to 1.5.12.
Exploit / POC
Joomla! Cross Site Scripting and Information Disclosure Vulnerabilities
Attackers can use a browser to exploit these issues. To exploit a cross-site scripting vulnerability, an attacker must entice an unsuspecting victim to follow a malicious URI.
The following exploit code is available:
Attackers can use a browser to exploit these issues. To exploit a cross-site scripting vulnerability, an attacker must entice an unsuspecting victim to follow a malicious URI.
The following exploit code is available:
Solution / Fix
Joomla! Cross Site Scripting and Information Disclosure Vulnerabilities
Solution:
The vendor has released an update. Please see the references for more information.
Joomla Joomla 1.5 RC1
Joomla Joomla 1.5 Beta 2
Joomla Joomla 1.5 RC2
Joomla Joomla 1.5.0 Beta
Joomla Joomla 1.5 RC3
Joomla Joomla 1.5
Joomla Joomla 1.5.1
Joomla Joomla 1.5.10
Joomla Joomla 1.5.11
Joomla Joomla 1.5.2
Joomla Joomla 1.5.3
Joomla Joomla 1.5.4
Joomla Joomla 1.5.5
Joomla Joomla 1.5.6
Joomla Joomla 1.5.7
Joomla Joomla 1.5.8
Joomla Joomla 1.5.9
Solution:
The vendor has released an update. Please see the references for more information.
Joomla Joomla 1.5 RC1
-
Joomla Joomla_1.5.12-Stable-Full_Package.zip
http://joomlacode.org/gf/download/frsrelease/10547/41305/Joomla_1.5.12 -Stable-Full_Package.zip
Joomla Joomla 1.5 Beta 2
-
Joomla Joomla_1.5.12-Stable-Full_Package.zip
http://joomlacode.org/gf/download/frsrelease/10547/41305/Joomla_1.5.12 -Stable-Full_Package.zip
Joomla Joomla 1.5 RC2
-
Joomla Joomla_1.5.12-Stable-Full_Package.zip
http://joomlacode.org/gf/download/frsrelease/10547/41305/Joomla_1.5.12 -Stable-Full_Package.zip
Joomla Joomla 1.5.0 Beta
-
Joomla Joomla_1.5.12-Stable-Full_Package.zip
http://joomlacode.org/gf/download/frsrelease/10547/41305/Joomla_1.5.12 -Stable-Full_Package.zip
Joomla Joomla 1.5 RC3
-
Joomla Joomla_1.5.12-Stable-Full_Package.zip
http://joomlacode.org/gf/download/frsrelease/10547/41305/Joomla_1.5.12 -Stable-Full_Package.zip
Joomla Joomla 1.5
-
Joomla Joomla_1.5.12-Stable-Full_Package.zip
http://joomlacode.org/gf/download/frsrelease/10547/41305/Joomla_1.5.12 -Stable-Full_Package.zip
Joomla Joomla 1.5.1
-
Joomla Joomla_1.5.12-Stable-Full_Package.zip
http://joomlacode.org/gf/download/frsrelease/10547/41305/Joomla_1.5.12 -Stable-Full_Package.zip
Joomla Joomla 1.5.10
-
Joomla Joomla_1.5.12-Stable-Full_Package.zip
http://joomlacode.org/gf/download/frsrelease/10547/41305/Joomla_1.5.12 -Stable-Full_Package.zip
Joomla Joomla 1.5.11
-
Joomla Joomla_1.5.12-Stable-Full_Package.zip
http://joomlacode.org/gf/download/frsrelease/10547/41305/Joomla_1.5.12 -Stable-Full_Package.zip
Joomla Joomla 1.5.2
-
Joomla Joomla_1.5.12-Stable-Full_Package.zip
http://joomlacode.org/gf/download/frsrelease/10547/41305/Joomla_1.5.12 -Stable-Full_Package.zip
Joomla Joomla 1.5.3
-
Joomla Joomla_1.5.12-Stable-Full_Package.zip
http://joomlacode.org/gf/download/frsrelease/10547/41305/Joomla_1.5.12 -Stable-Full_Package.zip
Joomla Joomla 1.5.4
-
Joomla Joomla_1.5.12-Stable-Full_Package.zip
http://joomlacode.org/gf/download/frsrelease/10547/41305/Joomla_1.5.12 -Stable-Full_Package.zip
Joomla Joomla 1.5.5
-
Joomla Joomla_1.5.12-Stable-Full_Package.zip
http://joomlacode.org/gf/download/frsrelease/10547/41305/Joomla_1.5.12 -Stable-Full_Package.zip
Joomla Joomla 1.5.6
-
Joomla Joomla_1.5.12-Stable-Full_Package.zip
http://joomlacode.org/gf/download/frsrelease/10547/41305/Joomla_1.5.12 -Stable-Full_Package.zip
Joomla Joomla 1.5.7
-
Joomla Joomla_1.5.12-Stable-Full_Package.zip
http://joomlacode.org/gf/download/frsrelease/10547/41305/Joomla_1.5.12 -Stable-Full_Package.zip
Joomla Joomla 1.5.8
-
Joomla Joomla_1.5.12-Stable-Full_Package.zip
http://joomlacode.org/gf/download/frsrelease/10547/41305/Joomla_1.5.12 -Stable-Full_Package.zip
Joomla Joomla 1.5.9
-
Joomla Joomla_1.5.12-Stable-Full_Package.zip
http://joomlacode.org/gf/download/frsrelease/10547/41305/Joomla_1.5.12 -Stable-Full_Package.zip
References
Joomla! Cross Site Scripting and Information Disclosure Vulnerabilities
References:
References:
- Joomla! 1.5.12 Released (Joomla!)
- [ISecAuditors Security Advisories] Joomla! < 1.5.12 Multiple XSS vulnerabilitie (ISecAuditors Security Advisories
)