Joomla! Prior to 1.6.1 Multiple Security Vulnerabilities
BID:46787
Info
Joomla! Prior to 1.6.1 Multiple Security Vulnerabilities
| Bugtraq ID: | 46787 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 07 2011 12:00AM |
| Updated: | Mar 07 2011 12:00AM |
| Credit: | YGN Ethical Hacker Group, Hoyt LLC Research, Jeff Channell and Marius Van Rijnsoever. |
| Vulnerable: |
Joomla Joomla! 1.6 Joomla Joomla! 1.5.22 Joomla Joomla! 1.5.20 Joomla Joomla! 1.5.19 Joomla Joomla! 1.5.18 Joomla Joomla! 1.5.17 Joomla Joomla! 1.5.16 Joomla Joomla! 1.5.15 Joomla Joomla! 1.5.14 Joomla Joomla! 1.5.13 Joomla Joomla! 1.5.12 Joomla Joomla! 1.5.11 Joomla Joomla! 1.5.10 Joomla Joomla! 1.5.9 Joomla Joomla! 1.5.8 Joomla Joomla! 1.5.7 Joomla Joomla! 1.5.6 Joomla Joomla! 1.5.5 Joomla Joomla! 1.5.4 Joomla Joomla! 1.5.2 Joomla Joomla! 1.5.3 Joomla Joomla! 1.5.15 Rc Joomla Joomla! 1.5.1 Joomla Joomla! 1.5.0 |
| Not Vulnerable: |
Joomla Joomla! 1.6.1 |
Discussion
Joomla! Prior to 1.6.1 Multiple Security Vulnerabilities
Joomla! is prone to multiple security vulnerabilities including:
An SQL-injection issue
A path-disclosure vulnerability
Multiple cross-site scripting issues
Multiple information-disclosure vulnerabilities
A URI-redirection vulnerability
A security-bypass vulnerability
A cross-site request-forgery vulnerability
A denial-of-service vulnerability
An attacker can exploit these vulnerabilities to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site, steal cookie-based authentication credentials, disclose or modify sensitive information, exploit latent vulnerabilities in the underlying database, deny service to legitimate users, redirect a victim to a potentially malicious site, or perform unauthorized actions. Other attacks are also possible.
Versions prior to Joomla! 1.6.1 are vulnerable.
Joomla! is prone to multiple security vulnerabilities including:
An SQL-injection issue
A path-disclosure vulnerability
Multiple cross-site scripting issues
Multiple information-disclosure vulnerabilities
A URI-redirection vulnerability
A security-bypass vulnerability
A cross-site request-forgery vulnerability
A denial-of-service vulnerability
An attacker can exploit these vulnerabilities to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site, steal cookie-based authentication credentials, disclose or modify sensitive information, exploit latent vulnerabilities in the underlying database, deny service to legitimate users, redirect a victim to a potentially malicious site, or perform unauthorized actions. Other attacks are also possible.
Versions prior to Joomla! 1.6.1 are vulnerable.
Exploit / POC
Joomla! Prior to 1.6.1 Multiple Security Vulnerabilities
Attackers can exploit these issues via a browser. To exploit the cross-site scripting issue, an attacker must entice an unsuspecting user into following a malicious URI.
Attackers can exploit these issues via a browser. To exploit the cross-site scripting issue, an attacker must entice an unsuspecting user into following a malicious URI.
Solution / Fix
Joomla! Prior to 1.6.1 Multiple Security Vulnerabilities
Solution:
The vendor released a patch. Please see the references for more information.
Solution:
The vendor released a patch. Please see the references for more information.
References
Joomla! Prior to 1.6.1 Multiple Security Vulnerabilities
References:
References:
- Joomla 1.6.1 Released (Joomla)
- Joomla Homepage (Joomla)