Security

  1. [20130407] - Core - XSS Vulnerability
    • Project: Joomla!
    • SubProject: All
    • Severity: Low
    • Versions: 2.5.9 and earlier 2.5.x versions. 3.0.3 and earlier 3.0.x versions.
    • Exploit type: XSS Vulnerability
    • Reported Date: 2013-April-17
    • Fixed Date: 2013-April-24
    • CVE Number: CVE-2013-3267

    Description

    Inadequate filtering leads to XSS vulnerability in highlighter plugin.

    Affected Installs

    Joomla! version 2.5.9 and earlier 2.5.x versions; and version 3.0.2 and earlier 3.0.x versions.

    Solution

    Upgrade to version 2.5.10,  3.1.0 or 3.0.4.

    Contact

    The JSST at the Joomla! Security Center.

    Reported By: Vertical Pigeon
  2. [20130401] - Core - Privilege Escalation
    • Project: Joomla!
    • SubProject: All
    • Severity: Low
    • Versions: 2.5.9 and earlier 2.5.x versions. 3.0.3 and earlier 3.0.x versions.
    • Exploit type: Privilege Escalation
    • Reported Date: 2013-March-29
    • Fixed Date: 2013-April-24
    • CVE Number: CVE-2013-3056

    Description

    Inadequate permission checking allows unauthorised user to delete private messages.

    Affected Installs

    Joomla! version 2.5.9 and earlier 2.5.x versions; and version 3.0.2 and earlier 3.0.x versions.

    Solution

    Upgrade to version 2.5.10,  3.1.0 or 3.0.4.

    Contact

    The JSST at the Joomla! Security Center.

    Reported By: Francois Gauthier
  3. [20130403] - Core - XSS Vulnerability
    • Project: Joomla!
    • SubProject: All
    • Severity: Moderate
    • Versions: 2.5.9 and earlier 2.5.x versions. 3.0.3 and earlier 3.0.x versions.
    • Exploit type: XSS Vulnerability
    • Reported Date: 2013-March-9
    • Fixed Date: 2013-April-24
    • CVE Number: CVE-2013-3058

    Description

    Inadequate filtering allows possibility of XSS exploit in some circumstances.

    Affected Installs

    Joomla! version 2.5.9 and earlier 2.5.x versions; and version 3.0.2 and earlier 3.0.x versions.

    Solution

    Upgrade to version 2.5.10,  3.1.0 or 3.0.4.

    Contact

    The JSST at the Joomla! Security Center.

    Reported By: James Kettle
  4. [20130405] - Core - XSS Vulnerability
    • Project: Joomla!
    • SubProject: All
    • Severity: Low
    • Versions: 2.5.9 and earlier 2.5.x versions. 3.0.3 and earlier 3.0.x versions.
    • Exploit type: XSS Vulnerability
    • Reported Date: 2013-February-26
    • Fixed Date: 2013-April-24
    • CVE Number: CVE-2013-3059

    Description

    Inadequate filtering leads to XSS vulnerability in Voting plugin.

    Affected Installs

    Joomla! version 2.5.9 and earlier 2.5.x versions; and version 3.0.2 and earlier 3.0.x versions.

    Solution

    Upgrade to version 2.5.10,  3.1.0 or 3.0.4.

    Contact

    The JSST at the Joomla! Security Center.

    Reported By: Yannick Gaultier and Jeff Channell
  5. [20130402] - Core - Information Disclosure
    • Project: Joomla!
    • SubProject: All
    • Severity: Low
    • Versions: 2.5.9 and earlier 2.5.x versions. 3.0.3 and earlier 3.0.x versions.
    • Exploit type: Information Disclosure
    • Reported Date: 2013-March-29
    • Fixed Date: 2013-April-24
    • CVE Number: CVE-2013-3057

    Description

    Inadequate permission checking allows unauthorised user to see permission settings in some circumstances.

    Affected Installs

    Joomla! version 2.5.9 and earlier 2.5.x versions; and version 3.0.2 and earlier 3.0.x versions.

    Solution

    Upgrade to version 2.5.10,  3.1.0 or 3.0.4.

    Contact

    The JSST at the Joomla! Security Center.

    Reported By: Francois Gauthier

Latest Interviews

drogbaPodolski: We're contenders for gold

Any player whose presence at the first training session of a new season prompts a turn-out in excess.

Read more...

drogbaRonaldo: Don't count us out

On the eve of his country’s South Africa 2010 bow, Portugal’s captain is quietly confident.

Read more...

drogbaDrogba: I'm afraid of nothing

His country's captain and primary source of goals, Didier Drogba has already won his first battle.

Read more...

About HOT Carousel Pro

Hot Joomla Carousel Pro is an advanced version of our popular module. Led by the popularity of this module, we created an advanced version with many new features. In addition to the image rotation mode, we've added an option for the rotation of articles that module can take over from sections or categories.

This extensions is sold separately for $9.95, but if you buy Hot Sportal template, you get it FREE!

About HOT Scroller (new!)

This module will create a Joomla Scroller of your content pages. You can select section or category of articles, or pick separate articles. This is perfect Joomla News Ticker for all kind of news portals powered by Joomla!

It can be purchased separately ($9.95), but you will get it FREE with Joomla Sports Template Hot Sporta!.

About HOT Lightbox (new!)

Hot Lightbox module ($9.95 value) allows you to include series of images from any directory on your server. This module automatically creates thumbnails from your images, as per given parameters. All you need to do is to select a directory with your images.

Our members or buyers of the Hot Sportal template will get this module FREE!

4 in 1

That's true! With purchase of the Hot Sportal template, you will get not the template only, but all extensions we used to build this demo! You can copy this demo site on your server easily, just follow the HotStart instructions from the template documentation

Hot Sportal template, plus Hot Joomla Carousel, plus Hot Scroller, plus Hot Lightbox, altogether for just $19.95 (or $39.95 for Developer license)!

top