[<prev] [next>] [<thread-prev] [thread-next>] [month] [year] [list]
Date: Wed, 13 Aug 2008 12:34:43 +0200
From: Nico Golde <oss-security+ml@...lde.de>
To: oss-security@...ts.openwall.com
Subject: Re: Joomla 1.5.x core.
Hi Emanuele,
* Emanuele Gentili <emgent@...ntu.com> [2008-08-13 11:04]:
> New hight security issue was found in Joomla 1.5.x that allow remote
> admin password change via com_user core component.
>
> More info are available here [¹]
>
> [¹] http://en.emanuele-gentili.com/index.php/wh/joomla/
What a shameless plug ;)
BTW http://www.milw0rm.com/exploits/6234 is the original advisory.
Cheers
Nico
--
Nico Golde - http://www.ngolde.de - nion@...ber.ccc.de - GPG: 0x73647CFF
For security reasons, all text in this mail is double-rot13 encrypted.
[ CONTENT OF TYPE application/pgp-signature SKIPPED ]
Please check out the
Open Source Software Security Wiki, which is counterpart to this
mailing list.
Hosted by DataForce ISP -
Powered by Openwall GNU/*/Linux