Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [thread-next>] [day] [month] [year] [list]
Message-ID: <20150226122840.56ca6cbf@pc>
Date: Thu, 26 Feb 2015 12:28:40 +0100
From: Hanno Böck <hanno@...eck.de>
To: oss-security@...ts.openwall.com
Subject: CVE request: Joomla Google Maps Plugin

Hi,

Akamai is currently warning of old versions of a joomla google maps
plugin. Akamai advisory:
http://www.stateoftheinternet.com/resources-web-security-threat-advisories-2015-joomla-reflection-attack-ddos-for-hire.html

These vulns have not seen CVEs as far as I can see. They have been fixed
in 3.1. This is the developers announcement:
http://tech.reumer.net/Google-Maps/Documentation-of-plugin-Googlemap/security-release-3-1-of-plugin-googlemaps.html

And here are some more details:
http://cxsecurity.com/issue/WLB-2014020215

1 Denial of Service / reflection issue (this seems the one akamai is
most concerned about)
1 XML injection
2 XSS
1 path disclosure
1 anti automation (not sure this counts as a vulnerability)

I've added detection to freewvs [1] (which is btw a tool you might find
interesting, although its functionality overlaps with a similar tool
called pyfiscan and there are some preliminary plans to maybe merge the
development work of the two in the future).

[1] https://source.schokokeks.org/freewvs/

cu,
-- 
Hanno Böck
http://hboeck.de/

mail/jabber: hanno@...eck.de
GPG: BBB51E42

Content of type "application/pgp-signature" skipped

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.