Joomla Security News

Joomla Security News

Below you will find the latest security news from Joomla.org's J.S.S.T. (Joomla Security Strike Team). It is imperitive for the security of your website and that of the server that you maintain your Joomla installation up to date with the latest release. If you require assistance in upgrading your website we are available to do this for you. Just visit our Joomla Upgrade page.

Joomla! Developer Network - Security News

Joomla! - the dynamic portal engine and content management system

  • — [20120202] - Core - Information Disclosure

       (Thursday, 02 February 2012 00:25)

    • Project: Joomla!
    • SubProject: All
    • Severity: Moderate
    • Versions: 1.7.4 and all earlier 1.7.x versions
    • Exploit type: Information Disclosure
    • Reported Date: 2012-January-06
    • Fixed Date: 2012-February-02

    Description

    On some servers the error log could be read by unauthorised users.

    Affected Installs

    Joomla! version 1.7.4 and all earlier 1.7.x versions

    Solution

    Upgrade to version 2.5.1 or 1.7.5 or higher

    Reported by Alain Rivest

    Contact

    The JSST at the Joomla! Security Center.

  • — [20120203] - Core - Information Disclosure

       (Thursday, 02 February 2012 00:25)

    • Project: Joomla!
    • SubProject: All
    • Severity: Low
    • Versions: 2.5.0 and 1.7.0 - 1.7.4
    • Exploit type: Information Disclosure
    • Reported Date: 2012-January-29
    • Fixed Date: 2012-February-02

    Description

    Inadequate validation leads to path disclosure in administrator.

    Affected Installs

    Joomla! version 2.5.0, 1.7.4, and all earlier 1.7.x versions

    Solution

    Upgrade to version 2.5.1 or 1.7.5 or higher

    Reported by Jakub Galczyk

    Contact

    The JSST at the Joomla! Security Center.

  • — [20120201] - Core - Information Disclosure

       (Thursday, 02 February 2012 00:25)

    • Project: Joomla!
    • SubProject: All
    • Severity: Low
    • Versions: 2.5.0 and 1.7.0 - 1.7.4
    • Exploit type: Information Disclosure
    • Reported Date: 2012-January-29
    • Fixed Date: 2012-February-02

    Description

    Inadequate validation leads to information disclosure in administrator.

    Affected Installs

    Joomla! version 2.5.0, 1.7.4, and all earlier 1.7.x versions

    Solution

    Upgrade to version 1.7.5 or 2.5.1 or higher

    Reported by Jakub Galczyk

    Contact

    The JSST at the Joomla! Security Center.

 
Banner

LiveZilla Live Help

Affordable Hosting Sign-Up


carbon_negative

Español(Spanish Formal International)English (United Kingdom)

You are here:

Is Joomla right for you?

sam-1Over the years our team has accumulated extensive knowledge on Joomla's practical use as a Content Management System in multiple usage environments. Is Joomla really right for you? Let's answer that question first. Contact us today and take that first step.

Our experience with Joomla will be put to work for you the moment you contact us.
footer_logos