Lost Password?
  • Narrow screen resolution
  • Wide screen resolution
  • Auto width resolution
  • Increase font size
  • Decrease font size
  • Default font size
  • default color
  • red color
  • green color

Software Plugins | Website

Monday
Oct 06th
SoftPlug Home
Joomla Vulnerability for 1.0.12 PDF Print E-mail
Cindy Chee has discovered a vulnerability in Joomla!, which can be exploited by malicious people to conduct cross-site scripting attacks.

Input passed to the "Title" and "Section Name" form fields when creating new sections in Section Manager is not properly sanitised before being stored. This can be exploited to insert arbitrary HTML and script code, which is executed in a user's browser session in context of an affected site when the data is viewed.

Successful exploitation requires that the target user has valid administrator credentials.

The vulnerability is confirmed in version 1.0.12. Other versions may also be affected.

Solution:
Do not browse untrusted sites when logged in as administrator.

Provided and/or discovered by:
Cindy Chee

Original Advisory:
http://joomlacode.org/gf/project/joomla/tracker/?action=TrackerItemEdit&tracker_item_id=5654
Comments (0)Add Comment

Write comment
quote
bold
italicize
underline
strike
url
image
quote
quote
smile
wink
laugh
grin
angry
sad
shocked
cool
tongue
kiss
cry
smaller | bigger

security code
Write the displayed characters


busy
 
< Prev   Next >

Translator

Login Form






Lost Password?

Polls

What you think about this website (Softplug.net)?
 

Syndicate