foto1 foto2 foto3 foto4 foto5


Watch

Love

SFbBox by psd to wordpress

Click

Support

donate200

Mind

Film Fest

mf logo small

Event

immortalcon

Feed

Joomla! Security News

  1. [20171103] - Core - Information Disclosure

    • Project: Joomla!
    • SubProject: CMS
    • Severity: Low
    • Versions: 3.7.0 through 3.8.1
    • Exploit type: Information Disclosure
    • Reported Date: 2017-May-17
    • Fixed Date: 2017-November-07
    • CVE Number: CVE-2017-16633

    Description

    A logic bug in com_fields exposed read-only information about a site's custom fields to unauthorized users.

    Affected Installs

    Joomla! CMS versions 3.7.0 through 3.8.1

    Solution

    Upgrade to version 3.8.2

    Contact

    The JSST at the Joomla! Security Centre.

    Reported By: Internal JSST audit
  2. [20171102] - Core - 2-factor-authentication bypass

    • Project: Joomla!
    • SubProject: CMS
    • Severity: Medium
    • Versions: 3.2.0 through 3.8.1
    • Exploit type: 
    • Reported Date: 2017-October-31
    • Fixed Date: 2017-November-07
    • CVE Number: CVE-2017-16634

    Description

    A bug allowed third parties to bypass a user's 2-factor-authentication method.

    Affected Installs

    Joomla! CMS versions 3.2.0 through 3.8.1

    Solution

    Upgrade to version 3.8.2

    Contact

    The JSST at the Joomla! Security Centre.

    Reported By:Yarince
  3. [20171101] - Core - LDAP Information Disclosure

    • Project: Joomla!
    • SubProject: CMS
    • Severity: Medium
    • Versions: 1.5.0 through 3.8.1
    • Exploit type: Information Disclosure
    • Reported Date: 2017-October-06
    • Fixed Date: 2017-November-07
    • CVE Number: CVE-2017-14596

    Description

    Inadequate escaping in the LDAP authentication plugin can result in disclosure of username and password.

    Affected Installs

    Joomla! CMS versions 1.5.0 through 3.8.1

    Solution

    Upgrade to version 3.8.2

    Contact

    The JSST at the Joomla! Security Centre.

    Reported By:Dr. Johannes Dahse, RIPS Technologies GmbH
  4. [20170901] - Core - Information Disclosure

    • Project: Joomla!
    • SubProject: CMS
    • Severity: Low
    • Versions: 3.7.0 through 3.7.5
    • Exploit type: Information Disclosure
    • Reported Date: 2017-August-4
    • Fixed Date: 2017-September-19
    • CVE Number: CVE-2017-14595

    Description

    A logic bug in a SQL query could lead to the disclosure of article intro texts when these articles are in the archived state.

    Affected Installs

    Joomla! CMS versions 3.7.0 through 3.7.5

    Solution

    Upgrade to version 3.8.0

    Contact

    The JSST at the Joomla! Security Centre.

    Reported By:Michal Prochaczek
  5. [20170902] - Core - LDAP Information Disclosure

    • Project: Joomla!
    • SubProject: CMS
    • Severity: Medium
    • Versions: 1.5.0 through 3.7.5
    • Exploit type: Information Disclosure
    • Reported Date: 2017-July-27
    • Fixed Date: 2017-September-19
    • CVE Number: CVE-2017-14596

    Description

    Inadequate escaping in the LDAP authentication plugin can result into a disclosure of username and password.

    Affected Installs

    Joomla! CMS versions 1.5.0 through 3.7.5

    Solution

    Upgrade to version 3.8.0

    Contact

    The JSST at the Joomla! Security Centre.

    Reported By:Dr. Johannes Dahse, RIPS Technologies GmbH

Tube

Who is

IMDb

Out of My Head TV

youtube

TEAM GAME

sponsors

Visions

#DailyDose

Quote of the Day

247 Ink Mag

247

Tune in to The POD

podsmall

Films & Events
Peepers