| Vigil@nce team describes computer vulnerabilities impacting your systems, and offers solutions to correct them. |
|
 |
|
|
|
vulnerability alert 8831
Joomla: several vulnerabilities
Synthesis of the vulnerability
| An attacker can execute JavaScript code in the context of the web site, or obtain internal information on Joomla. |
Severity: 2/4.
Creation date: 01/07/2009.
Revision date: 03/07/2009.
|
Description of the vulnerability
Three vulnerabilities were announced in Joomla.
The HTTP_REFERER variable, which contains the Referer header, is not correctly filtered. An attacker can therefore generate a Cross Site Scripting. [severity:2/4; 20090604, >]
The PHP_SELF variable, which contains a fragment of the requested url, is not correctly filtered. An attacker can therefore generate a Cross Site Scripting. [severity:2/4; 20090605, >]
Some PHP scripts do not use _JEXEC to limit their access. An attacker can therefore directly call these scripts, to generate an error which displays the installation path of Joomla. [severity:2/4; 20090606, >] |
Complete Vigil@nce bulletin
Characteristics
Title: Joomla: several vulnerabilities.
Keywords: 20090604 20090605 20090606 Cross HTTP_REFERER JavaScript Joomla PHP PHP_SELF Referer Scripting Site _JEXEC several vulnerabilities.
Identifiers: 20090604, 20090605, 20090606, BID-35544, VIGILANCE-VUL-8831.
|
Solutions for this vulnerability
Supplements
Vulnerability : HTTP_REFERER
The HTTP_REFERER variable, which contains the Referer header, is not correctly filtered. An attacker can therefore generate a Cross Site Scripting.
Severity: 2/4.
Identifiers: 20090604.
|
|
Vulnerability : PHP_SELF
The PHP_SELF variable, which contains a fragment of the requested url, is not correctly filtered. An attacker can therefore generate a Cross Site Scripting.
Severity: 2/4.
Identifiers: 20090605.
|
|
Vulnerability : JEXEC
Some PHP scripts do not use _JEXEC to limit their access. An attacker can therefore directly call these scripts, to generate an error which displays the installation path of Joomla.
Severity: 2/4.
Identifiers: 20090606.
|
|
Computer vulnerabilities tracking service
The Vigil@nce computer vulnerability tracking service alerts your teams of vulnerabilities or threats impacting your information system.
The Vigil@nce vulnerability database contains several thousand vulnerabilities.
This bulletin is published by the Vigil@nce team, which tracks computer vulnerabilities impacting systems and applications.
Computer vulnerability bulletins
|