Joomla Unauthorized Access Vulnerabilities

SECUNIA ADVISORY ID:
SA30974

VERIFY ADVISORY:
http://secunia.com/advisories/30974/

CRITICAL:
Moderately critical

IMPACT:
Security Bypass, Exposure of sensitive information

WHERE:
>From remote

SOFTWARE:
Joomla! 1.x
http://secunia.com/product/5788/

DESCRIPTION:
Some vulnerabilities have been reported in Joomla!, which can be
exploited by malicious people to bypass certain security restrictions
and disclose potentially sensitive information.

1) An unspecified error in LDAP can be exploited to gain unauthorized
access to the administration section.

2) An unspecified error within file caching can be exploited to gain
unauthorized access to cached pages.

NOTE: A fix regarding User Redirect Spam and a security enhancement
to the .htaccess file has also been reported.

The vulnerabilities are reported in versions prior to 1.5.4.

SOLUTION:
Update to version 1.5.4.
http://joomlacode.org/gf/project/joomla/frs/?action=FrsReleaseBrowse&frs_package_id=3786

PROVIDED AND/OR DISCOVERED BY:
Reported by the vendor.

ORIGINAL ADVISORY:
http://www.joomla.org/content/view/5180/1/

RECENT ARTICLE

RECENT POST