Joomla! Multiple Cross-Site Scripting Vulnerabilities

SECUNIA ADVISORY ID:
SA41772

VERIFY ADVISORY:
Secunia.com
http://secunia.com/advisories/41772/
Customer Area (Credentials Required)
https://ca.secunia.com/?page=viewadvisory&vuln_id=41772

RELEASE DATE:
2010-10-16
DESCRIPTION:
Multiple vulnerabilities have been reported in Joomla!, which can be
exploited by malicious people to conduct cross-site scripting
attacks.

Input passed via the URL to index.php is not properly sanitised
before being returned to the user. This can be exploited to execute
arbitrary HTML and script code in a user's browser session in context
of an affected website.

The vulnerabilities are reported in versions prior to 1.5.21.

SOLUTION:
Update to version 1.5.21.

PROVIDED AND/OR DISCOVERED BY:
Aung Khant, YEHG

ORIGINAL ADVISORY:
Joomla!:
http://developer.joomla.org/security/news/9-security/10-core-security/322-20101001-core-xss-vulnerabilities.html

YEHG:
http://yehg.net/lab/pr0js/advisories/joomla/core/%5Bjoomla_1.5.20%5D_cross_site_scripting%28XSS%29

RECENT ARTICLE

RECENT POST