Topic : | joomla multiple vuln.
|
SecurityAlert : 4275
CVE : CVE-2008-4103 CVE : CVE-2008-4104 CVE : CVE-2008-4105 CWE : CWE-20
SecurityRisk : Medium (About)
Remote Exploit : Yes
Local Exploit : No
Victim interaction required : No
Exploit Available : No
Credit : Emanuele Gentili
Published : 20.09.2008
Updated : 21.09.2008
Affected Software : | joomla:com_mailto |
 Advisory Content : http://developer.joomla.org/security/news/271-20080901-core-jrequest-variab
le-injection.html
http://developer.joomla.org/security/news/272-20080902-core-random-number-g
eneration-flaw.html
http://developer.joomla.org/security/news/273-20080903-core-commailto-spam.
html
http://developer.joomla.org/security/news/274-20080904-core-redirect-spam.h
tml
E.
--
Emanuele Gentili | http://launchpad.net/~emgent
emgent@ubuntu.com | Ubuntu Security Developer
emgent@windowmaker.info | Window Maker Developer
emgent@rapache.org | Rapache Developer
emanuele.gentili@community.joomla.org | Joomla! Security Developer
Key fingerprint: F4B7 0793 069A 217E BB9F 8925 E0AC 34C2 2201 1E9A
gpg --keyserver keyserver.ubuntu.com --recv-keys 22011E9A
References :
http://marc.info/?l=oss-security&m=122152798516853&w=2
http://marc.info/?l=oss-security&m=122118210029084&w=2
http://marc.info/?l=oss-security&m=1221153415232&w=2
http://developer.joomla.org/security/news/273-20080903-core-commailto-spam.html
Feedback :
If you have additional information or notice any errors regarding this security advisory, please use contact form or email us at info()securityreason()com.
|