• 301 777 99 61
  • nadosub@gmail.com

    News Feed Category

    Joomla! Security News

    1. [20171103] - Core - Information Disclosure

      • Project: Joomla!
      • SubProject: CMS
      • Severity: Low
      • Versions: 3.7.0 through 3.8.1
      • Exploit type: Information Disclosure
      • Reported Date: 2017-May-17
      • Fixed Date: 2017-November-07
      • CVE Number: CVE-2017-16633

      Description

      A logic bug in com_fields exposed read-only information about a site's custom fields to unauthorized users.

      Affected Installs

      Joomla! CMS versions 3.7.0 through 3.8.1

      Solution

      Upgrade to version 3.8.2

      Contact

      The JSST at the Joomla! Security Centre.

      Reported By: Internal JSST audit
    2. [20171102] - Core - 2-factor-authentication bypass

      • Project: Joomla!
      • SubProject: CMS
      • Severity: Medium
      • Versions: 3.2.0 through 3.8.1
      • Exploit type: 
      • Reported Date: 2017-October-31
      • Fixed Date: 2017-November-07
      • CVE Number: CVE-2017-16634

      Description

      A bug allowed third parties to bypass a user's 2-factor-authentication method.

      Affected Installs

      Joomla! CMS versions 3.2.0 through 3.8.1

      Solution

      Upgrade to version 3.8.2

      Contact

      The JSST at the Joomla! Security Centre.

      Reported By:Yarince
    3. [20171101] - Core - LDAP Information Disclosure

      • Project: Joomla!
      • SubProject: CMS
      • Severity: Medium
      • Versions: 1.5.0 through 3.8.1
      • Exploit type: Information Disclosure
      • Reported Date: 2017-October-06
      • Fixed Date: 2017-November-07
      • CVE Number: CVE-2017-14596

      Description

      Inadequate escaping in the LDAP authentication plugin can result in disclosure of username and password.

      Affected Installs

      Joomla! CMS versions 1.5.0 through 3.8.1

      Solution

      Upgrade to version 3.8.2

      Contact

      The JSST at the Joomla! Security Centre.

      Reported By:Dr. Johannes Dahse, RIPS Technologies GmbH
    4. [20170901] - Core - Information Disclosure

      • Project: Joomla!
      • SubProject: CMS
      • Severity: Low
      • Versions: 3.7.0 through 3.7.5
      • Exploit type: Information Disclosure
      • Reported Date: 2017-August-4
      • Fixed Date: 2017-September-19
      • CVE Number: CVE-2017-14595

      Description

      A logic bug in a SQL query could lead to the disclosure of article intro texts when these articles are in the archived state.

      Affected Installs

      Joomla! CMS versions 3.7.0 through 3.7.5

      Solution

      Upgrade to version 3.8.0

      Contact

      The JSST at the Joomla! Security Centre.

      Reported By:Michal Prochaczek
    5. [20170902] - Core - LDAP Information Disclosure

      • Project: Joomla!
      • SubProject: CMS
      • Severity: Medium
      • Versions: 1.5.0 through 3.7.5
      • Exploit type: Information Disclosure
      • Reported Date: 2017-July-27
      • Fixed Date: 2017-September-19
      • CVE Number: CVE-2017-14596

      Description

      Inadequate escaping in the LDAP authentication plugin can result into a disclosure of username and password.

      Affected Installs

      Joomla! CMS versions 1.5.0 through 3.7.5

      Solution

      Upgrade to version 3.8.0

      Contact

      The JSST at the Joomla! Security Centre.

      Reported By:Dr. Johannes Dahse, RIPS Technologies GmbH

    Lugar y Horario de Trabajo

    Actualmente trabajamos en el complejo acuático, en la piscina semi-olimpica  de 5.00 a.m. a 8.00 a.m. todas las edades, de 4.00 a 6.00 p.m. niños entre 6 y 12 años, 6.00 a 8.00 p.m. adolescentes y adultos jovenes entre 14 años y 25 años, adultos de 8.00 a 9.30 p.m.

    Ultimas Noticias