|
Saturday, 01 August 2009 00:00
The Joomla component Joo!BB 0.9.1 suffers from multiple persistent XSS vulnerabilities in its BBCode implementation, as well as Blind SQL Injection in its search feature.
These vulnerabilities have been patched and users are strongly urged to update to 0.9.1 Patch 1
Timeline
Last Updated on Thursday, 30 September 2010 17:39
Thursday, 16 July 2009 12:04
The Joomla component Agora 3.0.0 RC1 Rev.4 suffers from a Persistent XSS vulnerability. This can be exploited by uploading a malicious SWF file as an attachment then embedding it using the [swf] BBCode tag from the local server, thus bypassing any crossdomain policy.
Last Updated on Thursday, 30 September 2010 17:41
Saturday, 11 July 2009 23:37
Well, another XSS vulnerable BBCode implementation, this time on JTag Ticketing System. This is the exact same vulnerability I posted about earlier concerning WebAmoeba.
Friday, 10 July 2009 10:34
The Joomla component uddeIM is vulnerable to XSS injection in its BBCode implementation. Extra CSS parameters can be passed inside the [color] tag, and Internet Explorer versions before 8 will run scripts using the 'expression()' CSS function.
Last Updated on Friday, 10 July 2009 10:42
|
Featured Extensions
|
$25.00
|
$3.00
FREE You Save: $3.00 |
$3.00
FREE You Save: $3.00 |
$1.00
FREE You Save: $1.00 |
Latest Articles
Most Popular
The Joomla!® name is used under a limited license from Open Source Matters in the United States and other countries. Jeff Channell is not affiliated with or endorsed by Open Source Matters or the Joomla!® Project.

Joomla!

