Recommended Links
If you need hosting for your Joomla! site, be sure to consider web hosting choice for news and reviews.
JomSocial 1.8.8 Shell Upload Vulnerability
Thursday, 30 September 2010 17:05

There is a file upload vulnerability in version 1.8.8 and earlier of JomSocial, the popular community extension for Joomla!.

Last Updated on Thursday, 30 September 2010 17:43
Read more... [JomSocial 1.8.8 Shell Upload Vulnerability]
 
What's In A Name?
Thursday, 23 September 2010 18:01

I know it shouldn't bother me, but I've got to ask - what's so hard about my last name?

Read more... [What's In A Name?]
 
Æthan's Jack-O-Lantern
Friday, 17 September 2010 21:28

My 4 year old drew the face, and I cut it out... here comes Hallowe'en!

Last Updated on Friday, 17 September 2010 21:40
Read more... [Æthan's Jack-O-Lantern]
 
Joomla Component Mosets Tree 2.1.5 Shell Upload Vulnerability
Monday, 13 September 2010 11:46

Mosets Tree suffers from a shell upload vulnerabilty caused by improperly checking the filetype of uploaded images.

Last Updated on Thursday, 30 September 2010 17:34
Read more... [Joomla Component Mosets Tree 2.1.5 Shell Upload Vulnerability]
 
K2 2.3 Persistent XSS Vulnerability
Saturday, 11 September 2010 12:08

K2 v2.3, the popular Joomla! CCK extension, suffers from persistent XSS vulnerabilities in its comment facility.

Last Updated on Thursday, 30 September 2010 17:34
Read more... [K2 2.3 Persistent XSS Vulnerability]
 
I Hacked The JED
Friday, 10 September 2010 19:25

Over the Labor Day weekend I managed to upload and execute arbitrary PHP code on the Joomla! Extensions Directory. That site has been patched, but the patch is not yet publicly available. As soon as it is, I'll post the dirty details of the exploit I used to hack extensions.joomla.org!

Also, please note that I was given permission to do so and nothing of any value was harmed!

extensions.joomla.org - Hacked by jdc

UPDATE: THE JED HAS BEEN PATCHED AND IS NO LONGER VULNERABLE! This was confirmed patched BEFORE this was posted, and WAS NOT EXPLOITED PREVIOUSLY! Nothing was harmed and nothing is at risk!

Last Updated on Friday, 10 September 2010 20:47
 
JComments 2.2.0.0 Persistent XSS
Sunday, 05 September 2010 13:55

JComments 2.2.0.0 suffers from a persistent XSS vulnerability in the way it handles certain BBCodes.

Last Updated on Thursday, 30 September 2010 17:37
Read more... [JComments 2.2.0.0 Persistent XSS]
 
«StartPrev12345NextEnd»

Page 3 of 5

Featured Extensions

$1.00
FREE
You Save: $1.00
$10.00
FREE
You Save: $10.00
$3.00
FREE
You Save: $3.00
$1.00
FREE
You Save: $1.00

The Joomla!® name is used under a limited license from Open Source Matters in the United States and other countries. Jeff Channell is not affiliated with or endorsed by Open Source Matters or the Joomla!® Project.

Santorum
Joomla Extensions