040hosting.eu/new/

[20120305] – Core – Password ChangePosted: 28 Mar 2012 12:21 AM PDT

  • Project: Joomla!
  • SubProject: All
  • Severity: High
  • Versions: 1.5.25 and all earlier 1.5.x versions
  • Exploit type: Password Change
  • Reported Date: 2012-March-8
  • Fixed Date: 2012-March-27

Description

Insufficient randomness leads to password reset vulnerability.

Affected Installs

Joomla! versions 1.5.25 and all earlier 1.5.x versions

Solution

Upgrade to version 1.5.26

Reported by George Argyros and Aggelos Kiayias

Contact

The JSST at the Joomla! Security Center.

[20120306] – Core – Information DisclosurePosted: 28 Mar 2012 12:21 AM PDT

  • Project: Joomla!
  • SubProject: All
  • Severity: Low
  • Versions: 1.5.25 and all earlier 1.5.x versions
  • Exploit type: Information Disclosure
  • Reported Date: 2012-January-7
  • Fixed Date: 2012-March-27

Description

Inadequate permission checking allows unauthorised viewing of administrative back end information.

Affected Installs

Joomla! versions 1.5.25 and all earlier 1.5.x versions

Solution

Upgrade to version 1.5.26

Reported by Cyrille Barthelemy

Contact

The JSST at the Joomla! Security Center.

Need really RAW power, our 24 and 32 Core servers are here, and unlike our other servers you can configure them yourself and make them as powerful as you need or your budget allows. available in Europe and the USA. Click here to configure your server.

24/32 Core servers in Europe and the USA

Managed or Unmanaged RAW Power 24 and 32 Core servers

8core budget servers fully managed

040Hosting Fully managed 8 Core budget server in Europe or the USA