Openwall Project   /home  Owl  JtR  Pro  crypt  pam_passwdqc  tcb  phpass  scanlogd  popa3d  msulogin  /  Linux  BIND  /  advisories  presentations  /  services  donations  /  wordlists  passwords  /  NEWS  community  lists  Wiki  CVSweb  mirrors  signatures
bringing security into open environments
 
Password Recovery Resources on the Net
[<prev] [next>] [thread-next>] [month] [year] [list]
Date: Wed, 13 Aug 2008 02:01:05 +0200
From: Emanuele Gentili <emgent@...ntu.com>
To: oss-security@...ts.openwall.com
Subject: Joomla 1.5.x core.

New hight security issue was found in Joomla 1.5.x that allow remote
admin password change via com_user core component.

More info are available here [¹]

[¹] http://en.emanuele-gentili.com/index.php/wh/joomla/


E.

-- 
Emanuele Gentili 	    | https://edge.launchpad.net/~emgent
emgent@...ntu.com           | Ubuntu Security Developer
emgent@...dowmaker.info     | Window Maker Developer
emgent@...ache.org          | Rapache Developer

Key fingerprint: F4B7 0793 069A 217E BB9F 8925 E0AC 34C2 2201 1E9A
gpg --keyserver keyserver.ubuntu.com --recv-keys 22011E9A


Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Powered by Openwall GNU/*/Linux - Powered by OpenVZ