Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [thread-next>] [day] [month] [year] [list]
Date: Thu, 26 Feb 2015 12:28:40 +0100
From: Hanno Böck <>
Subject: CVE request: Joomla Google Maps Plugin


Akamai is currently warning of old versions of a joomla google maps
plugin. Akamai advisory:

These vulns have not seen CVEs as far as I can see. They have been fixed
in 3.1. This is the developers announcement:

And here are some more details:

1 Denial of Service / reflection issue (this seems the one akamai is
most concerned about)
1 XML injection
1 path disclosure
1 anti automation (not sure this counts as a vulnerability)

I've added detection to freewvs [1] (which is btw a tool you might find
interesting, although its functionality overlaps with a similar tool
called pyfiscan and there are some preliminary plans to maybe merge the
development work of the two in the future).


Hanno Böck


Content of type "application/pgp-signature" skipped

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.