Adobe Flash TextField.variable Setter – Use-After-Free
Admin Management Xtended <= 2.4.0 – Privilege Escalation
Брой прочитания на тази страница: 1233
[20151205] – Session – Remote Code Execution Vulnerability
Project: Joomla! Framework
SubProject: Session
Severity: High
Versions: 1.0.0 through 1.3.0
Exploit type: Remote Code Execution
Reported Date: 2015-December-13
Fixed Date: 2015-December-14
CVE Number: CVE-2015-8566
Description
Browser information is …
[20151201] – Core – Remote Code Execution Vulnerability
- Project: Joomla!
- SubProject: CMS
- Severity: High
- Versions: 1.5.0 through 3.4.5
- Exploit type: Remote Code Execution
- Reported Date: 2015-December-13
- Fixed Date: 2015-December-14
- CVE Numbers: CVE-2015-8562
Description
Browser information is not filtered properly while saving the session values into the database which leads to a Remote Code Execution vulnerability.
Affected Installs
Joomla! CMS versions 1.5.0 through 3.4.5
Solution
Upgrade to version 3.4.6
Contact
The JSST at the Joomla! Security Centre.
Reported By: Uwe Flottemensch
[20151202] – Core – CSRF Hardening
- Project: Joomla!
- SubProject: CMS
- Severity: Low
- Versions: 3.2.0 through 3.4.5
- Exploit type: CSRF
- Reported Date: 2015-November-26
- Fixed Date: 2015-December-14
- CVE Number: CVE-2015-8563
Description
Add additional CSRF hardening in com_templates.
Affected Installs
Joomla! CMS versions 3.2.0 through 3.4.5
Solution
Upgrade to version 3.4.6
Contact
The JSST at the Joomla! Security Centre.
Reported By: Phil Taylor

