Брой прочитания на тази страница: 1685
Podlove Podcast Publisher <= 2.3.15 – Multiple SQLi & XSS
Брой прочитания на тази страница: 1249
All In One WP Security & Firewall <= 4.2.1 – Cross-Site Scripting (XSS)
Брой прочитания на тази страница: 1461
[20161204] – Misc. Security Hardening
Project: Joomla!
SubProject: CMS
Description
Joomla! 3.6.5 includes additional security hardening mechanisms prepared by the JSST, thanks in part to issue reports from Fotis Evangelou and Nicholas Dionysopoulos, which restricts a user’s ability …
[20161203] – Core – Information Disclosure
- Project: Joomla!
- SubProject: CMS
- Severity: Low
- Versions: 3.0.0 through 3.6.4
- Exploit type: Information Disclosure
- Reported Date: 2016-April-15
- Fixed Date: 2016-December-06
- CVE Number: CVE-2016-9837
Description
Inadequate ACL checks in the Beez3 com_content article layout override enables a user to view restricted content.
Affected Installs
Joomla! CMS versions 3.0.0 through 3.6.4
Solution
Upgrade to version 3.6.5
Contact
The JSST at the Joomla! Security Centre.
Reported By: Christiaan Klatte and Brian Teeman

