diff --git a/security/vuxml/vuln.xml b/security/vuxml/vuln.xml index 07db7f71a818..a25567f1385d 100644 --- a/security/vuxml/vuln.xml +++ b/security/vuxml/vuln.xml @@ -34,6 +34,56 @@ Note: Please add new entries to the beginning of this file. --> + + joomla -- multiple vulnerabilities + + + joomla15 + 1.5.11.5.15 + + + + +

Joomla! reported the following vulnerabilities:

+
+

If a user entered a URL with a negative query limit + or offset, a PHP notice would display revealing information + about the system..

+
+
+

The migration script in the Joomla! installer does not + check the file type being uploaded. If the installation + application is present, an attacker could use it to + upload malicious files to a server.

+
+
+

Session id doesn't get modified when user logs in. A + remote site may be able to forward a visitor to the + Joomla! site and set a specific cookie. If the user + then logs in, the remote site can use that cookie to + authenticate as that user.

+
+
+

When a user requests a password reset, the reset tokens + were stored in plain text in the database. While this + is not a vulnerability in itself, it allows user accounts + to be compromised if there is an extension on the site + with an SQL injection vulnerability.

+
+ +
+ + http://developer.joomla.org/security/news/308-20100423-core-password-reset-tokens.html + http://developer.joomla.org/security/news/309-20100423-core-sessation-fixation.html + http://developer.joomla.org/security/news/310-20100423-core-installer-migration-script.html + http://developer.joomla.org/security/news/311-20100423-core-negative-values-for-limit-and-offset.html + + + 2010-04-23 + 2010-04-26 + +
+ cacti -- SQL injection and command execution vulnerabilities @@ -62,10 +112,12 @@ Note: Please add new entries to the beginning of this file. ports/146021 http://www.bonsai-sec.com/en/research/vulnerabilities/cacti-os-command-injection-0105.php http://www.bonsai-sec.com/en/research/vulnerabilities/cacti-sql-injection-0104.php + http://www.debian.org/security/2010/dsa-2039 2010-04-21 2010-04-24 + 2010-04-26