<?xml version="1.0" encoding="UTF-8" ?>
<rss version="2.0">
<channel>
	<title>Cartika Company and Application News</title>
	<description>Feed for Cartika news and application updates.</description>
	<link>http://cartikaforum.com</link>
	<pubDate>Fri, 16 Mar 2012 16:00:11 +0000</pubDate>
	<ttl>10</ttl>
	<item>
		<title>Joomla Security Bulletin - March 16, 2012</title>
		<link>http://cartikaforum.com/topic/2542-joomla-security-bulletin-march-16-2012/</link>
		<description><![CDATA[<a href='http://tinyurl.com/86yvfto' class='bbc_url' title='External link' rel='nofollow external'><span style='color: #0000cd'>[20120304] - Core - Password Change</span></a><br />
Posted: 16 Mar 2012 12:21 AM PDT<ul class='bbc'><li>Project: Joomla!<br /></li><li>SubProject: All<br /></li><li>Severity: High<br /></li><li>Versions: 2.5.2, 2.5.1, 2.5.0, and all 1.7.x and 1.6.x releases<br /></li><li>Exploit type: Password Change<br /></li><li>Reported Date: 2012-March-8<br /></li><li>Fixed Date: 2012-March-15</li></ul>
<strong class='bbc'><span style='font-size: 18px;'>Description</span></strong><br />
Insufficient randomness leads to password reset vulnerability.<br />
<br />
<strong class='bbc'><span style='font-size: 18px;'>Affected Installs</span></strong><br />
Joomla! versions 2.5.2, 2.5.1, 2.5.0, and all 1.7.x and 1.6.x versions<br />
<br />
<strong class='bbc'><span style='font-size: 18px;'>Solution</span></strong><br />
Upgrade to version 2.5.3<br />
Reported by George Argyros and Aggelos Kiayias<br />
<br />
<strong class='bbc'>Contact</strong><br />
The JSST at the Joomla! Security Center.<br />
<br />
<br />
<br />
<a href='http://tinyurl.com/6llo57u' class='bbc_url' title='External link' rel='nofollow external'>[20120303] - Core - Privilege Escalation</a><br />
Posted: 15 Mar 2012 05:00 AM PDT<ul class='bbc'><li>Project: Joomla!<br /></li><li>SubProject: All<br /></li><li>Severity: High<br /></li><li>Versions: 2.5.2, 2.5.1, 2.5.0, and all 1.7.x and 1.6.x releases<br /></li><li>Exploit type: Privilege Escalation<br /></li><li>Reported Date: 2012-March-12<br /></li><li>Fixed Date: 2012-March-15</li></ul>
<strong class='bbc'><span style='font-size: 18px;'>Description</span></strong><br />
Programming error allows privilege escalation in some cases.<br />
<br />
<strong class='bbc'><span style='font-size: 18px;'>Affected Installs</span></strong><br />
Joomla! versions 2.5.2, 2.5.1, 2.5.0, and all 1.7.x and 1.6.x versions<br />
<br />
<strong class='bbc'><span style='font-size: 18px;'>Solution</span></strong><br />
Upgrade to version 2.5.3<br />
Reported by Jeff Channel<br />
<br />
<strong class='bbc'>Contact</strong><br />
The JSST at the Joomla! Security Center.]]></description>
		<pubDate>Fri, 16 Mar 2012 16:00:11 +0000</pubDate>
		<guid>http://cartikaforum.com/topic/2542-joomla-security-bulletin-march-16-2012/</guid>
	</item>
	<item>
		<title>Joomla Security Bulletin - February 1, 2012</title>
		<link>http://cartikaforum.com/topic/2475-joomla-security-bulletin-february-1-2012/</link>
		<description><![CDATA[<strong class='bbc'>					<a href='http://developer.joomla.org/security/news.html' class='bbc_url' title='External link' rel='nofollow external'> <span style='color: #888888'><span style='font-family: Arial,sans-serif'><span style='font-size: 14px;'>Joomla! Security News</span></span></span></a></strong><br />
									     		   <ul class='bbc'><li><span style='color: black'><span style='font-family: Arial,sans-serif'><span style='font-size: 8px;'><span style='font-family: Arial,sans-serif'><span style='font-size: 8px;'><strong class='bbc'><span style='color: #000099'>[20120201] - Core - Information Disclosure</span></strong> </span></span></span></span></span><br /></li><li><span style='color: black'><span style='font-family: Arial,sans-serif'><span style='font-size: 8px;'><span style='font-family: Arial,sans-serif'><span style='font-size: 8px;'><strong class='bbc'><span style='color: #000099'>[20120202] - Core - Information Disclosure</span></strong> </span></span></span></span></span><br /></li><li><span style='color: black'><span style='font-family: Arial,sans-serif'><span style='font-size: 8px;'><span style='font-family: Arial,sans-serif'><span style='font-size: 8px;'><strong class='bbc'><span style='color: #000099'>[20120203] - Core - Information Disclosure</span></strong> </span></span></span></span></span></li></ul>
<strong class='bbc'><span style='color: #000099'><span style='font-family: Arial,sans-serif'><span style='font-size: 8px;'>[20120201] - Core - Information Disclosure</span></span></span></strong>			   <br />
<span style='color: #555555'><span style='font-family: Arial,sans-serif'><span style='font-size: 8px;'>Posted: 01 Feb 2012 09:25 PM PST</span></span></span>			   <p class='bbc_indent' style='margin-left: 40px;'>2]<strong class='bbc'><span style='color: black'><span style='font-family: Arial,sans-serif'><span style='font-size: 8px;'>Project:</span></span></span></strong><span style='color: black'><span style='font-family: Arial,sans-serif'><span style='font-size: 8px;'> Joomla!</span></span></span><br /></p><p class='bbc_indent' style='margin-left: 40px;'>2]<strong class='bbc'><span style='color: black'><span style='font-family: Arial,sans-serif'><span style='font-size: 8px;'>SubProject:</span></span></span></strong><span style='color: black'><span style='font-family: Arial,sans-serif'><span style='font-size: 8px;'> All</span></span></span><br /></p><p class='bbc_indent' style='margin-left: 40px;'>2]<strong class='bbc'><span style='color: black'><span style='font-family: Arial,sans-serif'><span style='font-size: 8px;'>Severity:</span></span></span></strong><span style='color: black'><span style='font-family: Arial,sans-serif'><span style='font-size: 8px;'> Low</span></span></span><br /></p><p class='bbc_indent' style='margin-left: 40px;'>2]<strong class='bbc'><span style='color: black'><span style='font-family: Arial,sans-serif'><span style='font-size: 8px;'>Versions:</span></span></span></strong><span style='color: black'><span style='font-family: Arial,sans-serif'><span style='font-size: 8px;'> 2.5.0 and 1.7.0 - 1.7.4</span></span></span><br /></p><p class='bbc_indent' style='margin-left: 40px;'>2]<strong class='bbc'><span style='color: black'><span style='font-family: Arial,sans-serif'><span style='font-size: 8px;'>Exploit type:</span></span></span></strong><span style='color: black'><span style='font-family: Arial,sans-serif'><span style='font-size: 8px;'> Information Disclosure</span></span></span><br /></p><p class='bbc_indent' style='margin-left: 40px;'>2]<strong class='bbc'><span style='color: black'><span style='font-family: Arial,sans-serif'><span style='font-size: 8px;'>Reported Date:</span></span></span></strong><span style='color: black'><span style='font-family: Arial,sans-serif'><span style='font-size: 8px;'> 2012-January-29</span></span></span><br /></p><p class='bbc_indent' style='margin-left: 40px;'>2]<strong class='bbc'><span style='color: black'><span style='font-family: Arial,sans-serif'><span style='font-size: 8px;'>Fixed Date:</span></span></span></strong><span style='color: black'><span style='font-family: Arial,sans-serif'><span style='font-size: 8px;'> 2012-February-02</span></span></span><br />
			   <br />
<strong class='bbc'>					<span style='color: black'><span style='font-family: Arial,sans-serif'>Description</span></span></strong><br />
			   <br />
<span style='color: black'><span style='font-family: Arial,sans-serif'><span style='font-size: 8px;'>Inadequate validation leads to information disclosure in administrator.</span></span></span>			   <br />
<strong class='bbc'>					<span style='color: black'><span style='font-family: Arial,sans-serif'>Affected Installs</span></span></strong><br />
			   <br />
<span style='color: black'><span style='font-family: Arial,sans-serif'><span style='font-size: 8px;'>Joomla! version 2.5.0, 1.7.4, and all earlier 1.7.x versions</span></span></span>			   <br />
<strong class='bbc'>					<span style='color: black'><span style='font-family: Arial,sans-serif'>Solution</span></span></strong><br />
			   <br />
<span style='color: black'><span style='font-family: Arial,sans-serif'><span style='font-size: 8px;'>Upgrade to version 1.7.5 or 2.5.1 or higher</span></span></span>			   <br />
<span style='color: black'><span style='font-family: Arial,sans-serif'><span style='font-size: 8px;'>Reported by Jakub Galczyk</span></span></span>			   <br />
<strong class='bbc'>					<span style='color: black'><span style='font-family: Arial,sans-serif'>Contact</span></span></strong><br />
			   <br />
<span style='color: black'><span style='font-family: Arial,sans-serif'><span style='font-size: 8px;'>The JSST at the Joomla! Security Center.</span></span></span>													   <br />
<strong class='bbc'><span style='color: #000099'><span style='font-family: Arial,sans-serif'><span style='font-size: 8px;'>[20120202] - Core - Information Disclosure</span></span></span></strong>			   <br />
<span style='color: #555555'><span style='font-family: Arial,sans-serif'><span style='font-size: 8px;'>Posted: 01 Feb 2012 09:25 PM PST</span></span></span></p><p class='bbc_indent' style='margin-left: 40px;'>2]<strong class='bbc'><span style='color: black'><span style='font-family: Arial,sans-serif'><span style='font-size: 8px;'>Project:</span></span></span></strong><span style='color: black'><span style='font-family: Arial,sans-serif'><span style='font-size: 8px;'> Joomla!</span></span></span><br /></p><p class='bbc_indent' style='margin-left: 40px;'>2]<strong class='bbc'><span style='color: black'><span style='font-family: Arial,sans-serif'><span style='font-size: 8px;'>SubProject:</span></span></span></strong><span style='color: black'><span style='font-family: Arial,sans-serif'><span style='font-size: 8px;'> All</span></span></span><br /></p><p class='bbc_indent' style='margin-left: 40px;'>2]<strong class='bbc'><span style='color: black'><span style='font-family: Arial,sans-serif'><span style='font-size: 8px;'>Severity:</span></span></span></strong><span style='color: black'><span style='font-family: Arial,sans-serif'><span style='font-size: 8px;'> Moderate</span></span></span><br /></p><p class='bbc_indent' style='margin-left: 40px;'>2]<strong class='bbc'><span style='color: black'><span style='font-family: Arial,sans-serif'><span style='font-size: 8px;'>Versions:</span></span></span></strong><span style='color: black'><span style='font-family: Arial,sans-serif'><span style='font-size: 8px;'> 1.7.4 and all earlier 1.7.x versions</span></span></span><br /></p><p class='bbc_indent' style='margin-left: 40px;'>2]<strong class='bbc'><span style='color: black'><span style='font-family: Arial,sans-serif'><span style='font-size: 8px;'>Exploit type:</span></span></span></strong><span style='color: black'><span style='font-family: Arial,sans-serif'><span style='font-size: 8px;'> Information Disclosure</span></span></span><br /></p><p class='bbc_indent' style='margin-left: 40px;'>2]<strong class='bbc'><span style='color: black'><span style='font-family: Arial,sans-serif'><span style='font-size: 8px;'>Reported Date:</span></span></span></strong><span style='color: black'><span style='font-family: Arial,sans-serif'><span style='font-size: 8px;'> 2012-January-06</span></span></span><br /></p><p class='bbc_indent' style='margin-left: 40px;'>2]<strong class='bbc'><span style='color: black'><span style='font-family: Arial,sans-serif'><span style='font-size: 8px;'>Fixed Date:</span></span></span></strong><span style='color: black'><span style='font-family: Arial,sans-serif'><span style='font-size: 8px;'> 2012-February-02</span></span></span><br />
			   <br />
<strong class='bbc'>					<span style='color: black'><span style='font-family: Arial,sans-serif'>Description</span></span></strong><br />
			   <br />
<span style='color: black'><span style='font-family: Arial,sans-serif'><span style='font-size: 8px;'>On some servers the error log could be read by unauthorised users.</span></span></span>			   <br />
<strong class='bbc'>					<span style='color: black'><span style='font-family: Arial,sans-serif'>Affected Installs</span></span></strong><br />
			   <br />
<span style='color: black'><span style='font-family: Arial,sans-serif'><span style='font-size: 8px;'>Joomla! version 1.7.4 and all earlier 1.7.x versions</span></span></span>			   <br />
<strong class='bbc'>					<span style='color: black'><span style='font-family: Arial,sans-serif'>Solution</span></span></strong><br />
			   <br />
<span style='color: black'><span style='font-family: Arial,sans-serif'><span style='font-size: 8px;'>Upgrade to version 2.5.1 or 1.7.5 or higher</span></span></span>			   <br />
<span style='color: black'><span style='font-family: Arial,sans-serif'><span style='font-size: 8px;'>Reported by Alain Rivest</span></span></span>			   <br />
<strong class='bbc'>					<span style='color: black'><span style='font-family: Arial,sans-serif'>Contact</span></span></strong><br />
			   <br />
<span style='color: black'><span style='font-family: Arial,sans-serif'><span style='font-size: 8px;'>The JSST at the Joomla! Security Center.</span></span></span>													   <br />
<strong class='bbc'><span style='color: #000099'><span style='font-family: Arial,sans-serif'><span style='font-size: 8px;'>[20120203] - Core - Information Disclosure</span></span></span></strong>			   <br />
<span style='color: #555555'><span style='font-family: Arial,sans-serif'><span style='font-size: 8px;'>Posted: 01 Feb 2012 09:25 PM PST</span></span></span></p><p class='bbc_indent' style='margin-left: 40px;'>2]<strong class='bbc'><span style='color: black'><span style='font-family: Arial,sans-serif'><span style='font-size: 8px;'>Project:</span></span></span></strong><span style='color: black'><span style='font-family: Arial,sans-serif'><span style='font-size: 8px;'> Joomla!</span></span></span><br /></p><p class='bbc_indent' style='margin-left: 40px;'>2]<strong class='bbc'><span style='color: black'><span style='font-family: Arial,sans-serif'><span style='font-size: 8px;'>SubProject:</span></span></span></strong><span style='color: black'><span style='font-family: Arial,sans-serif'><span style='font-size: 8px;'> All</span></span></span><br /></p><p class='bbc_indent' style='margin-left: 40px;'>2]<strong class='bbc'><span style='color: black'><span style='font-family: Arial,sans-serif'><span style='font-size: 8px;'>Severity:</span></span></span></strong><span style='color: black'><span style='font-family: Arial,sans-serif'><span style='font-size: 8px;'> Low</span></span></span><br /></p><p class='bbc_indent' style='margin-left: 40px;'>2]<strong class='bbc'><span style='color: black'><span style='font-family: Arial,sans-serif'><span style='font-size: 8px;'>Versions:</span></span></span></strong><span style='color: black'><span style='font-family: Arial,sans-serif'><span style='font-size: 8px;'> 2.5.0 and 1.7.0 - 1.7.4</span></span></span><br /></p><p class='bbc_indent' style='margin-left: 40px;'>2]<strong class='bbc'><span style='color: black'><span style='font-family: Arial,sans-serif'><span style='font-size: 8px;'>Exploit type:</span></span></span></strong><span style='color: black'><span style='font-family: Arial,sans-serif'><span style='font-size: 8px;'> Information Disclosure</span></span></span><br /></p><p class='bbc_indent' style='margin-left: 40px;'>2]<strong class='bbc'><span style='color: black'><span style='font-family: Arial,sans-serif'><span style='font-size: 8px;'>Reported Date:</span></span></span></strong><span style='color: black'><span style='font-family: Arial,sans-serif'><span style='font-size: 8px;'> 2012-January-29</span></span></span><br /></p><p class='bbc_indent' style='margin-left: 40px;'>2]<strong class='bbc'><span style='color: black'><span style='font-family: Arial,sans-serif'><span style='font-size: 8px;'>Fixed Date:</span></span></span></strong><span style='color: black'><span style='font-family: Arial,sans-serif'><span style='font-size: 8px;'> 2012-February-02</span></span></span><br />
			   <br />
<strong class='bbc'>					<span style='color: black'><span style='font-family: Arial,sans-serif'>Description</span></span></strong><br />
			   <br />
<span style='color: black'><span style='font-family: Arial,sans-serif'><span style='font-size: 8px;'>Inadequate validation leads to path disclosure in administrator.</span></span></span>			   <br />
<strong class='bbc'>					<span style='color: black'><span style='font-family: Arial,sans-serif'>Affected Installs</span></span></strong><br />
			   <br />
<span style='color: black'><span style='font-family: Arial,sans-serif'><span style='font-size: 8px;'>Joomla! version 2.5.0, 1.7.4, and all earlier 1.7.x versions</span></span></span>			   <br />
<strong class='bbc'>					<span style='color: black'><span style='font-family: Arial,sans-serif'>Solution</span></span></strong><br />
			   <br />
<span style='color: black'><span style='font-family: Arial,sans-serif'><span style='font-size: 8px;'>Upgrade to version 2.5.1 or 1.7.5 or higher</span></span></span>			   <br />
<span style='color: black'><span style='font-family: Arial,sans-serif'><span style='font-size: 8px;'>Reported by Jakub Galczyk</span></span></span>			   <br />
<strong class='bbc'>					<span style='color: black'><span style='font-family: Arial,sans-serif'>Contact</span></span></strong><br />
			   <br />
<span style='color: black'><span style='font-family: Arial,sans-serif'><span style='font-size: 8px;'>The JSST at the Joomla! Security Center.</span></span></span>			   <br />
					   <br /></p>]]></description>
		<pubDate>Fri, 03 Feb 2012 16:56:43 +0000</pubDate>
		<guid>http://cartikaforum.com/topic/2475-joomla-security-bulletin-february-1-2012/</guid>
	</item>
	<item>
		<title>Joomla Security Bulletin - January 25, 2012</title>
		<link>http://cartikaforum.com/topic/2449-joomla-security-bulletin-january-25-2012/</link>
		<description><![CDATA[<ul class='bbc'><li><strong class='bbc'>[20120101] - Core - Information Disclosure</strong><br /></li><li><strong class='bbc'>[20120102] - Core - XSS Vulnerability</strong><br /></li><li><strong class='bbc'>[20120103] - Core - Information Disclosure</strong><br /></li><li><strong class='bbc'>[20120104] - Core - XSS Vulnerability</strong></li></ul>
<a href='http://developer.joomla.org/security/news/382-20120101-core-information-disclosure.html' class='bbc_url' title='External link' rel='nofollow external'><strong class='bbc'>[20120101] - Core - Information Disclosure</strong></a><br />
 <br />
Posted: 23 Jan 2012 01:45 AM PST<br />
Project: Joomla! SubProject: All Severity: Low Versions: 1.7.3 and all earlier 1.7 and 1.6 versions Exploit type: Information Disclosure Reported Date: 2012-January-07 Fixed Date: 2012-January-24 Description Inadequate filtering leads to information disclosure. Affected Installs Joomla! version 1.7.3 and all earlier versions Solution Upgrade to version 1.7.4 or 2.5.0 or higher Reported by Cyrille Barthelemy Contact The JSST at the Joomla! Security Center.<br />
											       <br />
<a href='http://developer.joomla.org/security/news/383-20120102-core-xss-vulnerability.html' class='bbc_url' title='External link' rel='nofollow external'><strong class='bbc'>[20120102] - Core - XSS Vulnerability</strong></a><br />
Posted: 23 Jan 2012 01:45 AM PST<br />
Project: Joomla! SubProject: All Severity: Moderate Versions: 1.7.3 and all earlier 1.7 and 1.6 versions Exploit type: XSS Vulnerability Reported Date: 2011-November-16 Fixed Date: 2012-January-24 Description Inadequate filtering leads to XSS vulnerability. Affected Installs Joomla! version 1.7.3 and all earlier versions Solution Upgrade to version 1.7.4 or 2.5.0 or higher Reported by Ankita Kapadia Contact The JSST at the Joomla! Security Center.<br />
 <br />
											       <br />
<a href='http://developer.joomla.org/security/news/384-20120103-core-information-disclosure.html' class='bbc_url' title='External link' rel='nofollow external'><strong class='bbc'>[20120103] - Core - Information Disclosure</strong></a><br />
Posted: 23 Jan 2012 01:45 AM PST<br />
Project: Joomla! SubProject: All Severity: Low Versions: 1.7.3 and all earlier 1.7 and 1.6 versions Exploit type: Information Disclosure Reported Date: 2011-December-19 Fixed Date: 2012-January-24 Description Inadequate filtering leads to information disclosure. Affected Installs Joomla! version 1.7.3 and all earlier versions Solution Upgrade to version 1.7.4 or 2.5.0 or higher Reported by Jean-Marie Simonet Contact The JSST at the Joomla! Security Center.<br />
 <br />
											       <br />
<a href='http://developer.joomla.org/security/news/385-20120104-core-xss-vulnerability.html' class='bbc_url' title='External link' rel='nofollow external'><strong class='bbc'>[20120104] - Core - XSS Vulnerability</strong></a><br />
Posted: 23 Jan 2012 01:45 AM PST<br />
Project: Joomla! SubProject: All Severity: Moderate Versions: 1.7.3 and all earlier versions Exploit type: XSS Vulnerability Reported Date: 2012-January-22 Fixed Date: 2012-January-24 Description Inadequate filtering leads to XSS vulnerability. Affected Installs Joomla! version 1.7.3 and all earlier 1.7 and 1.6 versions Solution Upgrade to version 1.7.4 or 2.5.0 or higher Reported by David Jardin Contact The JSST at the Joomla! Security Center.]]></description>
		<pubDate>Wed, 25 Jan 2012 15:40:59 +0000</pubDate>
		<guid>http://cartikaforum.com/topic/2449-joomla-security-bulletin-january-25-2012/</guid>
	</item>
	<item>
		<title>Joomla Security Bulletin - November 14, 2011</title>
		<link>http://cartikaforum.com/topic/2375-joomla-security-bulletin-november-14-2011/</link>
		<description><![CDATA[<ul class='bbc'><li><strong class='bbc'>[20111102] - Core - Password Change</strong><br /></li><li><strong class='bbc'>[20111103] - Core - Password Change</strong><br /></li><li><strong class='bbc'>[20111101] - Core - XSS Vulnerability</strong></li></ul>
<a href='http://feedproxy.google.com/~r/JoomlaSecurityNews/~3/JbROZtZZkvQ/374-20111102-core-password-change.html?utm_source=feedburner&utm_medium=email' class='bbc_url' title='External link' rel='nofollow external'> <strong class='bbc'>[20111102] - Core - Password Change</strong></a><br />
 <br />
 <br />
Posted: 14 Nov 2011 08:33 PM PST<ul class='bbc'><li><strong class='bbc'>Project:</strong> Joomla!<br /></li><li><strong class='bbc'>SubProject:</strong> All<br /></li><li><strong class='bbc'>Severity:</strong> High<br /></li><li><strong class='bbc'>Versions:</strong> 1.7.2 and all 1.6.x versions<br /></li><li><strong class='bbc'>Exploit type:</strong> Password Change<br /></li><li><strong class='bbc'>Reported Date:</strong> 2011-October-28<br /></li><li><strong class='bbc'>Fixed Date:</strong> 2011-November-14</li></ul>
<strong class='bbc'>	Description</strong><br />
 <br />
Weak random number generation during password reset leads to possibility of changing a user's password.<br />
<strong class='bbc'>	Affected Installs</strong><br />
 <br />
Joomla! version 1.7.2 and all earlier 1.7.x and 1.6.x versions<br />
<strong class='bbc'>	Solution</strong><br />
 <br />
Upgrade to the latest Joomla! version (1.7.3 or later)<br />
Reported by David Jardin<br />
<strong class='bbc'>	Contact</strong><br />
 <br />
The JSST at the <a href='http://developer.joomla.org/security.html' class='bbc_url' title='External link' rel='nofollow external'><strong class='bbc'> Joomla! Security Center</strong></a>.<br />
<a href='http://feedproxy.google.com/~r/JoomlaSecurityNews/~3/nF-FZ-0jMUM/375-20111103-core-password-change.html?utm_source=feedburner&utm_medium=email' class='bbc_url' title='External link' rel='nofollow external'> <strong class='bbc'>[20111103] - Core - Password Change</strong></a><br />
Posted: 14 Nov 2011 08:33 PM PST<ul class='bbc'><li><strong class='bbc'>Project:</strong> Joomla!<br /></li><li><strong class='bbc'>SubProject:</strong> All<br /></li><li><strong class='bbc'>Severity:</strong> High<br /></li><li><strong class='bbc'>Versions:</strong> 1.5.24 and all earlier 1.5 versions<br /></li><li><strong class='bbc'>Exploit type:</strong> Password Change<br /></li><li><strong class='bbc'>Reported Date:</strong> 2011-October-28<br /></li><li><strong class='bbc'>Fixed Date:</strong> 2011-November-14</li></ul>
<strong class='bbc'>	Description</strong><br />
 <br />
Weak random number generation during password reset leads to possibility of changing a user's password.<br />
<strong class='bbc'>	Affected Installs</strong><br />
 <br />
Joomla! version 1.5.24 and all earlier 1.5 versions<br />
<strong class='bbc'>	Solution</strong><br />
 <br />
Upgrade to the latest Joomla! 1.5 version (1.5.25 or later)<br />
Reported by David Jardin<br />
<strong class='bbc'>	Contact</strong><br />
 <br />
The JSST at the <a href='http://developer.joomla.org/security.html' class='bbc_url' title='External link' rel='nofollow external'><strong class='bbc'> Joomla! Security Center</strong></a>.<br />
<a href='http://feedproxy.google.com/~r/JoomlaSecurityNews/~3/sz1HyAL_294/373-20111101-core-xss-vulnerability.html?utm_source=feedburner&utm_medium=email' class='bbc_url' title='External link' rel='nofollow external'> <strong class='bbc'>[20111101] - Core - XSS Vulnerability</strong></a><br />
Posted: 14 Nov 2011 08:33 PM PST<ul class='bbc'><li><strong class='bbc'>Project:</strong> Joomla!<br /></li><li><strong class='bbc'>SubProject:</strong> All<br /></li><li><strong class='bbc'>Severity:</strong> Medium<br /></li><li><strong class='bbc'>Versions:</strong> 1.7.2 and all 1.6.x versions<br /></li><li><strong class='bbc'>Exploit type:</strong> XSS<br /></li><li><strong class='bbc'>Reported Date:</strong> 2011-October-21<br /></li><li><strong class='bbc'>Fixed Date:</strong> 2011-November-14</li></ul>
<strong class='bbc'>	Description</strong><br />
 <br />
 <br />
Inadequate filtering leads to XSS vulnerability in back end.<br />
<strong class='bbc'>	Affected Installs</strong><br />
 <br />
Joomla! version 1.7.2 and all earlier 1.7.x and 1.6.x versions<br />
<strong class='bbc'>	Solution</strong><br />
 <br />
Upgrade to the latest Joomla! version (1.7.3 or later)<br />
Reported by Corn&#233; Hannema<br />
<strong class='bbc'>	Contact</strong><br />
 <br />
The JSST at the <a href='http://developer.joomla.org/security.html' class='bbc_url' title='External link' rel='nofollow external'><strong class='bbc'> Joomla! Security Center</strong></a>.]]></description>
		<pubDate>Mon, 14 Nov 2011 15:48:51 +0000</pubDate>
		<guid>http://cartikaforum.com/topic/2375-joomla-security-bulletin-november-14-2011/</guid>
	</item>
	<item>
		<title>Joomla Security Bulletin - October 17, 2011</title>
		<link>http://cartikaforum.com/topic/2359-joomla-security-bulletin-october-17-2011/</link>
		<description><![CDATA[<ul class='bbc'><li><span style='font-family: Arial,sans-serif'><span style='font-size: 8px;'><strong class='bbc'><span style='color: #000099'>[20111001] - Core - Information Disclosure</span></strong> </span></span><br /></li><li><span style='font-family: Arial,sans-serif'><span style='font-size: 8px;'><strong class='bbc'><span style='color: #000099'>[20111002] - Core - Information Disclosure</span></strong> </span></span><br /></li><li><span style='font-family: Arial,sans-serif'><span style='font-size: 8px;'><strong class='bbc'><span style='color: #000099'>[20111003] - Core - Information Disclosure</span></strong> </span></span></li></ul>
<a href='http://feedproxy.google.com/~r/JoomlaSecurityNews/~3/_TyaH8ToZ98/370-20111001-core-information-disclosure.html?utm_source=feedburner&utm_medium=email' class='bbc_url' title='External link' rel='nofollow external'> <strong class='bbc'><span style='color: #000099'><span style='font-family: Arial,sans-serif'><span style='font-size: 8px;'>[20111001] - Core - Information Disclosure</span></span></span></strong></a><br />
 <br />
<span style='font-size: 8px;'>Posted: 17 Oct 2011 01:59 PM PDT</span><br />
<strong class='bbc'><span style='color: black'><span style='font-family: Arial,sans-serif'><span style='font-size: 8px;'>Project:</span></span></span></strong><span style='color: black'><span style='font-family: Arial,sans-serif'><span style='font-size: 8px;'> Joomla!</span></span></span><br />
<strong class='bbc'><span style='color: black'><span style='font-family: Arial,sans-serif'><span style='font-size: 8px;'>SubProject:</span></span></span></strong><span style='color: black'><span style='font-family: Arial,sans-serif'><span style='font-size: 8px;'> All</span></span></span><br />
<strong class='bbc'><span style='color: black'><span style='font-family: Arial,sans-serif'><span style='font-size: 8px;'>Severity:</span></span></span></strong><span style='color: black'><span style='font-family: Arial,sans-serif'><span style='font-size: 8px;'> Moderate</span></span></span><br />
<strong class='bbc'><span style='color: black'><span style='font-family: Arial,sans-serif'><span style='font-size: 8px;'>Versions:</span></span></span></strong><span style='color: black'><span style='font-family: Arial,sans-serif'><span style='font-size: 8px;'> 1.7.1</span></span></span><br />
<strong class='bbc'><span style='color: black'><span style='font-family: Arial,sans-serif'><span style='font-size: 8px;'>Exploit type:</span></span></span></strong><span style='color: black'><span style='font-family: Arial,sans-serif'><span style='font-size: 8px;'> Information Disclosure</span></span></span><br />
<strong class='bbc'><span style='color: black'><span style='font-family: Arial,sans-serif'><span style='font-size: 8px;'>Reported Date:</span></span></span></strong><span style='color: black'><span style='font-family: Arial,sans-serif'><span style='font-size: 8px;'> 2011-September-09</span></span></span><br />
<strong class='bbc'><span style='color: black'><span style='font-family: Arial,sans-serif'><span style='font-size: 8px;'>Fixed Date:</span></span></span></strong><span style='color: black'><span style='font-family: Arial,sans-serif'><span style='font-size: 8px;'> 2011-October-17</span></span></span><br />
<strong class='bbc'>	<span style='color: black'><span style='font-family: Arial,sans-serif'>Description</span></span></strong><br />
 <br />
<span style='font-size: 8px;'>Weak encryption causes potential information disclosure.</span><br />
<strong class='bbc'>	<span style='color: black'><span style='font-family: Arial,sans-serif'>Affected Installs</span></span></strong><br />
 <br />
<span style='font-size: 8px;'>Joomla! version 1.7.1 and earlier</span><br />
<strong class='bbc'>	<span style='color: black'><span style='font-family: Arial,sans-serif'>Solution</span></span></strong><br />
 <br />
<span style='font-size: 8px;'>Upgrade to the latest Joomla! version (1.7.2 or later)</span><br />
<span style='font-size: 8px;'>Reported by Jeff Channell</span><br />
<strong class='bbc'>	<span style='color: black'><span style='font-family: Arial,sans-serif'>Contact</span></span></strong><br />
 <br />
<span style='font-size: 8px;'>The JSST at the <a href='http://developer.joomla.org/security.html' class='bbc_url' title='External link' rel='nofollow external'><strong class='bbc'> <span style='color: #000099'>Joomla! Security Center</span></strong></a>.</span><span style='color: black'><span style='font-family: Arial,sans-serif'><span style='font-size: 8px;'><a href='http://feeds.feedburner.com/~r/JoomlaSecurityNews/~4/_TyaH8ToZ98?utm_source=feedburner&utm_medium=email' class='bbc_url' title='External link' rel='nofollow external'>http://feeds.feedbur...tm_medium=email</a></span></span></span><br />
<a href='http://feedproxy.google.com/~r/JoomlaSecurityNews/~3/Nyl0K1n4nak/371-20111002-core-information-disclosure.html?utm_source=feedburner&utm_medium=email' class='bbc_url' title='External link' rel='nofollow external'> <strong class='bbc'><span style='color: #000099'><span style='font-family: Arial,sans-serif'><span style='font-size: 8px;'>[20111002] - Core - Information Disclosure</span></span></span></strong></a><br />
<span style='font-size: 8px;'>Posted: 17 Oct 2011 01:59 PM PDT</span><br />
<strong class='bbc'><span style='color: black'><span style='font-family: Arial,sans-serif'><span style='font-size: 8px;'>Project:</span></span></span></strong><span style='color: black'><span style='font-family: Arial,sans-serif'><span style='font-size: 8px;'> Joomla!</span></span></span><br />
<strong class='bbc'><span style='color: black'><span style='font-family: Arial,sans-serif'><span style='font-size: 8px;'>SubProject:</span></span></span></strong><span style='color: black'><span style='font-family: Arial,sans-serif'><span style='font-size: 8px;'> All</span></span></span><br />
<strong class='bbc'><span style='color: black'><span style='font-family: Arial,sans-serif'><span style='font-size: 8px;'>Severity:</span></span></span></strong><span style='color: black'><span style='font-family: Arial,sans-serif'><span style='font-size: 8px;'> Low</span></span></span><br />
<strong class='bbc'><span style='color: black'><span style='font-family: Arial,sans-serif'><span style='font-size: 8px;'>Versions:</span></span></span></strong><span style='color: black'><span style='font-family: Arial,sans-serif'><span style='font-size: 8px;'> 1.7.1</span></span></span><br />
<strong class='bbc'><span style='color: black'><span style='font-family: Arial,sans-serif'><span style='font-size: 8px;'>Exploit type:</span></span></span></strong><span style='color: black'><span style='font-family: Arial,sans-serif'><span style='font-size: 8px;'> Information Disclosure</span></span></span><br />
<strong class='bbc'><span style='color: black'><span style='font-family: Arial,sans-serif'><span style='font-size: 8px;'>Reported Date:</span></span></span></strong><span style='color: black'><span style='font-family: Arial,sans-serif'><span style='font-size: 8px;'> 2011-August-02</span></span></span><br />
<strong class='bbc'><span style='color: black'><span style='font-family: Arial,sans-serif'><span style='font-size: 8px;'>Fixed Date:</span></span></span></strong><span style='color: black'><span style='font-family: Arial,sans-serif'><span style='font-size: 8px;'> 2011-October-17</span></span></span><br />
<strong class='bbc'>	<span style='color: black'><span style='font-family: Arial,sans-serif'>Description</span></span></strong><br />
 <br />
<span style='font-size: 8px;'>Inadequate error checking causes potential information disclosure.</span><br />
 <br />
 <br />
<strong class='bbc'>	<span style='color: black'><span style='font-family: Arial,sans-serif'>Affected Installs</span></span></strong><br />
 <br />
<span style='font-size: 8px;'>Joomla! version 1.7.1 and earlier</span><br />
<strong class='bbc'>	<span style='color: black'><span style='font-family: Arial,sans-serif'>Solution</span></span></strong><br />
 <br />
<span style='font-size: 8px;'>Upgrade to the latest Joomla! version (1.7.2 or later)</span><br />
<span style='font-size: 8px;'>Reported by Aung Khant, YGN Ethical Hacker Group</span><br />
<strong class='bbc'>	<span style='color: black'><span style='font-family: Arial,sans-serif'>Contact</span></span></strong><br />
 <br />
<span style='font-size: 8px;'>The JSST at the <a href='http://developer.joomla.org/security.html' class='bbc_url' title='External link' rel='nofollow external'><strong class='bbc'> <span style='color: #000099'>Joomla! Security Center</span></strong></a>.</span><br />
<a href='http://feedproxy.google.com/~r/JoomlaSecurityNews/~3/Qzmq6A_Uzk4/372-20111003-core-information-disclosure.html?utm_source=feedburner&utm_medium=email' class='bbc_url' title='External link' rel='nofollow external'> <strong class='bbc'><span style='color: #000099'><span style='font-family: Arial,sans-serif'><span style='font-size: 8px;'>[20111003] - Core - Information Disclosure</span></span></span></strong></a><br />
<span style='font-size: 8px;'>Posted: 17 Oct 2011 01:59 PM PDT</span><br />
<strong class='bbc'><span style='color: black'><span style='font-family: Arial,sans-serif'><span style='font-size: 8px;'>Project:</span></span></span></strong><span style='color: black'><span style='font-family: Arial,sans-serif'><span style='font-size: 8px;'> Joomla!</span></span></span><br />
<strong class='bbc'><span style='color: black'><span style='font-family: Arial,sans-serif'><span style='font-size: 8px;'>SubProject:</span></span></span></strong><span style='color: black'><span style='font-family: Arial,sans-serif'><span style='font-size: 8px;'> All</span></span></span><br />
<strong class='bbc'><span style='color: black'><span style='font-family: Arial,sans-serif'><span style='font-size: 8px;'>Severity:</span></span></span></strong><span style='color: black'><span style='font-family: Arial,sans-serif'><span style='font-size: 8px;'> Moderate</span></span></span><br />
<strong class='bbc'><span style='color: black'><span style='font-family: Arial,sans-serif'><span style='font-size: 8px;'>Versions:</span></span></span></strong><span style='color: black'><span style='font-family: Arial,sans-serif'><span style='font-size: 8px;'> 1.5.23 and earlier</span></span></span><br />
<strong class='bbc'><span style='color: black'><span style='font-family: Arial,sans-serif'><span style='font-size: 8px;'>Exploit type:</span></span></span></strong><span style='color: black'><span style='font-family: Arial,sans-serif'><span style='font-size: 8px;'> Information Disclosure</span></span></span><br />
<strong class='bbc'><span style='color: black'><span style='font-family: Arial,sans-serif'><span style='font-size: 8px;'>Reported Date:</span></span></span></strong><span style='color: black'><span style='font-family: Arial,sans-serif'><span style='font-size: 8px;'> 2011-September-09</span></span></span><br />
<strong class='bbc'><span style='color: black'><span style='font-family: Arial,sans-serif'><span style='font-size: 8px;'>Fixed Date:</span></span></span></strong><span style='color: black'><span style='font-family: Arial,sans-serif'><span style='font-size: 8px;'> 2011-October-17</span></span></span><br />
<strong class='bbc'>	<span style='color: black'><span style='font-family: Arial,sans-serif'>Description</span></span></strong><br />
 <br />
<span style='font-size: 8px;'>Weak encryption causes potential information disclosure.</span><br />
 <br />
<span style='color: black'><span style='font-family: Arial,sans-serif'>Affected Installs</span></span><br />
<span style='font-size: 8px;'>Joomla! version 1.5.23 and earlier</span><br />
<strong class='bbc'>	<span style='color: black'><span style='font-family: Arial,sans-serif'>Solution</span></span></strong><br />
 <br />
<span style='font-size: 8px;'>Upgrade to the latest Joomla! version (1.5.24 or later)</span><br />
<span style='font-size: 8px;'>Reported by Jeff Channell</span><br />
<strong class='bbc'>	<span style='color: black'><span style='font-family: Arial,sans-serif'>Contact</span></span></strong><br />
 <br />
<span style='font-size: 8px;'>The JSST at the <a href='http://developer.joomla.org/security.html' class='bbc_url' title='External link' rel='nofollow external'><strong class='bbc'> <span style='color: #000099'>Joomla! Security Center</span></strong></a>.</span>]]></description>
		<pubDate>Tue, 18 Oct 2011 14:12:52 +0000</pubDate>
		<guid>http://cartikaforum.com/topic/2359-joomla-security-bulletin-october-17-2011/</guid>
	</item>
</channel>
</rss>
