Thursday, December 2, 2010

Joomla: Insufficient Anti-automation and Abuse of Functionality Vulnerabilities

Users of Joomla please be advised of an Insufficient Anti-automation and Abuse of Functionality Vulnerabilities that has been identified.

To view this vulnerability, possible remedies, and others please check out the Security Advisories at Critical Watch (http://criticalwatch.com/support/security-advisories.aspx)

Amplify’d from www.criticalwatch.com
SecurityVulns ID: 11272: Vulnerabilities in Joomla
Affected products:
-------------------------

Vulnerable are all versions of Joomla with corresponding functionality
(Joomla! 1.5.22 and previous versions).
Details:
----------

In details about such vulnerabilities, about sending of spam via web sites
and creating of spam-botnets it's possible to read in my article Sending
spam via sites and creating spam-botnets
(http://www.webappsec.org/lists/websecurity/archive/2010-07/msg00099.html).
I want to warn you about Insufficient Anti-automation and Abuse of
Functionality vulnerabilities in Joomla. Vulnerabilities exist in component
com_contact, which is a core component of Joomla.
Read more at www.criticalwatch.com
 

No comments:

Post a Comment