Начало arrow 1.0.х Промени arrow Промени във версия 1.0.11
Промени във версия 1.0.11 PDF Печат Е-мейл
This Release Contains the following 26 Security Fixes

Joomla! utilizes the Open Web Application Security Project (OWASP) Top Ten Project to categorize security vunerabilities found within Joomla!
http://www.owasp.org/index.php/OWASP_Top_Ten_Project

--- - - - - - - - - ---

04 HIGH Level Threats fixed

A1 Unvalidated Input
* Secured mosMail() against unvalidated input
* Secured JosIsValidEmail() - in previous versions the existance of an email address somewhere in the string was sufficient

A6 Injection Flaws
* Fixed remote execution issue in PEAR.php
* Fixed Zend Hash Del Key Or Index Vulnerability

--- - - - - - - - - ---

04 MEDIUM Level Threats fixed

A1 Unvalidated Input
* globals.php not included in administrator/index.php

A2 Broken Access Control 
* Added Missing defined( '_VALID_MOS' ) checks
* Limit Admin `Upload Image` from uploading below `/images/stories/` directory
* Fixed do_pdf command bypassing the user authentication

--- - - - - - - - - ---

18 LOW Level Threats fixed

A1 Unvalidated Input
* Hardened Admin `User Manager`
* Hardened poll module
* Fixed josSpoofValue function to ensure the hash is a string

A2 Broken Access Control 
* Secured com_content to not allow the tasks 'emailform' and 'emailsend' if $mosConfig_hideEmail is set
* Fixed emailform com_content task bypassing the user authentication
* Limit access to Admin `Popups` functionality

A4 Cross Site Scripting
* Fixed XSS injection issue in Admin `Module Manager`
* Fixed XSS injection issue in Admin `Help`
* Fixed XSS injection issue in Search

A6 Injection Flaws
* Harden loading of globals.php by using require() instead of include_once();
* Block potential misuse of $option variable
* Block against injection issue in Admin `Upload Image` 
* Secured against possible injection attacks on ->load()
* Secured against injection attack on content submissions where frontpage is selected
* Secured against possible injection attack thru mosPageNav constructor
* Secured against possible injection attack thru saveOrder functions
* Add exploit blocking rules to htaccess
* Harden ACL from possible injection attacks


-- -- -- -- -- ---- -- ---- -- ---- -- ---- -- ---- -- ---- -- ---- -- ---- -- ---- -- ---- -- --


28-Aug-2006 Rey Gigataras
# SECURITY A6 [ LOW Level ]: Block potential misuse of $option variable


28-Aug-2006 Andrew Eddie
# SECURITY A6 [ LOW Level ]: Harden ACL from possible injection attacks


24-Aug-2006 Rey Gigataras
# SECURITY A6 [ LOW Level ]: Add exploit blocking rules to htaccess
# SECURITY A6 [ LOW Level ]: Harden loading of globals.php by using require() instead of include_once();

+ Installation Security Warning check
+ Admin & Installation Version age warning


23-Aug-2006 Rey Gigataras
# SECURITY A2 [ MEDIUM Level ]: Missing defined( '_VALID_MOS' ) checks

+ Admin Security Warning check


21-Aug-2006 Rey Gigataras
# SECURITY A1 [ LOW Level ]: Hardened Admin `User Manager`
 

19-Aug-2006 Rey Gigataras
# SECURITY A2 [ MEDIUM Level ]: Limit Admin `Upload Image` from uploading below `/images/stories/` directory
# SECURITY A2 [ LOW Level ]: Limit access to Admin `Popups` functionality
# SECURITY A4 [ LOW Level ]: [topic,73761] : XSS injection issue in Admin `Module Manager`
# SECURITY A4 [ LOW Level ]: [topic,73761] : XSS injection issue in Admin `Help`
# SECURITY A4 [ LOW Level ]: [topic,73761] : XSS injection issue in Search
# SECURITY A6 [ LOW Level ]: [topic,73761] : Block against injection issue in Admin `Upload Image`


19-Aug-2006 Enno Klasing
# SECURITY A1 [ HIGH Level ]: Secured mosMail() against unvalidated input
# SECURITY A1 [ HIGH  Level ]: Secured JosIsValidEmail() - in previous versions the existance of an email address somewhere in the string was sufficient
# SECURITY A2 [ LOW Level ]: Secured com_content to not allow the tasks 'emailform' and 'emailsend' if $mosConfig_hideEmail is set

# Fixed : Empty subject in com_content mail2friend no longer possible
# Fixed : Show error message if com_content mail2friend fails
# Fixed : Show error message if com_contact mail fails
^ Moved all instances of is_email() amalgamated into JosIsValidEmail in /includes/joomla.php


18-Aug-2006 Rey Gigataras
# SECURITY A1 [ MEDIUM Level ]: globals.php not included in administrator/index.php
# SECURITY A2 [ MEDIUM Level ]: do_pdf command bypasses the user authentication
# SECURITY A2 [ LOW Level ]: emailform com_content task bypasses the user authentication
# SECURITY A1 [ LOW Level ]: harden poll module

# Fixed [topic,72209] : Mambots fired on Modules
+ enable selective disabling of `Email Cloaking` bot via {emailcloak=off}


17-Aug-2006 Rey Gigataras
+ PERFORMANCE : Cache handling expanded to com_content showItem
# Fixed [artf5266] : Blog-view shows "more..." even without intros
# Fixed [topic,81673] : frontend.php itemid issue


17-Aug-2006 Mateusz Krzeszowiec
# Fixed logging query before applying LIMIT


15-Aug-2006 Marko Schmuck
# SECURITY A6 [ LOW Level ]: possible injection attacks on ->load()


15-Aug-2006 Andrew Eddie
# SECURITY A6 [ HIGH Level ]: remote execution issue in PEAR.php


15-Aug-2006 Mateusz Krzeszowiec
# PERFORMANCE [topic,83325] : SQL LIMIT in com_content frontend


14-Aug-2006 Andrew Eddie
# SECURITY A6 [ LOW Level ]: Injection attack on content submissions where frontpage is selected
# SECURITY A6 [ LOW Level ]: possible injection attack thru mosPageNav constructor
# SECURITY A6 [ LOW Level ]: possible injection attack thru saveOrder functions


07-Aug-2006 Andrew Eddie
# SECURITY A6 [ HIGH Level ]: Zend Hash Del Key Or Index Vulnerability
# SECURITY A1 [ LOW Level ]: josSpoofValue function to ensure the hash is a string


28-July-2006 Robin Muilwijk
# Fixed [artf5291] : missing onChange javascript code for filter field


27-July-2006 Robin Muilwijk
# SECURITY A2 [ MEDIUM Level ]: [artf5335] : missing direct access line

# Fixed [artf5282] : missing table row tag and self closing tag
# Fixed [artf5297] : small html errors


17-July-2006 Robin Muilwijk
# Fixed [artf5157] : typo in media manager
# Fixed [artf5218] : duplicate entry of artf5157, typo in media manager


03-July-2006 Rey Gigataras
# Fixed [artf5181] : 5 step for unrecoverable admin-page crash.
# Fixed [artf5123] : Wrong name of function in joomla.cache.php
# Fixed [artf5126] : includes/database.php uses deprecated function
# Fixed [artf5171] : mosGetParam Default value issue
# Fixed [artf5112] : A mere mistake in the file contact.html.php
 
< Предишна   Следваща >

Приложения

Components icon  Компонент: приложение, което се зарежда в основата на страницата

Modules icon  Модул: показва малки html блокове на избрана страница

  Бот: променя кода динамично (mambot)

  Език: съдържа превод на български

Tool  Разни : външно приложение, което помага за изграждане на Джумла! сайт

Tool  Шаблони : шаблони, които променят външния вид на сайта.

© 2002 - 2008 Джумла! България
auto tuning links exchange auto tuning, wheels auto tuning auto tuning auto tuning counter-strike, 1.6, simferopol, cstrike, movies, maps, demos, teams, champs, cs, players, cs gaming, cs servers, amx counter-strike, 1.6,cstrike,карты на кс,maps cs, cs 1.6 maps, cs sourse maps, кс 1,6 карты, кс сурс карты, mapping, маппинг< counter-strike, 1.6, simferopol, cstrike, movies, maps, demos, teams, champs, cs, players, cs gaming, cs servers, amx counter-strike, 1.6, simferopol, симферополь,крым, cstrike, cs sourse, контра, статьи по кс, статьи по контре counter-strike, 1.6,cstrike,карты на кс,maps cs, cs 1.6 maps, cs sourse maps, кс 1,6 карты, кс сурс карты, mapping, маппинг counter strike wallpapers,cs wallpapers,обои кс,обои контр страйк,cs 1.6 wallpapers, cs sourse обои дополнительное оружие для кс, оружие кс 1.6, weapon cs, weapon cs 1.6, weapon cs sourse, оружие кс cs 1.6 сурс боты для кс, боты cs, боты для контры, bots cs 1.6, bots counter strike sourse фраги, фраги кс, frags cs 1.6 sourse, видео cs 1.6 sourse, frags counter strike 1.6 sourse демки на кс, cs 1.6 demos, demo cs sourse статьи по кс, статьи по контре, статьи cs 1.6, статьи cs sourse патчи на кс, patches for cs, patch for counter strike, cs patch, cs 1.6 patch, cs sourse patch, патчи на контру cs, cs 1.6, cs sourse, links exchange, cs1.6, 1.6, cs source,counter strike, cs:s, source, source maps, cs 1.6 maps, movies, frags, cs frag movie, cs players, cs teams, source movies, modes, patches auto tuning,wheels,key chain,neonset,pedalset,Sparco,adapter,antenne,auto tattoo,Mirror set,Undercar Kit,ZKL AR,ZKL HQ,Tail lights,lowering springs,Performance Instrument,ESD Uni,Spoorverbreder set,Gearknob,SteeringWheel,Sportseat rap music,rap festival,tracks,underground,freestyle,Hip Hop,dis tracks,rap battle,russian rap,rap team seo, PR, php seo, optimizator, php, clean url, wordpress seo, wp optimization, web feeds, cloaking, geo-targeting, IP delivery, se-friendly blog, content relocation web-design, html+css, php+ajax+mysql rails,ruby on rails,rails installation,rails models,rails structure,rails tables,classes,modules ajax, php ajax, rss, atom, ajax xml, xmlhttp requests, ajax patterns, xpath, xslt, json, ajaxmail ruby syntax, ruby oop, ruby semantics, dynamic aspects of ruby, regular expressions, internationalization if ruby, graphical interfaces for ruby, threads in ruby, ruby web applications cs1.6, 1.6, cs source,counter strike, cs:s, source, source maps, cs 1.6 maps, movies, frags, cs frag movie, cs players, cs teams, source movies, modes, patches auto tuning,wheels,key chain,neonset,pedalset,Sparco,adapter,antenne,auto tattoo,Mirror set,Undercar Kit,ZKL AR,ZKL HQ,Tail lights,lowering springs,Performance Instrument,ESD Uni,Spoorverbreder set,Gearknob,SteeringWheel,Sportseat rap music,rap festival,tracks,underground,freestyle,Hip Hop,dis tracks,rap battle,russian rap,rap team seo, PR, php seo, optimizator, php, clean url, wordpress seo, wp optimization, web feeds, cloaking, geo-targeting, IP delivery, se-friendly blog, content relocation web-design, html+css, php+ajax+mysql rails,ruby on rails,rails installation,rails models,rails structure,rails tables,classes,modules ajax, php ajax, rss, atom, ajax xml, xmlhttp requests, ajax patterns, xpath, xslt, json, ajaxmail ruby syntax, ruby oop, ruby semantics, dynamic aspects of ruby, regular expressions, internationalization if ruby, graphical interfaces for ruby, threads in ruby, ruby web applications
buy viagra online viagra viagra buy where to buy viagra buy viagra now online buy viagra on line buy generic viagra buy cheap viagra viagra buy online buy online viagra buy viagra now buy viagra cheap buy generic viagra online buy viagra in canada buy viagra uk buy viagra internet buy viagra in uk where can i buy viagra viagra online buy buy viagra c.o.d buy viagra in the uk buy cheap generic viagra want to buy viagra at cheap price buy viagra online uk buy viagra no prescription to buy viagra buy cheap viagra in uk where can i buy viagra in the uk viagra best buy buy viagra in great britain viagra to buy buy viagra online without prescription buy viagra norway buy viagra low cost order viagra online how to buy viagra buy generic viagra by the pill buy cialis viagra buy viagra without prescription where to buy viagra online buy viagra without a prescription buy prescription viagra buy viagra canada buy viagra from india buy viagra in usa buy cheap viagra online buy discount viagra online where to buy viagra on line buy online order viagra buy to viagra where buy viagra com buy cheap viagra online uk how to buy viagra in stores buy viagra pills buy viagra online cheap to buy genuine pfizer viagra generic viagra buy on line want to buy viagra viagra where to buy in the united kingdom how can i buy viagra buy viagra rx buy viagra pill online buy viagra online without a prescription where to buy generic viagra buy and purchase viagra online buy viagra low price how to buy viagra online order viagra order viagra online viagra order mail order viagra viagra mail order online order viagra viagra order online viagra online order order viagra without a prescription viagra order on line order cheap viagra buy online order viagra order generic viagra viagra no prescripion order order viagra prescription order viagra pills order viagra online discount order viagra order viagra canada how to order viagra on line order viagra on line order viagra no consultation how to order viagra order generic viagra on line order viagra without prescription order viagra now viagra mail order uk viagra pay by money order viagra order online no prescription order viagra no prescripion free viagra order online order no prescripion viagra order viagra buying viagra uk order viagra online viagra by mail order viagra order no prescription viagra order canada mail order for viagra tablets how order viagra online order viagra buy viagra order cheap online cheap viagra order online generic online order viagra how we can order viagra from india to nepal mail order viagra mail online order viagra mail order viagra online order online free viagra order viagra cheap order viagra cialis order viagra for cheap viagra price price viagra best price viagra lowest price viagra low price viagra viagra price comparison viagra lowest price want to buy viagra at cheap price viagra best price best price for viagra lowest price generic viagra best price for generic viagra price of viagra half price viagra cheapest price viagra viagra dosage and price cheap cost discount price viagra lowest viagra price cheapest viagra price buy viagra low price best price on generic viagra viagra cheap price viagra low price best viagra price low price viagra pills mexico generic viagra price viagra sale viagra sale online viagra for sale online viagra sale generic viagra for sale viagra on sale viagra for sale in the uk viagra prescription sale viagra pills for sale sale viagra viagra for sale from usa viagra for sale in uk cheap viagra for sale viagra for sale online viagra cialis sale cheap discounted viagra for sale generic viagra sale viagra sale rx viagra drugs for sale viagra for sale cheap viagra sale prices viagra for sale in us viagra online sale viagra sale uk for sale viagra without perscription from canada for sale viagra without perscription online sale viagra no prescription viagra sale no prescription viagra for sale viagra for sale euro viagra pills for sale without prescription viagra sale lowest prices viagra sildenafil citrate for sale sale on viagra sale uk viagra viagra discount sale viagra for sale cheapest viagra for sale in u.k viagra for sale in usa viagra for sale on line viagra for sale on the internet viagra for sale will buy canada sale of viagra europe online sale viagra viagra in india for sale viagra sale usa viagra sales viagra sales in uk viagra online sales sales viagra viagra discount sales online viagra sales viagra sales online generic viagra sales viagra uk sales viagra sales uk viagra for sales uk viagra sales