Joomla Security Update 1.5.13
The security update can be downloaded here
[20090722] - Core - Missing JEXEC Check Posted: 22 Jul 2009 04:36 PM PDT
DescriptionSome files were missing the check for JEXEC. These scripts will then expose internal path information of the host. Affected InstallsAll 1.5.x installs prior to and including 1.5.12 are affected. SolutionUpgrade to latest Joomla! version (1.5.13 or newer). Reported by Juan Galiana Lara (Internet Security Auditors) ContactThe JSST at the Joomla! Security Center. Posted: 22 Jul 2009 04:17 PM PDT
DescriptionTiny browser included with TinyMCE 3.0 editor allowed files to be uploaded and removed without logging in. Affected InstallsVersion 1.5.12 only SolutionUpgrade to latest Joomla! version (1.5.13 or newer). Related Articles![]() Best Canadian Web Host for Joomla Our Latest Joomla News |