
|
|
Written by Marcelo Almeida (Vympel)
|
|
Wednesday, 13 August 2008 |
- Project: Joomla!
- SubProject: com_user
- Severity: Critical
- Versions: 1.5.5 and all previous 1.5 releases
- Exploit type: Password Reset Forgery
- Reported Date: 2008-August-12
- Fixed Date: 2008-August-12
Description
A flaw in the reset token validation mechanism allows for non-validating tokens to be forged.
This will allow an unauthenticated, unauthorized user to reset the password of the first
enabled user (lowest id). Typically, this is an administrator user. Note, that changing the
first users username may lessen the impact of this exploit (since the person who changed the
password does not know the login associated with the new password). However, the only way to
completely rectify the issue is to upgrade to 1.5.6 (or patch the
/components/com_user/models/reset.php file)...
Write Comment (2 Comments) |
|
Read more...
|
|
Written by Marcelo Almeida (Vympel)
|
|
Tuesday, 24 June 2008 |
SUSE Security Announcement
Package: kernel
Announcement ID: SUSE-SA:2008:030
Date: Fri, 20 Jun 2008 14:00:00 +0000
Affected Products: openSUSE 10.2
openSUSE 10.3
Vulnerability Type: remote denial of service
Severity (1-10): 9
SUSE Default Package: yes
Cross-References: CVE-2007-5500, CVE-2007-5904, CVE-2007-6206
CVE-2007-6282, CVE-2007-6712, CVE-2008-0600
CVE-2008-1367, CVE-2008-1375, CVE-2008-1615
CVE-2008-1669, CVE-2008-2136, CVE-2008-2148
CVE-2008-2358...
Write Comment (0 Comments) |
|
Read more...
|
|
Written by Marcelo Almeida (Vympel)
|
|
Tuesday, 24 June 2008 |
|
SkyOut has discovered a vulnerability in AproxEngine, which can be
exploited by malicious people to disclose potentially sensitive
information.
Input passed to the "page" parameter in index.php is not properly
verified before being used to include files. This can be exploited to
include arbitrary files from local resources.
The vulnerability is confirmed in version 5.1.0.4. Other versions may also be affected...
Write Comment (1 Comments) |
|
Read more...
|
|
|
<< Start < Prev 1 2 3 4 5 6 7 8 9 10 Next > End >>
|
| Results 1 - 15 of 9513 |