Position top1

The Parks sample site is designed as a simple site that can be routinely updated from the front end of Joomla!.

As a site, it is largely focused on a blog which can be updated using the front end article submission.

New weblinks can also be added through the front end.

Position top2

This Module displays other Articles that are related to the one currently being viewed. These relations are established by the Meta Keywords. All the keywords of the current Article are searched against all the keywords of all other published articles.

Position top3

The Fruit Shop site shows a number of Joomla! features.

The template uses classes in cascading style sheets to change the layout of items, such as creating the horizontal alphabetical list in the Fruit Encyclopedia.

 

22 - 04 - 2017
Position newsflashload

If you are an experienced Joomla! 1.5 user, 1.6 will seem very familiar. There are new templates and improved user interfaces, but most functionality is the same. The biggest changes are improved access control (ACL) and nested categories.

    • Project: Joomla!
    • Severity: High
    • Versions: 1.5.0 through 3.6.5
    • Exploit type: Remote Code Execution in third-party PHPMailer library
    • CVE Numbers: and
    Note: This advisory was revised to reflect the addition of CVE-2016-10045 and the PHPMailer 5.2.20 release

    Description

    All versions of the third-party PHPMailer library distributed with Joomla! versions up to 3.6.5 are vulnerable to a remote code execution vulnerability. This is patched in PHPMailer 5.2.20 which will be included with Joomla! 3.7. After analysis, the JSST has determined that through correct use of the JMail class, there are additional validations in place which make executing this vulnerability impractical within the Joomla environment. As well, the vulnerability requires being able to pass user input to a message's "from" address; all places in the core Joomla API which send mail use the sender address set in the global configuration and does not allow for user input to be set elsewhere. However, extensions which bundle a separate version of PHPMailer or do not use the Joomla API to send email may be vulnerable to this issue.

    Generally, the Joomla project does not issue advisories regarding third party libraries, however given the severity of this issue we felt it important to advise our users that we are aware of this issue and we have determined that the additional validations in our API prevent triggering this vulnerability.

    Affected Installs

    Joomla! CMS versions 1.5.0 through 3.6.5

    Solution

    No action required for Joomla users, the updated library will be included in the next scheduled release and additional mechanisms exist in Joomla core to prevent triggering the vulnerability. Users of the PHPMailer library separate from Joomla are advised to upgrade to 5.2.20 or newer ASAP.

    Additional Resources

    Contact

    Reported By: Dawid Golunski
    • Project: Joomla!
    • SubProject: CMS

    Description

    Joomla! 3.6.5 includes additional security hardening mechanisms prepared by the JSST, thanks in part to issue reports from Fotis Evangelou and Nicholas Dionysopoulos, which restricts a user's ability to make potentially damaging configuration changes. This includes restricting the ability to set the "New User Registration Group" and "Guest User Group" to a group with Super User permissions and restricting the ability for a lesser privileged user to make user group assignment changes to users in a Super User group.

    Additionally, we have modified the behavior of JUser::authorise() to only return a boolean value. Previously, this method could return either a boolean value or null because the underlying call to JAccess::check() can also return a null value; neither JUser::authorise() or JAccess::check() documented this though. We have determined that based on how the API is used that JUser::authorise() should only return a boolean value. If a developer requires the previous behavior of a null return value (which indicates an "implicit" denied state versus "explicit" signified by boolean false), they should use JAccess::check() instead. The documentation for JAccess::check() has been updated to indicate the null return value as well.

    Contact

    • Project: Joomla!
    • SubProject: CMS
    • Severity: Low
    • Versions: 3.0.0 through 3.6.4
    • Exploit type: Information Disclosure
    • Reported Date: 2016-April-15
    • Fixed Date: 2016-December-06
    • CVE Number:

    Description

    Inadequate ACL checks in the Beez3 com_content article layout override enables a user to view restricted content.

    Affected Installs

    Joomla! CMS versions 3.0.0 through 3.6.4

    Solution

    Upgrade to version 3.6.5

    Contact

    Reported By: Christiaan Klatte and Brian Teeman
    • Project: Joomla!
    • SubProject: CMS
    • Severity: Low
    • Versions: 3.0.0 through 3.6.4
    • Exploit type: Shell Upload
    • Reported Date: 2016-October-26
    • Fixed Date: 2016-December-06
    • CVE Number:

    Description

    Inadequate filesystem checks allowed files with alternative PHP file extensions to be uploaded.

    Affected Installs

    Joomla! CMS versions 3.0.0 through 3.6.4

    Solution

    Upgrade to version 3.6.5

    Contact

    Reported By: Xiphos Research Ltd.
    • Project: Joomla!
    • SubProject: CMS
    • Severity: High
    • Versions: 1.6.0 through 3.6.4
    • Exploit type: Elevated Privileges
    • Reported Date: 2016-November-04
    • Fixed Date: 2016-December-06
    • CVE Number:

    Description

    Incorrect use of unfiltered data stored to the session on a form validation failure allows for existing user accounts to be modified; to include resetting their username, password, and user group assignments.

    Affected Installs

    Joomla! CMS versions 1.6.0 through 3.6.4

    Solution

    Upgrade to version 3.6.5

    Contact

    Reported By: @iamsecurity
Position bottom

This is a custom html module. That means you can enter whatever content you want.

Random Image
200px_phyllopteryx_taeniolatus1.jpg
Position right

We have 42 guests and no members online

position bottom1

There are millions of users around the world and thousands of people who contribute to the Joomla! Project. They work in three main groups: the Production Working Group, responsible for everything that goes into software and documentation; the Community Working Group, responsible for creating a nurturing the community; and Open Source Matters, the non profit organization responsible for managing legal, financial and organizational issues

position bottom2

There are millions of users around the world and thousands of people who contribute to the Joomla! Project. They work in three main groups: the Production Working Group, responsible for everything that goes into software and documentation; the Community Working Group, responsible for creating a nurturing the community; and Open Source Matters, the non profit organization responsible for managing legal, financial and organizational issues

position bottom3

There are millions of users around the world and thousands of people who contribute to the Joomla! Project. They work in three main groups: the Production Working Group, responsible for everything that goes into software and documentation; the Community Working Group, responsible for creating a nurturing the community; and Open Source Matters, the non profit organization responsible for managing legal, financial and organizational issues