Profil anzeigen WWW Private Mitteilung (Online)
Re: Attention: Official List of Vulnerable 3rd Party Add-ons!!!
« Antwort #3 am: 01-08-2006, 08:40:07 »
Updated again. Added 7 components to the naughty list.
PC Cook Book
User Home Pages 1 and 2
Mambo Gallery Manager
JD-WordPress
Colophon
LMO
Bayesian Naive Filter
That brings this list to 34 components.
Last updated on July 31, 2006 @ 11:34 PM PDT.
Moderator informieren Gespeichert
Rob Schley - Rob[at]NocLabs[dot]com - --ALTER LINK WURDE ENTFERNT--
Technical Lead, Joomla! Quality & Testing Working Group
List of Insecure 3rd Party Extensions: --ALTER LINK WURDE ENTFERNT--
RobS
Moderator
Joomla! Hero
*
Online Online
Beiträge: 564
Profil anzeigen WWW Private Mitteilung (Online)
Re: Attention: Official List of Vulnerable 3rd Party Add-ons!!!
« Antwort #4 am: 10-08-2006, 10:46:18 »
Updated Again...
Added
JD-Wiki
Community Builder (com_profiler) ((Thank you JM!))
Updated status for LMO
Updated link for SMF Bridge (for SMF 1.1RC2 only)
Last updated on August 10th, 2006 at 1:45 AM PDT (GMT-7)
Moderator informieren Gespeichert
Rob Schley - Rob[at]NocLabs[dot]com - --ALTER LINK WURDE ENTFERNT--
Technical Lead, Joomla! Quality & Testing Working Group
List of Insecure 3rd Party Extensions: --ALTER LINK WURDE ENTFERNT--
RobS
Moderator
Joomla! Hero
*
Online Online
Beiträge: 564
Profil anzeigen WWW Private Mitteilung (Online)
Re: Attention: Official List of Vulnerable 3rd Party Add-ons!!!
« Antwort #5 am: 10-08-2006, 11:15:08 »
I forgot some...
Added:
Classifieds
Events
Hot Properties
Last updated on August 10th, 2006 at 2:15 AM PDT (GMT-7)
Moderator informieren Gespeichert
Rob Schley - Rob[at]NocLabs[dot]com - --ALTER LINK WURDE ENTFERNT--
Technical Lead, Joomla! Quality & Testing Working Group
List of Insecure 3rd Party Extensions: --ALTER LINK WURDE ENTFERNT--
RobS
Moderator
Joomla! Hero
*
Online Online
Beiträge: 564
Profil anzeigen WWW Private Mitteilung (Online)
Re: Attention: Official List of Vulnerable 3rd Party Add-ons!!!
« Antwort #6 am: 10-08-2006, 21:07:53 »
Added Blogg-X Mambot. - Removed Blogg-X. It does not appear to be vulnerable upon further investigation.
Updated information about Security Images.
That brings the number of insecure 3rd party extensions up to 40 extensions.
Last updated on August 12th, 2006 at 11:16 AM PDT (GMT-7)
« Letzte Änderung: 12-08-2006, 20:17:29 von RobS » Moderator informieren Gespeichert
Rob Schley - Rob[at]NocLabs[dot]com - --ALTER LINK WURDE ENTFERNT--
Technical Lead, Joomla! Quality & Testing Working Group
List of Insecure 3rd Party Extensions: --ALTER LINK WURDE ENTFERNT--
RobS
Moderator
Joomla! Hero
*
Online Online
Beiträge: 564
Profil anzeigen WWW Private Mitteilung (Online)
Re: Attention: Official List of Vulnerable 3rd Party Add-ons!!!
« Antwort #7 am: 12-08-2006, 20:18:30 »
Removed Blogg-X. Upon further investigation Blogg-X does not appear to be vulnerable.
Moderator informieren Gespeichert
Rob Schley - Rob[at]NocLabs[dot]com - --ALTER LINK WURDE ENTFERNT--
Technical Lead, Joomla! Quality & Testing Working Group
List of Insecure 3rd Party Extensions: --ALTER LINK WURDE ENTFERNT--
infograf768
Global Moderator
Joomla! Hero
*
Offline Offline
Beiträge: 3599
Profil anzeigen Private Mitteilung (Offline)
Re: Attention: Official List of Vulnerable 3rd Party Add-ons!!!
« Antwort #8 am: 15-08-2006, 07:59:41 »
Temporarily added the abandonned Webring component until updated by Robs.
Moderator informieren Gespeichert
Jean-Marie Simonet / infograf · --ALTER LINK WURDE ENTFERNT-- · GMT +1
• --ALTER LINK WURDE ENTFERNT-- •
RobInk
Q&T Workgroup
Joomla! Hero
*
Offline Offline
Beiträge: 3921
NL :: GMT+1
Profil anzeigen WWW Private Mitteilung (Offline)
Re: Attention: Official List of Vulnerable 3rd Party Add-ons!!!
« Antwort #9 am: 15-08-2006, 20:58:29 »
Update has come in about Mosets Hot Property, there 0.98 release should fix the security issues. Still need to verify before we change the current listing.
Regards Robin
Moderator informieren Gespeichert
Joomla! Core Team Member :: Stability Team Member :: Team Co-Leader, Quality & Testing
Joom!Fish Project Member, Quality & Testing
--ALTER LINK WURDE ENTFERNT-- :: RobInk's Joomla! Solutions - Affordable and Quality Web Design
--ALTER LINK WURDE ENTFERNT-- :: As IVIVIO we bring true enterprise-grade systems to market
RobInk
Q&T Workgroup
Joomla! Hero
*
Offline Offline
Beiträge: 3921
NL :: GMT+1
Profil anzeigen WWW Private Mitteilung (Offline)
Re: Attention: Official List of Vulnerable 3rd Party Add-ons!!!
« Antwort #10 am: 16-08-2006, 09:16:00 »
I have received a reply from the developer of Mosets Tree and Hot Property. Mosets Tree 1.5.9 and Hot Property 0.98 are now solving the security issues. The list will be changed accordingly.
Moderator informieren Gespeichert
Joomla! Core Team Member :: Stability Team Member :: Team Co-Leader, Quality & Testing
Joom!Fish Project Member, Quality & Testing
--ALTER LINK WURDE ENTFERNT-- :: RobInk's Joomla! Solutions - Affordable and Quality Web Design
--ALTER LINK WURDE ENTFERNT-- :: As IVIVIO we bring true enterprise-grade systems to market
infograf768
Global Moderator
Joomla! Hero
*
Offline Offline
Beiträge: 3599
Profil anzeigen Private Mitteilung (Offline)
Re: Attention: Official List of Vulnerable 3rd Party Add-ons!!!
« Antwort #11 am: 18-08-2006, 06:22:02 »
See here for hacks concerning Joomlaboard 1.1.2 and CB 1.0.1 to make them compatible with register globals off as set in globals.php
--ALTER LINK WURDE ENTFERNT--
(please integrate in your list, Robs)
Moderator informieren Gespeichert
Jean-Marie Simonet / infograf · --ALTER LINK WURDE ENTFERNT-- · GMT +1
• --ALTER LINK WURDE ENTFERNT-- •
RobInk
Q&T Workgroup
Joomla! Hero
*
Offline Offline
Beiträge: 3921
NL :: GMT+1
Profil anzeigen WWW Private Mitteilung (Offline)
Re: Attention: Official List of Vulnerable 3rd Party Add-ons!!!
« Antwort #12 am: 18-08-2006, 08:33:20 »
Thanks JM, added as a note/reference to the listing.
Moderator informieren Gespeichert
Joomla! Core Team Member :: Stability Team Member :: Team Co-Leader, Quality & Testing
Joom!Fish Project Member, Quality & Testing
--ALTER LINK WURDE ENTFERNT-- :: RobInk's Joomla! Solutions - Affordable and Quality Web Design
--ALTER LINK WURDE ENTFERNT-- :: As IVIVIO we bring true enterprise-grade systems to market
RobInk
Q&T Workgroup
Joomla! Hero
*
Offline Offline
Beiträge: 3921
NL :: GMT+1
Profil anzeigen WWW Private Mitteilung (Offline)
Re: Attention: Official List of Vulnerable 3rd Party Add-ons!!!
« Antwort #13 am: 18-08-2006, 13:23:45 »
Added JIM 1.0.1. (PMS) to the list, regarding --ALTER LINK WURDE ENTFERNT--
( --ALTER LINK WURDE ENTFERNT-- )
Robin
Moderator informieren Gespeichert
Joomla! Core Team Member :: Stability Team Member :: Team Co-Leader, Quality & Testing
Joom!Fish Project Member, Quality & Testing
--ALTER LINK WURDE ENTFERNT-- :: RobInk's Joomla! Solutions - Affordable and Quality Web Design
--ALTER LINK WURDE ENTFERNT-- :: As IVIVIO we bring true enterprise-grade systems to market
RobInk
Q&T Workgroup
Joomla! Hero
*
Offline Offline
Beiträge: 3921
NL :: GMT+1
Profil anzeigen WWW Private Mitteilung (Offline)
Re: Attention: Official List of Vulnerable 3rd Party Add-ons!!!
« Antwort #14 am: 18-08-2006, 13:34:30 »
Added Mambelfish 1.x due to report ; --ALTER LINK WURDE ENTFERNT--