Joomla! Forum Schweiz wird Teil der D-A-CH Community

Nach vielen Jahren als zentrale Anlaufstelle für Fragen rund um Joomla! in der Schweiz wird das Joomla! Forum Schweiz künftig als Archiv weitergeführt.

Die Joomla!-Communities aus Deutschland, Österreich und der Schweiz arbeiten heute enger denn je zusammen. Deshalb bündeln wir künftig auch den deutschsprachigen Support und Austausch an einem gemeinsamen Ort im Joomla! D-A-CH Forum.

Für neue Fragen, Diskussionen und den Austausch mit der Community nutzt bitte ab sofort:

forum.joomla.de

Das Joomla! Forum Schweiz bleibt weiterhin bestehen und wird als Archiv im Lesemodus erhalten. Die vielen Beiträge, Lösungen und Erfahrungen aus den vergangenen Jahren bleiben damit weiterhin zugänglich und über die Suche auffindbar.

Wir bedanken uns herzlich bei allen Mitgliedern, Moderatoren und Helfern, die das Schweizer Joomla! Forum über viele Jahre mit ihrem Wissen und ihrem Engagement geprägt haben.

Wir sehen uns im Joomla! D-A-CH Forum!

Aus dem Joomla.org Forum

Mehr
22 Aug. 2006 23:18 #3169 von ghosty
Aus dem Joomla.org Forum wurde erstellt von ghosty
Attention: Official List of Vulnerable 3rd Party Add-ons!!!
« am: 24-07-2006, 00:11:29 »

This will be the home of an official list of all the 3rd party components with known vulnerabilities. Please keep in mind that this list is a work in progress. If there is a "(?)" mark next to an entry it means that I am not sure about some of the details like which version is vulnerable, etc. If you are familiar with these or are the developer or something of that nature I would appreciate your help in clarifying the information. So please check to make sure that I listed the component name, short name, version and suggested fix accurately. I have also added as many references as I could reasonably find so people can find more information on the reports and possibly problems other users have faced from upgrading or not upgrading. Wink

I also advise subscribing to this thread via the notify button. I will be sure to add a response to the thread whenever I make changes to that you will receive an email notification when new components are added to the list. Obviously you don't have to do it but it is probably a good idea if you are concerned about any of the extensions you are using on your site. Also, I think I have almost all of the vulnerable extensions for Joomla! I have not and probably will not add the extensions that were built for Mambo as they probably suffer from an assortment of problems and it is generally not good practice to use those components at all unless they have been ported to Joomla.

Full Name: A6MamboHelpDesk
Short Name: com_a6mambohelpdesk
Version: <= 1.8 RC1.
Fix: Abandoned. Remove completely or use at your own risk.
References: --ALTER LINK WURDE ENTFERNT--
--ALTER LINK WURDE ENTFERNT--

Full Name: Advanced Poll
Short Name: com_advancedpoll (?)
Version: <= 2.2.0.
Fix: Abandoned. Remove completely or use at your own risk.
References: --ALTER LINK WURDE ENTFERNT--

Full Name: ArtLinks
Short Name: com_artlinks
Version: All Versions.
Fix: Abandoned. Remove completely or use at your own risk.
References: --ALTER LINK WURDE ENTFERNT--

Full Name: Bayesian Naive Filter
Short Name: com_bayesiannaivefilter
Version: <= 1.1
Fix: No Fix Available. Please disable or remove this component until a fix can be made available.
References: --ALTER LINK WURDE ENTFERNT--

Full Name: BSQ Site Stats
Short Name: com_bsqsitestats
Version: <= 2.1.0
Fix: Upgrade to version 2.1.1. Download it here.
References: --ALTER LINK WURDE ENTFERNT--

Full Name: Classifieds
Short Name: com_classifieds
Version: <= 1.3
Fix: Upgrade to version 1.4. Download it here.
References: --ALTER LINK WURDE ENTFERNT--

Full Name: Colophon
Short Name: com_colophon
Version: <= 1.2
Fix: No Fix Available. Please disable or remove this component until a fix can be made available.
References: --ALTER LINK WURDE ENTFERNT--
--ALTER LINK WURDE ENTFERNT--

Full Name: Community Builder (comprofiler)
Short Name: com_profiler
Version: <= 1.0.0
Fix: Upgrade to version 1.0.1. Download it here.
References: --ALTER LINK WURDE ENTFERNT--
--ALTER LINK WURDE ENTFERNT--
Fix, compatible with register globals off as set in globals.php


Full Name: Events
Short Name: com_events
Version: <= 1.3 Beta
Fix: Upgrade to version 1.3 Beta2. Download it here.
References: --ALTER LINK WURDE ENTFERNT--

Full Name: ExtCalendar
Short Name: com_extcalendar
Version: <= 0.9.1
Fix: Upgrade to version 0.9.2. See this post for details.
References: --ALTER LINK WURDE ENTFERNT--
--ALTER LINK WURDE ENTFERNT--
--ALTER LINK WURDE ENTFERNT--
--ALTER LINK WURDE ENTFERNT--

Full Name: Galleria
Short Name: com_galleria
Version: All Versions.
Fix: Abandoned. Remove completely or use at your own risk.
References: --ALTER LINK WURDE ENTFERNT--
--ALTER LINK WURDE ENTFERNT--

Full Name: Hash Cash
Short Name: com_hashcash
Version: All Versions.
Fix: Abandoned. Remove completely or use at your own risk.
References: --ALTER LINK WURDE ENTFERNT--
--ALTER LINK WURDE ENTFERNT--

Full Name: Hot Properties
Short Name: com_hotproperties (?)
Version: <= 0.97
Fix: Upgrade to 0.98 Download it here.
References: No references available at this time.

Full Name: JD-Wiki
Short Name: com_jd-wiki
Version: <= 1.0.2
Fix: Upgrade to version 1.0.3. Download it here.
References: --ALTER LINK WURDE ENTFERNT--

Full Name: JD-WordPress
Short Name: com_jd-wp
Version: <= 2.0-1.0 RC2
Fix: Patch Available. See this post.
References: --ALTER LINK WURDE ENTFERNT--

Full Name: JIM 1.0.1. (PMS)
Short Name: com_jim
Version: 1.0.1. (possibly lower versions as well)
Fix: Not available
References: --ALTER LINK WURDE ENTFERNT--

Full Name: JoomlaBoard
Short Name: com_joomlaboard
Version: <= 1.1.1
Fix: Upgrade to version 1.1.2. Download it here.
References: --ALTER LINK WURDE ENTFERNT--
--ALTER LINK WURDE ENTFERNT--
Fix, compatible with register globals off as set in globals.php


Full Name: JoomlaLib
Short Name: com_joomlalib
Version: <= 1.2.1
Fix: Upgrade to version 1.2.2. Download it here.
References: --ALTER LINK WURDE ENTFERNT--

Full Name: LoudMouth
Short Name: com_loudmouth
Version: <= 4.0j
Fix: Upgrade to version 4.1 then apply Security Patch 1. Download upgrade and security patch here.
References: --ALTER LINK WURDE ENTFERNT--
--ALTER LINK WURDE ENTFERNT--

Full Name: LMO
Short Name: com_lmo
Version: <= 1.0b2
Fix: Upgrade to version 1.0b3. Download it here.
References: --ALTER LINK WURDE ENTFERNT--
--ALTER LINK WURDE ENTFERNT--

Continued in next post.
« Letzte Änderung: 18-08-2006, 13:22:57 von RobInk » Moderator informieren Gespeichert
Rob Schley - Rob[at]NocLabs[dot]com - --ALTER LINK WURDE ENTFERNT--
Technical Lead, Joomla! Quality & Testing Working Group
List of Insecure 3rd Party Extensions: --ALTER LINK WURDE ENTFERNT--
RobS
Moderator
Joomla! Hero
*
Online Online

Beiträge: 564


Profil anzeigen WWW Private Mitteilung (Online)

Re: Attention: Official List of Vulnerable 3rd Party Add-ons!!!
« Antwort #1 am: 29-07-2006, 10:03:38 »

I had to split it into two posts as it exceeded the maximum post length. Who knew?

Full Name: MambelFish 1.x
Short Name: com_mambelfish
Version: <= 1.x
Fix: Upgrade to 1.5 (or to Joom!Fish) Mambelfish 1.5 Joom!Fish 1.7
References: --ALTER LINK WURDE ENTFERNT--

Full Name: Mambo Gallery Manager
Short Name: com_mgm
Version: All Versions.
Fix: Abandoned. Remove completely or use at your own risk.
References: --ALTER LINK WURDE ENTFERNT--
--ALTER LINK WURDE ENTFERNT--

Full Name: MiniBB
Short Name: com_minibb
Version: <= 1.5a
Fix: Abandoned. Remove completely or use at your own risk.
References: --ALTER LINK WURDE ENTFERNT--
--ALTER LINK WURDE ENTFERNT--

Full Name: MamCom (?)
Short Name: com_trade
Version: All Versions.
Fix: Abandoned. Remove completely or use at your own risk. *Unconfirmed*
References: --ALTER LINK WURDE ENTFERNT--

Full Name: MosMedia
Short Name: com_mosmedia
Version: <= 1.0.8
Fix: Temporary Fix Available. See this thread for details.
References: --ALTER LINK WURDE ENTFERNT--

Full Name: MoSpray
Short Name: com_mospray
Version: <= 1.8 RC1
Fix: Abandoned. Remove completely or use at your own risk.
References: --ALTER LINK WURDE ENTFERNT--

Full Name: Mos Tree
Short Name: com_mtree
Version: <= 1.5.8
Fix: Upgrade to version 1.5.9. Download it here.
References: --ALTER LINK WURDE ENTFERNT--

Full Name: Multibanners
Short Name: com_multibanners *Note: Not the same as the Multibanners Module.*
Version: All Versions.
Fix: Abandoned. Remove completely or use at your own risk.
References: --ALTER LINK WURDE ENTFERNT--
--ALTER LINK WURDE ENTFERNT--

Full Name: OpenSEF
Short Name: com_sef
Version: <= 2.0.0 RC5 Unpatched
Fix: Patch Available. Download it here.
References: --ALTER LINK WURDE ENTFERNT--

Full Name: PC Cook Book
Short Name: com_pccookbook
Version: <= 1.3.1
Fix: No Fix Available. Please disable or remove this component until a fix can be made available.
References: --ALTER LINK WURDE ENTFERNT--
--ALTER LINK WURDE ENTFERNT--

Full Name: People Book
Short Name: com_peoplebook
Version: <= 1.1.5
Fix: Upgrade to version 1.1.6. Download it here.
References: --ALTER LINK WURDE ENTFERNT--

Full Name: Prince Clan Chess
Short Name: com_pcchess
Version: <= 0.8
Fix: Author suggest manually patching. See this site.

Full Name: Per Forms
Short Name: com_performs
Version: <= v1_beta
Fix: Upgrade to version v2_beta. Download it here.
References: --ALTER LINK WURDE ENTFERNT--
--ALTER LINK WURDE ENTFERNT--
--ALTER LINK WURDE ENTFERNT--

Full Name: PollXT
Short Name: com_pollxt
Version: <= 1.22.07
Fix: Upgrade to version 1.22.08. Download it here.
References: --ALTER LINK WURDE ENTFERNT--
--ALTER LINK WURDE ENTFERNT--

Full Name: RS Gallery2
Short Name: com_rsgallery2
Version: <= 1.11.3
Fix: Upgrade to version 1.11.4. Download it here.
References: --ALTER LINK WURDE ENTFERNT--

Full Name: Security Images
Short Name: com_securityimages
Version: <= 3.0.5
Fix: Upgrade to version 3.0.6. Download it here.
References: --ALTER LINK WURDE ENTFERNT--
--ALTER LINK WURDE ENTFERNT--

Full Name: SimpleBoard
Short Name: com_simpleboard
Version: All Versions.
Fix: Upgrade to JoomlaBoard 1.1.2. JoomlaBoard is compatible with SimpleBoard. Download it here.
References: --ALTER LINK WURDE ENTFERNT--
--ALTER LINK WURDE ENTFERNT--
--ALTER LINK WURDE ENTFERNT--

Full Name: Site Map
Short Name: com_sitemap
Version: All Versions.
Fix: Abandoned. Remove completely or use at your own risk.
References: --ALTER LINK WURDE ENTFERNT--
--ALTER LINK WURDE ENTFERNT--

Full Name: SMF Bridge
Short Name: com_smf
Version: <= 1.1.4
Fix: For SMF version 1.1RC2 only. Upgrade available. See this thread.
References: --ALTER LINK WURDE ENTFERNT--
--ALTER LINK WURDE ENTFERNT--
--ALTER LINK WURDE ENTFERNT--
--ALTER LINK WURDE ENTFERNT--
--ALTER LINK WURDE ENTFERNT--
--ALTER LINK WURDE ENTFERNT--

Full Name: SMF Bridge
Short Name: com_smf
Version: <= 1.1.4
Fix: For SMF versions other than 1.1RC2. Fix Available. See this thread.
References: --ALTER LINK WURDE ENTFERNT--
--ALTER LINK WURDE ENTFERNT--
--ALTER LINK WURDE ENTFERNT--
--ALTER LINK WURDE ENTFERNT--
--ALTER LINK WURDE ENTFERNT--
--ALTER LINK WURDE ENTFERNT--

Full Name: User Home Pages 1 and 2
Short Name: com_uhp and com_uhp2
Version: <= 1.1.1 (?)
Fix: Upgrade to 1.1.2. Download it here.
References: --ALTER LINK WURDE ENTFERNT--
--ALTER LINK WURDE ENTFERNT--

Note: This is a work in progress!!! Last updated on August 10th, 2006 @ 12:06 PM PDT (GMT-7).
See Below for changes made.
« Letzte Änderung: 18-08-2006, 13:33:42 von RobInk » Moderator informieren Gespeichert
Rob Schley - Rob[at]NocLabs[dot]com - --ALTER LINK WURDE ENTFERNT--
Technical Lead, Joomla! Quality & Testing Working Group
List of Insecure 3rd Party Extensions: --ALTER LINK WURDE ENTFERNT--
RobS
Moderator
Joomla! Hero
*
Online Online

Beiträge: 564


Profil anzeigen WWW Private Mitteilung (Online)

Re: Attention: Official List of Vulnerable 3rd Party Add-ons!!!
« Antwort #2 am: 29-07-2006, 21:06:26 »

Updated. Added A6MamboHelpDesk to the list of vulnerable components and also updated the information for LoudMouth as it has reportedly been fixed now.

Last updated July 29, 2006 @ 12:06 PM PDT.
Moderator informieren Gespeichert
Rob Schley - Rob[at]NocLabs[dot]com - --ALTER LINK WURDE ENTFERNT--
Technical Lead, Joomla! Quality & Testing Working Group
Mehr
22 Aug. 2006 23:18 #3170 von ghosty
ghosty antwortete auf Re: Aus dem Joomla.org Forum Teil 2
Profil anzeigen WWW Private Mitteilung (Online)

Re: Attention: Official List of Vulnerable 3rd Party Add-ons!!!
« Antwort #3 am: 01-08-2006, 08:40:07 »

Updated again. Added 7 components to the naughty list.

PC Cook Book
User Home Pages 1 and 2
Mambo Gallery Manager
JD-WordPress
Colophon
LMO
Bayesian Naive Filter

That brings this list to 34 components.
Last updated on July 31, 2006 @ 11:34 PM PDT.
Moderator informieren Gespeichert
Rob Schley - Rob[at]NocLabs[dot]com - --ALTER LINK WURDE ENTFERNT--
Technical Lead, Joomla! Quality & Testing Working Group
List of Insecure 3rd Party Extensions: --ALTER LINK WURDE ENTFERNT--
RobS
Moderator
Joomla! Hero
*
Online Online

Beiträge: 564


Profil anzeigen WWW Private Mitteilung (Online)

Re: Attention: Official List of Vulnerable 3rd Party Add-ons!!!
« Antwort #4 am: 10-08-2006, 10:46:18 »

Updated Again...

Added
JD-Wiki
Community Builder (com_profiler) ((Thank you JM!))
Updated status for LMO
Updated link for SMF Bridge (for SMF 1.1RC2 only)

Last updated on August 10th, 2006 at 1:45 AM PDT (GMT-7)
Moderator informieren Gespeichert
Rob Schley - Rob[at]NocLabs[dot]com - --ALTER LINK WURDE ENTFERNT--
Technical Lead, Joomla! Quality & Testing Working Group
List of Insecure 3rd Party Extensions: --ALTER LINK WURDE ENTFERNT--
RobS
Moderator
Joomla! Hero
*
Online Online

Beiträge: 564


Profil anzeigen WWW Private Mitteilung (Online)

Re: Attention: Official List of Vulnerable 3rd Party Add-ons!!!
« Antwort #5 am: 10-08-2006, 11:15:08 »

I forgot some...

Added:
Classifieds
Events
Hot Properties

Last updated on August 10th, 2006 at 2:15 AM PDT (GMT-7)
Moderator informieren Gespeichert
Rob Schley - Rob[at]NocLabs[dot]com - --ALTER LINK WURDE ENTFERNT--
Technical Lead, Joomla! Quality & Testing Working Group
List of Insecure 3rd Party Extensions: --ALTER LINK WURDE ENTFERNT--
RobS
Moderator
Joomla! Hero
*
Online Online

Beiträge: 564


Profil anzeigen WWW Private Mitteilung (Online)

Re: Attention: Official List of Vulnerable 3rd Party Add-ons!!!
« Antwort #6 am: 10-08-2006, 21:07:53 »

Added Blogg-X Mambot. - Removed Blogg-X. It does not appear to be vulnerable upon further investigation.
Updated information about Security Images.

That brings the number of insecure 3rd party extensions up to 40 extensions.

Last updated on August 12th, 2006 at 11:16 AM PDT (GMT-7)
« Letzte Änderung: 12-08-2006, 20:17:29 von RobS » Moderator informieren Gespeichert
Rob Schley - Rob[at]NocLabs[dot]com - --ALTER LINK WURDE ENTFERNT--
Technical Lead, Joomla! Quality & Testing Working Group
List of Insecure 3rd Party Extensions: --ALTER LINK WURDE ENTFERNT--
RobS
Moderator
Joomla! Hero
*
Online Online

Beiträge: 564


Profil anzeigen WWW Private Mitteilung (Online)

Re: Attention: Official List of Vulnerable 3rd Party Add-ons!!!
« Antwort #7 am: 12-08-2006, 20:18:30 »

Removed Blogg-X. Upon further investigation Blogg-X does not appear to be vulnerable.
Moderator informieren Gespeichert
Rob Schley - Rob[at]NocLabs[dot]com - --ALTER LINK WURDE ENTFERNT--
Technical Lead, Joomla! Quality & Testing Working Group
List of Insecure 3rd Party Extensions: --ALTER LINK WURDE ENTFERNT--
infograf768
Global Moderator
Joomla! Hero
*
Offline Offline

Beiträge: 3599


Profil anzeigen Private Mitteilung (Offline)

Re: Attention: Official List of Vulnerable 3rd Party Add-ons!!!
« Antwort #8 am: 15-08-2006, 07:59:41 »

Temporarily added the abandonned Webring component until updated by Robs.
Moderator informieren Gespeichert
Jean-Marie Simonet / infograf · --ALTER LINK WURDE ENTFERNT-- · GMT +1
• --ALTER LINK WURDE ENTFERNT-- •
RobInk
Q&T Workgroup
Joomla! Hero
*
Offline Offline

Beiträge: 3921


NL :: GMT+1

Profil anzeigen WWW Private Mitteilung (Offline)

Re: Attention: Official List of Vulnerable 3rd Party Add-ons!!!
« Antwort #9 am: 15-08-2006, 20:58:29 »

Update has come in about Mosets Hot Property, there 0.98 release should fix the security issues. Still need to verify before we change the current listing.

Regards Robin
Moderator informieren Gespeichert
Joomla! Core Team Member :: Stability Team Member :: Team Co-Leader, Quality & Testing
Joom!Fish Project Member, Quality & Testing
--ALTER LINK WURDE ENTFERNT-- :: RobInk's Joomla! Solutions - Affordable and Quality Web Design
--ALTER LINK WURDE ENTFERNT-- :: As IVIVIO we bring true enterprise-grade systems to market
RobInk
Q&T Workgroup
Joomla! Hero
*
Offline Offline

Beiträge: 3921


NL :: GMT+1

Profil anzeigen WWW Private Mitteilung (Offline)

Re: Attention: Official List of Vulnerable 3rd Party Add-ons!!!
« Antwort #10 am: 16-08-2006, 09:16:00 »

I have received a reply from the developer of Mosets Tree and Hot Property. Mosets Tree 1.5.9 and Hot Property 0.98 are now solving the security issues. The list will be changed accordingly.
Moderator informieren Gespeichert
Joomla! Core Team Member :: Stability Team Member :: Team Co-Leader, Quality & Testing
Joom!Fish Project Member, Quality & Testing
--ALTER LINK WURDE ENTFERNT-- :: RobInk's Joomla! Solutions - Affordable and Quality Web Design
--ALTER LINK WURDE ENTFERNT-- :: As IVIVIO we bring true enterprise-grade systems to market
infograf768
Global Moderator
Joomla! Hero
*
Offline Offline

Beiträge: 3599


Profil anzeigen Private Mitteilung (Offline)

Re: Attention: Official List of Vulnerable 3rd Party Add-ons!!!
« Antwort #11 am: 18-08-2006, 06:22:02 »

See here for hacks concerning Joomlaboard 1.1.2 and CB 1.0.1 to make them compatible with register globals off as set in globals.php

--ALTER LINK WURDE ENTFERNT--

(please integrate in your list, Robs)
Moderator informieren Gespeichert
Jean-Marie Simonet / infograf · --ALTER LINK WURDE ENTFERNT-- · GMT +1
• --ALTER LINK WURDE ENTFERNT-- •
RobInk
Q&T Workgroup
Joomla! Hero
*
Offline Offline

Beiträge: 3921


NL :: GMT+1

Profil anzeigen WWW Private Mitteilung (Offline)

Re: Attention: Official List of Vulnerable 3rd Party Add-ons!!!
« Antwort #12 am: 18-08-2006, 08:33:20 »

Thanks JM, added as a note/reference to the listing.
Moderator informieren Gespeichert
Joomla! Core Team Member :: Stability Team Member :: Team Co-Leader, Quality & Testing
Joom!Fish Project Member, Quality & Testing
--ALTER LINK WURDE ENTFERNT-- :: RobInk's Joomla! Solutions - Affordable and Quality Web Design
--ALTER LINK WURDE ENTFERNT-- :: As IVIVIO we bring true enterprise-grade systems to market
RobInk
Q&T Workgroup
Joomla! Hero
*
Offline Offline

Beiträge: 3921


NL :: GMT+1

Profil anzeigen WWW Private Mitteilung (Offline)

Re: Attention: Official List of Vulnerable 3rd Party Add-ons!!!
« Antwort #13 am: 18-08-2006, 13:23:45 »

Added JIM 1.0.1. (PMS) to the list, regarding --ALTER LINK WURDE ENTFERNT--

( --ALTER LINK WURDE ENTFERNT-- )

Robin
Moderator informieren Gespeichert
Joomla! Core Team Member :: Stability Team Member :: Team Co-Leader, Quality & Testing
Joom!Fish Project Member, Quality & Testing
--ALTER LINK WURDE ENTFERNT-- :: RobInk's Joomla! Solutions - Affordable and Quality Web Design
--ALTER LINK WURDE ENTFERNT-- :: As IVIVIO we bring true enterprise-grade systems to market
RobInk
Q&T Workgroup
Joomla! Hero
*
Offline Offline

Beiträge: 3921


NL :: GMT+1

Profil anzeigen WWW Private Mitteilung (Offline)

Re: Attention: Official List of Vulnerable 3rd Party Add-ons!!!
« Antwort #14 am: 18-08-2006, 13:34:30 »

Added Mambelfish 1.x due to report ; --ALTER LINK WURDE ENTFERNT--
Mehr
22 Aug. 2006 23:21 #3171 von ghosty
ghosty antwortete auf Re: Aus dem Joomla.org Forum Teil 3
So ...

Sorry erstmal das alles in Englisch ist oben, doch wir denken das die Info wichtiger ist als die Sprache..

Zudem auch hier ein Link : --ALTER LINK WURDE ENTFERNT--

Auf das Joomla.org Developer (Entwickler) Netz das einwening aufschluss darüber geben soll ..

Wir hoffen das Ihr die Beschriebenen Anmerkungen usw. verstehen könnt, ansonsten bitte fragt ..

Griessli

Pete
Powered by Kunena Forum

Joomla! Verband Schweiz - Mitglied werden