<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/rss2full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><!-- generator="Joomla! - Open Source Content Management" --><rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" version="2.0">
	<channel>
		<title>Joomla! Developer Network - Security News</title>
		<description>Joomla! - the dynamic portal engine and content management system</description>
		<link>http://developer.joomla.org/security/news.html</link>
		<lastBuildDate>Sat, 04 Feb 2012 03:43:00 +0000</lastBuildDate>
		<generator>Joomla! - Open Source Content Management</generator>
		
		<language>en-gb</language>
		<atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/rss+xml" href="http://feeds.feedburner.com/JoomlaSecurityNews" /><feedburner:info uri="joomlasecuritynews" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" /><feedburner:emailServiceId>JoomlaSecurityNews</feedburner:emailServiceId><feedburner:feedburnerHostname>http://feedburner.google.com</feedburner:feedburnerHostname><item>
			<title>[20120201] - Core - Information Disclosure</title>
			<link>http://feedproxy.google.com/~r/JoomlaSecurityNews/~3/PkBR45UJQxo/387-20120201-core-information-disclosure.html</link>
			<guid isPermaLink="false">http://developer.joomla.org/security/news/387-20120201-core-information-disclosure.html</guid>
			<description>&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Project:&lt;/strong&gt; Joomla!&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;SubProject:&lt;/strong&gt; All&lt;/li&gt;
&lt;li&gt;&lt;strong&gt; Severity:&lt;/strong&gt; Low&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Versions:&lt;/strong&gt; 2.5.0 and 1.7.0 - 1.7.4&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Exploit type:&lt;/strong&gt; Information Disclosure&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Reported Date:&lt;/strong&gt; 2012-January-29&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Fixed Date:&lt;/strong&gt; 2012-February-02&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Description&lt;/h2&gt;
&lt;p&gt;Inadequate validation leads to information disclosure in administrator.&lt;/p&gt;
&lt;h2&gt;Affected Installs&lt;/h2&gt;
&lt;p&gt;Joomla! version 2.5.0, 1.7.4, and all earlier 1.7.x versions&lt;/p&gt;
&lt;h2&gt;Solution&lt;/h2&gt;
&lt;p&gt;Upgrade to version 1.7.5 or 2.5.1 or higher&lt;/p&gt;
&lt;p&gt;Reported by Jakub Galczyk&lt;/p&gt;
&lt;h2&gt;Contact&lt;/h2&gt;
&lt;p&gt;The JSST at the Joomla! Security Center.&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/JoomlaSecurityNews?a=PkBR45UJQxo:tozT3WXEdn0:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/JoomlaSecurityNews?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/JoomlaSecurityNews/~4/PkBR45UJQxo" height="1" width="1"/&gt;</description>
			<author>dextercowley@gmail.com (Mark Dexter)</author>
			<pubDate>Thu, 02 Feb 2012 05:25:21 +0000</pubDate>
		<feedburner:origLink>http://developer.joomla.org/security/news/387-20120201-core-information-disclosure.html</feedburner:origLink></item>
		<item>
			<title>[20120202] - Core - Information Disclosure</title>
			<link>http://feedproxy.google.com/~r/JoomlaSecurityNews/~3/MFhhodAeXho/388-20120202-core-information-disclosure.html</link>
			<guid isPermaLink="false">http://developer.joomla.org/security/news/388-20120202-core-information-disclosure.html</guid>
			<description>&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Project:&lt;/strong&gt; Joomla!&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;SubProject:&lt;/strong&gt; All&lt;/li&gt;
&lt;li&gt;&lt;strong&gt; Severity:&lt;/strong&gt; Moderate&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Versions:&lt;/strong&gt; 1.7.4 and all earlier 1.7.x versions&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Exploit type:&lt;/strong&gt; Information Disclosure&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Reported Date:&lt;/strong&gt; 2012-January-06&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Fixed Date:&lt;/strong&gt; 2012-February-02&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Description&lt;/h2&gt;
&lt;p&gt;On some servers the error log could be read by unauthorised users.&lt;/p&gt;
&lt;h2&gt;Affected Installs&lt;/h2&gt;
&lt;p&gt;Joomla! version 1.7.4 and all earlier 1.7.x versions&lt;/p&gt;
&lt;h2&gt;Solution&lt;/h2&gt;
&lt;p&gt;Upgrade to version 2.5.1 or 1.7.5 or higher&lt;/p&gt;
&lt;p&gt;Reported by Alain Rivest&lt;/p&gt;
&lt;h2&gt;Contact&lt;/h2&gt;
&lt;p&gt;The JSST at the Joomla! Security Center.&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/JoomlaSecurityNews?a=MFhhodAeXho:TcD6ohzsuCc:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/JoomlaSecurityNews?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/JoomlaSecurityNews/~4/MFhhodAeXho" height="1" width="1"/&gt;</description>
			<author>dextercowley@gmail.com (Mark Dexter)</author>
			<pubDate>Thu, 02 Feb 2012 05:25:21 +0000</pubDate>
		<feedburner:origLink>http://developer.joomla.org/security/news/388-20120202-core-information-disclosure.html</feedburner:origLink></item>
		<item>
			<title>[20120203] - Core - Information Disclosure</title>
			<link>http://feedproxy.google.com/~r/JoomlaSecurityNews/~3/LY07jV4Rnvs/389-20120203-core-information-disclosure.html</link>
			<guid isPermaLink="false">http://developer.joomla.org/security/news/389-20120203-core-information-disclosure.html</guid>
			<description>&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Project:&lt;/strong&gt; Joomla!&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;SubProject:&lt;/strong&gt; All&lt;/li&gt;
&lt;li&gt;&lt;strong&gt; Severity:&lt;/strong&gt; Low&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Versions:&lt;/strong&gt; 2.5.0 and 1.7.0 - 1.7.4&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Exploit type:&lt;/strong&gt; Information Disclosure&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Reported Date:&lt;/strong&gt; 2012-January-29&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Fixed Date:&lt;/strong&gt; 2012-February-02&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Description&lt;/h2&gt;
&lt;p&gt;Inadequate validation leads to path disclosure in administrator.&lt;/p&gt;
&lt;h2&gt;Affected Installs&lt;/h2&gt;
&lt;p&gt;Joomla! version 2.5.0, 1.7.4, and all earlier 1.7.x versions&lt;/p&gt;
&lt;h2&gt;Solution&lt;/h2&gt;
&lt;p&gt;Upgrade to version 2.5.1 or 1.7.5 or higher&lt;/p&gt;
&lt;p&gt;Reported by Jakub Galczyk&lt;/p&gt;
&lt;h2&gt;Contact&lt;/h2&gt;
&lt;p&gt;The JSST at the Joomla! Security Center.&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/JoomlaSecurityNews?a=LY07jV4Rnvs:YgvDxlGAUzQ:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/JoomlaSecurityNews?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/JoomlaSecurityNews/~4/LY07jV4Rnvs" height="1" width="1"/&gt;</description>
			<author>dextercowley@gmail.com (Mark Dexter)</author>
			<pubDate>Thu, 02 Feb 2012 05:25:21 +0000</pubDate>
		<feedburner:origLink>http://developer.joomla.org/security/news/389-20120203-core-information-disclosure.html</feedburner:origLink></item>
		<item>
			<title>[20120101] - Core - Information Disclosure</title>
			<link>http://feedproxy.google.com/~r/JoomlaSecurityNews/~3/MYKnZ2QJKYE/382-20120101-core-information-disclosure.html</link>
			<guid isPermaLink="false">http://developer.joomla.org/security/news/382-20120101-core-information-disclosure.html</guid>
			<description>&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Project:&lt;/strong&gt; Joomla!&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;SubProject:&lt;/strong&gt; All&lt;/li&gt;
&lt;li&gt;&lt;strong&gt; Severity:&lt;/strong&gt; Low&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Versions:&lt;/strong&gt; 1.7.3 and all earlier 1.7 and 1.6 versions&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Exploit type:&lt;/strong&gt; Information Disclosure&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Reported Date:&lt;/strong&gt; 2012-January-07&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Fixed Date:&lt;/strong&gt; 2012-January-24&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Description&lt;/h2&gt;
&lt;p&gt;Inadequate filtering leads to information disclosure.&lt;/p&gt;
&lt;h2&gt;Affected Installs&lt;/h2&gt;
&lt;p&gt;Joomla! version 1.7.3 and all earlier versions&lt;/p&gt;
&lt;h2&gt;Solution&lt;/h2&gt;
&lt;p&gt;Upgrade to version 1.7.4 or 2.5.0 or higher&lt;/p&gt;
&lt;p&gt;Reported by Cyrille Barthelemy&lt;/p&gt;
&lt;h2&gt;Contact&lt;/h2&gt;
&lt;p&gt;The JSST at the Joomla! Security Center.&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/JoomlaSecurityNews?a=MYKnZ2QJKYE:LuZxJDgem44:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/JoomlaSecurityNews?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/JoomlaSecurityNews/~4/MYKnZ2QJKYE" height="1" width="1"/&gt;</description>
			<author>dextercowley@gmail.com (Mark Dexter)</author>
			<pubDate>Mon, 23 Jan 2012 09:45:28 +0000</pubDate>
		<feedburner:origLink>http://developer.joomla.org/security/news/382-20120101-core-information-disclosure.html</feedburner:origLink></item>
		<item>
			<title>[20120102] - Core - XSS Vulnerability</title>
			<link>http://feedproxy.google.com/~r/JoomlaSecurityNews/~3/XAEsWEG3dgU/383-20120102-core-xss-vulnerability.html</link>
			<guid isPermaLink="false">http://developer.joomla.org/security/news/383-20120102-core-xss-vulnerability.html</guid>
			<description>&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Project: &lt;/strong&gt;Joomla!&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;SubProject:&lt;/strong&gt; All&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Severity:&lt;/strong&gt; Moderate&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Versions:&lt;/strong&gt; 1.7.3 and all earlier 1.7 and 1.6 versions&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Exploit type:&lt;/strong&gt; XSS Vulnerability&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Reported Date:&lt;/strong&gt; 2011-November-16&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Fixed Date:&lt;/strong&gt; 2012-January-24&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Description&lt;/h2&gt;
&lt;p&gt;Inadequate filtering leads to XSS vulnerability.&lt;/p&gt;
&lt;h2&gt;Affected Installs&lt;/h2&gt;
&lt;p&gt;Joomla! version 1.7.3 and all earlier versions&lt;/p&gt;
&lt;h2&gt;Solution&lt;/h2&gt;
&lt;p&gt;Upgrade to version 1.7.4 or 2.5.0 or higher&lt;/p&gt;
&lt;p&gt;Reported by Ankita Kapadia&lt;/p&gt;
&lt;h2&gt;Contact&lt;/h2&gt;
&lt;p&gt;The JSST at the Joomla! Security Center.&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/JoomlaSecurityNews?a=XAEsWEG3dgU:63AinNntsww:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/JoomlaSecurityNews?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/JoomlaSecurityNews/~4/XAEsWEG3dgU" height="1" width="1"/&gt;</description>
			<author>dextercowley@gmail.com (Mark Dexter)</author>
			<pubDate>Mon, 23 Jan 2012 09:45:28 +0000</pubDate>
		<feedburner:origLink>http://developer.joomla.org/security/news/383-20120102-core-xss-vulnerability.html</feedburner:origLink></item>
		<item>
			<title>[20120103] - Core - Information Disclosure</title>
			<link>http://feedproxy.google.com/~r/JoomlaSecurityNews/~3/Ed0TMAvyQ4g/384-20120103-core-information-disclosure.html</link>
			<guid isPermaLink="false">http://developer.joomla.org/security/news/384-20120103-core-information-disclosure.html</guid>
			<description>&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Project:&lt;/strong&gt; Joomla!&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;SubProject:&lt;/strong&gt; All&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Severity:&lt;/strong&gt; Low&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Versions:&lt;/strong&gt; 1.7.3 and all earlier 1.7 and 1.6 versions&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Exploit type:&lt;/strong&gt; Information Disclosure&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Reported Date:&lt;/strong&gt; 2011-December-19&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Fixed Date:&lt;/strong&gt; 2012-January-24&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Description&lt;/h2&gt;
&lt;p&gt;Inadequate filtering leads to information disclosure.&lt;/p&gt;
&lt;h2&gt;Affected Installs&lt;/h2&gt;
&lt;p&gt;Joomla! version 1.7.3 and all earlier versions&lt;/p&gt;
&lt;h2&gt;Solution&lt;/h2&gt;
&lt;p&gt;Upgrade to version 1.7.4 or 2.5.0 or higher&lt;/p&gt;
&lt;p&gt;Reported by Jean-Marie Simonet&lt;/p&gt;
&lt;h2&gt;Contact&lt;/h2&gt;
&lt;p&gt;The JSST at the Joomla! Security Center.&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/JoomlaSecurityNews?a=Ed0TMAvyQ4g:blmC1ASORQc:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/JoomlaSecurityNews?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/JoomlaSecurityNews/~4/Ed0TMAvyQ4g" height="1" width="1"/&gt;</description>
			<author>dextercowley@gmail.com (Mark Dexter)</author>
			<pubDate>Mon, 23 Jan 2012 09:45:28 +0000</pubDate>
		<feedburner:origLink>http://developer.joomla.org/security/news/384-20120103-core-information-disclosure.html</feedburner:origLink></item>
		<item>
			<title>[20120104] - Core - XSS Vulnerability</title>
			<link>http://feedproxy.google.com/~r/JoomlaSecurityNews/~3/K4UuOr8BroM/385-20120104-core-xss-vulnerability.html</link>
			<guid isPermaLink="false">http://developer.joomla.org/security/news/385-20120104-core-xss-vulnerability.html</guid>
			<description>&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Project:&lt;/strong&gt; Joomla!&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;SubProject:&lt;/strong&gt; All&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Severity:&lt;/strong&gt; Moderate&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Versions:&lt;/strong&gt; 1.7.3 and all earlier versions&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Exploit type:&lt;/strong&gt; XSS Vulnerability&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Reported Date:&lt;/strong&gt; 2012-January-22&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Fixed Date:&lt;/strong&gt; 2012-January-24&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Description&lt;/h2&gt;
&lt;p&gt;Inadequate filtering leads to XSS vulnerability.&lt;/p&gt;
&lt;h2&gt;Affected Installs&lt;/h2&gt;
&lt;p&gt;Joomla! version 1.7.3 and all earlier 1.7 and 1.6 versions&lt;/p&gt;
&lt;h2&gt;Solution&lt;/h2&gt;
&lt;p&gt;Upgrade to version 1.7.4 or 2.5.0 or higher&lt;/p&gt;
&lt;p&gt;Reported by David Jardin&lt;/p&gt;
&lt;h2&gt;Contact&lt;/h2&gt;
&lt;p&gt;The JSST at the Joomla! Security Center.&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/JoomlaSecurityNews?a=K4UuOr8BroM:a7HBKupbzlE:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/JoomlaSecurityNews?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/JoomlaSecurityNews/~4/K4UuOr8BroM" height="1" width="1"/&gt;</description>
			<author>dextercowley@gmail.com (Mark Dexter)</author>
			<pubDate>Mon, 23 Jan 2012 09:45:28 +0000</pubDate>
		<feedburner:origLink>http://developer.joomla.org/security/news/385-20120104-core-xss-vulnerability.html</feedburner:origLink></item>
		<item>
			<title>[20111102] - Core - Password Change</title>
			<link>http://feedproxy.google.com/~r/JoomlaSecurityNews/~3/JbROZtZZkvQ/374-20111102-core-password-change.html</link>
			<guid isPermaLink="false">http://developer.joomla.org/security/news/374-20111102-core-password-change.html</guid>
			<description>&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Project:&lt;/strong&gt; Joomla!&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;SubProject:&lt;/strong&gt; All&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Severity:&lt;/strong&gt; High&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Versions:&lt;/strong&gt; 1.7.2 and all 1.6.x versions&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Exploit type:&lt;/strong&gt; Password Change&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Reported Date:&lt;/strong&gt; 2011-October-28&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Fixed Date:&lt;/strong&gt; 2011-November-14&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Description&lt;/h2&gt;
&lt;p&gt;&lt;span id=":1d2" dir="ltr"&gt;Weak random number generation during password reset leads to possibility of changing a user's password.&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;Affected Installs&lt;/h2&gt;
&lt;p&gt;Joomla! version 1.7.2 and all earlier 1.7.x and 1.6.x versions&lt;/p&gt;
&lt;h2&gt;Solution&lt;/h2&gt;
&lt;p&gt;Upgrade to the latest Joomla! version (1.7.3 or later)&lt;/p&gt;
&lt;p&gt;Reported by Gregor Kopf and &lt;span&gt;David Jardin&lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;Contact&lt;/h2&gt;
&lt;p&gt;The JSST at the &lt;a href="http://developer.joomla.org/security.html" title="Contact the JSST"&gt;Joomla! Security Center&lt;/a&gt;.&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/JoomlaSecurityNews?a=JbROZtZZkvQ:e4a90cSPPRA:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/JoomlaSecurityNews?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/JoomlaSecurityNews/~4/JbROZtZZkvQ" height="1" width="1"/&gt;</description>
			<author>dextercowley@gmail.com (Mark Dexter)</author>
			<pubDate>Tue, 15 Nov 2011 04:33:00 +0000</pubDate>
		<feedburner:origLink>http://developer.joomla.org/security/news/374-20111102-core-password-change.html</feedburner:origLink></item>
		<item>
			<title>[20111103] - Core - Password Change</title>
			<link>http://feedproxy.google.com/~r/JoomlaSecurityNews/~3/nF-FZ-0jMUM/375-20111103-core-password-change.html</link>
			<guid isPermaLink="false">http://developer.joomla.org/security/news/375-20111103-core-password-change.html</guid>
			<description>&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Project:&lt;/strong&gt; Joomla!&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;SubProject:&lt;/strong&gt; All&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Severity:&lt;/strong&gt; High&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Versions:&lt;/strong&gt; 1.5.24 and all earlier 1.5 versions&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Exploit type:&lt;/strong&gt; Password Change&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Reported Date:&lt;/strong&gt; 2011-October-28&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Fixed Date:&lt;/strong&gt; 2011-November-14&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Description&lt;/h2&gt;
&lt;p&gt;&lt;span id=":1d2" dir="ltr"&gt;Weak random number generation during password reset leads to possibility of changing a user's password.&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;Affected Installs&lt;/h2&gt;
&lt;p&gt;Joomla! version 1.5.24 and all earlier 1.5 versions&lt;/p&gt;
&lt;h2&gt;Solution&lt;/h2&gt;
&lt;p&gt;Upgrade to the latest Joomla! 1.5 version (1.5.25 or later)&lt;/p&gt;
&lt;p&gt;Reported by &lt;span&gt;Gregor Kopf and David Jardin&lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;Contact&lt;/h2&gt;
&lt;p&gt;The JSST at the &lt;a href="http://developer.joomla.org/security.html" title="Contact the JSST"&gt;Joomla! Security Center&lt;/a&gt;.&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/JoomlaSecurityNews?a=nF-FZ-0jMUM:nNhJ-8IavSc:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/JoomlaSecurityNews?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/JoomlaSecurityNews/~4/nF-FZ-0jMUM" height="1" width="1"/&gt;</description>
			<author>dextercowley@gmail.com (Mark Dexter)</author>
			<pubDate>Tue, 15 Nov 2011 04:33:00 +0000</pubDate>
		<feedburner:origLink>http://developer.joomla.org/security/news/375-20111103-core-password-change.html</feedburner:origLink></item>
		<item>
			<title>[20111101] - Core - XSS Vulnerability</title>
			<link>http://feedproxy.google.com/~r/JoomlaSecurityNews/~3/sz1HyAL_294/373-20111101-core-xss-vulnerability.html</link>
			<guid isPermaLink="false">http://developer.joomla.org/security/news/373-20111101-core-xss-vulnerability.html</guid>
			<description>&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Project:&lt;/strong&gt; Joomla!&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;SubProject:&lt;/strong&gt; All&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Severity:&lt;/strong&gt; Medium&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Versions:&lt;/strong&gt; 1.7.2 and all 1.6.x versions&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Exploit type:&lt;/strong&gt; XSS&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Reported Date:&lt;/strong&gt; 2011-October-21&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Fixed Date:&lt;/strong&gt; 2011-November-14&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Description&lt;/h2&gt;
&lt;p&gt;&lt;span id=":1d2" dir="ltr"&gt;Inadequate filtering leads to XSS vulnerability in back end.&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;Affected Installs&lt;/h2&gt;
&lt;p&gt;Joomla! version 1.7.2 and all earlier 1.7.x and 1.6.x versions&lt;/p&gt;
&lt;h2&gt;Solution&lt;/h2&gt;
&lt;p&gt;Upgrade to the latest Joomla! version (1.7.3 or later)&lt;/p&gt;
&lt;p&gt;Reported by &lt;span&gt;Corné Hannema&lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;Contact&lt;/h2&gt;
&lt;p&gt;The JSST at the &lt;a href="http://developer.joomla.org/security.html" title="Contact the JSST"&gt;Joomla! Security Center&lt;/a&gt;.&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/JoomlaSecurityNews?a=sz1HyAL_294:eau9ddWZMWw:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/JoomlaSecurityNews?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/JoomlaSecurityNews/~4/sz1HyAL_294" height="1" width="1"/&gt;</description>
			<author>dextercowley@gmail.com (Mark Dexter)</author>
			<pubDate>Tue, 15 Nov 2011 04:33:00 +0000</pubDate>
		<feedburner:origLink>http://developer.joomla.org/security/news/373-20111101-core-xss-vulnerability.html</feedburner:origLink></item>
		<item>
			<title>[20111001] - Core - Information Disclosure</title>
			<link>http://feedproxy.google.com/~r/JoomlaSecurityNews/~3/_TyaH8ToZ98/370-20111001-core-information-disclosure.html</link>
			<guid isPermaLink="false">http://developer.joomla.org/security/news/370-20111001-core-information-disclosure.html</guid>
			<description>&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Project:&lt;/strong&gt; Joomla!&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;SubProject:&lt;/strong&gt; All&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Severity:&lt;/strong&gt; Moderate&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Versions:&lt;/strong&gt; 1.7.1&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Exploit type:&lt;/strong&gt; Information Disclosure&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Reported Date:&lt;/strong&gt; 2011-September-09&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Fixed Date:&lt;/strong&gt; 2011-October-17&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Description&lt;/h2&gt;
&lt;p&gt;&lt;span id=":1d2" dir="ltr"&gt;Weak encryption causes potential information disclosure.&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;Affected Installs&lt;/h2&gt;
&lt;p&gt;Joomla! version 1.7.1 and earlier&lt;/p&gt;
&lt;h2&gt;Solution&lt;/h2&gt;
&lt;p&gt;Upgrade to the latest Joomla! version (1.7.2 or later)&lt;/p&gt;
&lt;p&gt;Reported by Jeff Channell&lt;/p&gt;
&lt;h2&gt;Contact&lt;/h2&gt;
&lt;p&gt;The JSST at the &lt;a href="http://developer.joomla.org/security.html" title="Contact the JSST"&gt;Joomla! Security Center&lt;/a&gt;.&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/JoomlaSecurityNews?a=_TyaH8ToZ98:Bdw0j-A8nR0:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/JoomlaSecurityNews?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/JoomlaSecurityNews/~4/_TyaH8ToZ98" height="1" width="1"/&gt;</description>
			<author>dextercowley@gmail.com (Mark Dexter)</author>
			<pubDate>Mon, 17 Oct 2011 20:59:00 +0000</pubDate>
		<feedburner:origLink>http://developer.joomla.org/security/news/370-20111001-core-information-disclosure.html</feedburner:origLink></item>
		<item>
			<title>[20111002] - Core - Information Disclosure</title>
			<link>http://feedproxy.google.com/~r/JoomlaSecurityNews/~3/Nyl0K1n4nak/371-20111002-core-information-disclosure.html</link>
			<guid isPermaLink="false">http://developer.joomla.org/security/news/371-20111002-core-information-disclosure.html</guid>
			<description>&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Project:&lt;/strong&gt; Joomla!&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;SubProject:&lt;/strong&gt; All&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Severity:&lt;/strong&gt; Low&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Versions:&lt;/strong&gt; 1.7.1&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Exploit type:&lt;/strong&gt; Information Disclosure&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Reported Date:&lt;/strong&gt; 2011-August-02&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Fixed Date:&lt;/strong&gt; 2011-October-17&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Description&lt;/h2&gt;
&lt;p&gt;&lt;span id=":1d2" dir="ltr"&gt;Inadequate error checking causes potential information disclosure.&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;Affected Installs&lt;/h2&gt;
&lt;p&gt;Joomla! version 1.7.1 and earlier&lt;/p&gt;
&lt;h2&gt;Solution&lt;/h2&gt;
&lt;p&gt;Upgrade to the latest Joomla! version (1.7.2 or later)&lt;/p&gt;
&lt;p&gt;Reported by Aung Khant, YGN Ethical Hacker Group&lt;/p&gt;
&lt;h2&gt;Contact&lt;/h2&gt;
&lt;p&gt;The JSST at the &lt;a href="http://developer.joomla.org/security.html" title="Contact the JSST"&gt;Joomla! Security Center&lt;/a&gt;.&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/JoomlaSecurityNews?a=Nyl0K1n4nak:YD53CN4ZPxc:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/JoomlaSecurityNews?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/JoomlaSecurityNews/~4/Nyl0K1n4nak" height="1" width="1"/&gt;</description>
			<author>dextercowley@gmail.com (Mark Dexter)</author>
			<pubDate>Mon, 17 Oct 2011 20:59:00 +0000</pubDate>
		<feedburner:origLink>http://developer.joomla.org/security/news/371-20111002-core-information-disclosure.html</feedburner:origLink></item>
		<item>
			<title>[20111003] - Core - Information Disclosure</title>
			<link>http://feedproxy.google.com/~r/JoomlaSecurityNews/~3/Qzmq6A_Uzk4/372-20111003-core-information-disclosure.html</link>
			<guid isPermaLink="false">http://developer.joomla.org/security/news/372-20111003-core-information-disclosure.html</guid>
			<description>&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Project:&lt;/strong&gt; Joomla!&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;SubProject:&lt;/strong&gt; All&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Severity:&lt;/strong&gt; Moderate&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Versions:&lt;/strong&gt; 1.5.23 and earlier&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Exploit type:&lt;/strong&gt; Information Disclosure&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Reported Date:&lt;/strong&gt; 2011-September-09&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Fixed Date:&lt;/strong&gt; 2011-October-17&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Description&lt;/h2&gt;
&lt;p&gt;&lt;span id=":1d2" dir="ltr"&gt;Weak encryption causes potential information disclosure.&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;Affected Installs&lt;/h2&gt;
&lt;p&gt;Joomla! version 1.5.23 and earlier&lt;/p&gt;
&lt;h2&gt;Solution&lt;/h2&gt;
&lt;p&gt;Upgrade to the latest Joomla! version (1.5.24 or later)&lt;/p&gt;
&lt;p&gt;Reported by Jeff Channell&lt;/p&gt;
&lt;h2&gt;Contact&lt;/h2&gt;
&lt;p&gt;The JSST at the &lt;a href="http://developer.joomla.org/security.html" title="Contact the JSST"&gt;Joomla! Security Center&lt;/a&gt;.&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/JoomlaSecurityNews?a=Qzmq6A_Uzk4:R0qeVJ8ZGR4:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/JoomlaSecurityNews?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/JoomlaSecurityNews/~4/Qzmq6A_Uzk4" height="1" width="1"/&gt;</description>
			<author>dextercowley@gmail.com (Mark Dexter)</author>
			<pubDate>Mon, 17 Oct 2011 20:59:00 +0000</pubDate>
		<feedburner:origLink>http://developer.joomla.org/security/news/372-20111003-core-information-disclosure.html</feedburner:origLink></item>
		<item>
			<title>[20110903] - Core - Information Disclosure</title>
			<link>http://feedproxy.google.com/~r/JoomlaSecurityNews/~3/ud9WY8V6zwA/369-20110903-core-information-disclosure.html</link>
			<guid isPermaLink="false">http://developer.joomla.org/security/news/369-20110903-core-information-disclosure.html</guid>
			<description>&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Project:&lt;/strong&gt; Joomla!&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;SubProject:&lt;/strong&gt; All&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Severity:&lt;/strong&gt; Low&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Versions:&lt;/strong&gt; 1.7.0&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Exploit type:&lt;/strong&gt; Information Disclosure&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Reported Date:&lt;/strong&gt; 2011-September-23&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Fixed Date:&lt;/strong&gt; 2011-September-26&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Description&lt;/h2&gt;
&lt;p&gt;&lt;span id=":1d2" dir="ltr"&gt;Inadequate error checking causes information disclosure.&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;Affected Installs&lt;/h2&gt;
&lt;p&gt;Joomla! version 1.7.0&lt;/p&gt;
&lt;h2&gt;Solution&lt;/h2&gt;
&lt;p&gt;Upgrade to the latest Joomla! version (1.7.1 or later)&lt;/p&gt;
&lt;p&gt;Reported by National Vulnerability Database&lt;/p&gt;
&lt;h2&gt;Contact&lt;/h2&gt;
&lt;p&gt;The JSST at the &lt;a href="http://developer.joomla.org/security.html" title="Contact the JSST"&gt;Joomla! Security Center&lt;/a&gt;.&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/JoomlaSecurityNews?a=ud9WY8V6zwA:bbi92clX2gw:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/JoomlaSecurityNews?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/JoomlaSecurityNews/~4/ud9WY8V6zwA" height="1" width="1"/&gt;</description>
			<author>dextercowley@gmail.com (Mark Dexter)</author>
			<pubDate>Mon, 26 Sep 2011 20:59:22 +0000</pubDate>
		<feedburner:origLink>http://developer.joomla.org/security/news/369-20110903-core-information-disclosure.html</feedburner:origLink></item>
		<item>
			<title>[20110901] - Core - XSS Vulnerability</title>
			<link>http://feedproxy.google.com/~r/JoomlaSecurityNews/~3/0HLFpgWwqKw/367-20110901-core-xss-vulnerability.html</link>
			<guid isPermaLink="false">http://developer.joomla.org/security/news/367-20110901-core-xss-vulnerability.html</guid>
			<description>&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Project:&lt;/strong&gt; Joomla!&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;SubProject:&lt;/strong&gt; All&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Severity:&lt;/strong&gt; Medium&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Versions:&lt;/strong&gt; 17.0 and all 1.6.x versions&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Exploit type:&lt;/strong&gt; XSS&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Reported Date:&lt;/strong&gt; 2011-August-02&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Fixed Date:&lt;/strong&gt; 2011-September-22&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Description&lt;/h2&gt;
&lt;p&gt;&lt;span id=":1d2" dir="ltr"&gt;Inadequate escaping leads to XSS vulnerability in com_search.&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;Affected Installs&lt;/h2&gt;
&lt;p&gt;Joomla! version 1.7.0 and all 1.6.x versions&lt;/p&gt;
&lt;h2&gt;Solution&lt;/h2&gt;
&lt;p&gt;Upgrade to the latest Joomla! version (1.7.1 or later)&lt;/p&gt;
&lt;p&gt;Reported by Aung Khant&lt;/p&gt;
&lt;h2&gt;Contact&lt;/h2&gt;
&lt;p&gt;The JSST at the &lt;a href="http://developer.joomla.org/security.html" title="Contact the JSST"&gt;Joomla! Security Center&lt;/a&gt;.&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/JoomlaSecurityNews?a=0HLFpgWwqKw:Zu2t6ae74kI:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/JoomlaSecurityNews?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/JoomlaSecurityNews/~4/0HLFpgWwqKw" height="1" width="1"/&gt;</description>
			<author>dextercowley@gmail.com (Mark Dexter)</author>
			<pubDate>Fri, 23 Sep 2011 02:33:00 +0000</pubDate>
		<feedburner:origLink>http://developer.joomla.org/security/news/367-20110901-core-xss-vulnerability.html</feedburner:origLink></item>
	</channel>
</rss>

