Actions

Archived

Difference between revisions of "Vulnerable Extensions List 0210"

From Joomla! Documentation

m (removing {{tl|inuse}} template, this article has not been edited since Feb 2010 and it is showing up in actively editing category)
(9 intermediate revisions by 2 users not shown)
Line 1: Line 1:
{{inuse}}
 
 
 
== February 2010 Reported Vulnerable Extensions ==
 
== February 2010 Reported Vulnerable Extensions ==
 
<startFeed />
 
<startFeed />
  
 
'''Please check with the extension publisher in case of any questions over the security of their product.'''
 
'''Please check with the extension publisher in case of any questions over the security of their product.'''
Report Vulnerable extensions either in the [[jforum:432]] security topic clearly marked with the first word in the title being ''Vulnerable Report'' where the security moderators or JSST team will respond. For a guide to the codes, polease see here.  
+
Report Vulnerable extensions either in the [[jforum:432]] security topic clearly marked with the first word in the title being ''Vulnerable Report'' where the security moderators or JSST team will respond. For a guide to the [http://docs.joomla.org/Vulnerable_Extensions_List_0210#Codes_used codes]
  
 
[http://docs.joomla.org/Vulnerable_Extensions_List Previous Reports]
 
[http://docs.joomla.org/Vulnerable_Extensions_List Previous Reports]
Line 23: Line 21:
 
|style="background:red; color:white" | '''  Not Known'''
 
|style="background:red; color:white" | '''  Not Known'''
 
|-
 
|-
|style="background:red; color:white" |
+
|style="#cef2e0; color:black" |
  
 
==  [http://extensions.joomla.org/extensions/calendars-a-events/events/95 JEvent] ==
 
==  [http://extensions.joomla.org/extensions/calendars-a-events/events/95 JEvent] ==
 
| SQLi  
 
| SQLi  
 
|reported Jan 29
 
|reported Jan 29
|style="background:red; color:white" | ''' Not Known'''
+
|style="background:#cef2e0; color:black" | ''' fixes in version 1.5.3.b'''
 
|-
 
|-
 
|style="background:red; color:white" |
 
|style="background:red; color:white" |
Line 44: Line 42:
 
<endFeed />
 
<endFeed />
  
''This list is change protected, for updates or editing requests [http://forum.joomla.org/memberlist.php?mode=viewprofile&u=28000 Mandville] or [http://forum.joomla.org/memberlist.php?mode=viewprofile&u=87230 lafrance]
+
''This list is change protected, for updates or additions [http://forum.joomla.org/memberlist.php?mode=viewprofile&u=28000 Mandville] or [http://forum.joomla.org/memberlist.php?mode=viewprofile&u=87230 lafrance]
 
''
 
''
  
Line 50: Line 48:
  
 
== Codes used ==
 
== Codes used ==
SQLi - SQL injection [[http://en.wikipedia.org/wiki/Code_injection#SQL_injection]]
+
SQLi - SQL injection [http://en.wikipedia.org/wiki/Code_injection#SQL_injection wikipedia]
LFI - Local File Inclusion [http://www.scribd.com/doc/6498408/Remote-and-Local-File-Inclusion-Explained]
+
RFI - Remote file inclusion [http://en.wikipedia.org/wiki/Remote_File_Inclusion]
+
DT - Directory Traversal [[http://en.wikipedia.org/wiki/Directory_traversal]]
+
  
 +
LFI - Local File Inclusion [http://www.scribd.com/doc/6498408/Remote-and-Local-File-Inclusion-Explained scribd]
  
 +
RFI - Remote file inclusion [http://en.wikipedia.org/wiki/Remote_File_Inclusion wikipedia]
  
== [[A note to developers.]] ==
+
DT - Directory Traversal [http://en.wikipedia.org/wiki/Directory_traversal wikipedia]
 +
 
 +
== Developers - How to get yourself removed from the from the VEL ==
 +
 
 +
Resolved items will be removed after a suitable period and not on resolution
  
We only pass out information that is already out there, we will not
 
remove anything from the list until a suitable period has passed, we will mark is as resolved or updated.
 
If your entry is on this list and you "fixed" it ages ago, tell us please.
 
 
Please solve the issues and:
 
Please solve the issues and:
''  If JED listed''
+
 
 +
* If JED listed  
 
Attach the new zip file at your actual JED listing.
 
Attach the new zip file at your actual JED listing.
 +
 
Change the extension version at JED listing.
 
Change the extension version at JED listing.
Contact the JED by mail back with a notice and ask them to republish
 
your listing.
 
'' If not JED listed.''
 
  
 +
Contact the JED by mail with a notice and ask them republish your listing.
 +
 +
 +
* If not JED listed.
 
Inform us by PM of the link to your resolution notice on your website.
 
Inform us by PM of the link to your resolution notice on your website.
 +
 +
 
NB '''We do not fix, we report'''
 
NB '''We do not fix, we report'''
 +
 +
 +
== Notes ==
 +
We try and put the newest item to the top of the list but it is not always possible.
 +
List as discussed in  [[jtopic:455746]] by [http://forum.joomla.org/memberlist.php?mode=viewprofile&u=67439 PhilD] editing by [http://forum.joomla.org/memberlist.php?mode=viewprofile&u=28000 Mandville]
 +
For instructions on how to [http://forum.joomla.org/viewtopic.php?f=432&t=478030 receive the feed.]
 +
----
 +
 +
 +
----

Revision as of 15:38, 2 February 2013

Replacement filing cabinet.png
This page has been archived - Please Do Not Edit or Create Pages placed in this namespace. The pages in the Archived namespace exist only as a historical reference, it will not be improved and its content may be incomplete.

Contents

February 2010 Reported Vulnerable Extensions

Please check with the extension publisher in case of any questions over the security of their product. Report Vulnerable extensions either in the jforum:432 security topic clearly marked with the first word in the title being Vulnerable Report where the security moderators or JSST team will respond. For a guide to the codes

Previous Reports

Extension Details Date Added Extension Update Link & Date

Jvideodirect

SQLi Jan 29 Not Known

JEvent

SQLi reported Jan 29 fixes in version 1.5.3.b

Item3

3a 3b 3c

Item4

This list is change protected, for updates or additions Mandville or lafrance


Codes used

SQLi - SQL injection wikipedia

LFI - Local File Inclusion scribd

RFI - Remote file inclusion wikipedia

DT - Directory Traversal wikipedia

Developers - How to get yourself removed from the from the VEL

Resolved items will be removed after a suitable period and not on resolution

Please solve the issues and:

  • If JED listed

Attach the new zip file at your actual JED listing.

Change the extension version at JED listing.

Contact the JED by mail with a notice and ask them republish your listing.


  • If not JED listed.

Inform us by PM of the link to your resolution notice on your website.


NB We do not fix, we report


Notes

We try and put the newest item to the top of the list but it is not always possible. List as discussed in jtopic:455746 by PhilD editing by Mandville For instructions on how to receive the feed.