Joomla

Get help on web editors (Frontpage, Dreamweaver) and web languages (HTML, ASP, PHP).
KALSTER
Forum Moderator
Posts: 5439
Joined: 12 Oct 2008, 02:08

Re: Joomla

Post by KALSTER »

Joomla Remote
Looks pretty interesting! Trying it out now.
"It is the mark of an educated mind to be able to entertain a thought without accepting it." - Aristotle
Intel i5 2500; AsRock Z77 Extreme 4; Asus GTX580; 4x 2GB DDR3 1333; Intel 520 240GB SSD + 2x WD 3TB + 2TB Samsung; Samsung 22X DVD/RW; 23" LG W2343T-PF; Huntkey 700W
doo_much
Registered User
Posts: 26022
Joined: 13 May 2004, 02:00
Location: Getting there...
Contact:

Re: Joomla

Post by doo_much »

Stuart wrote: My biggest gripe with Joomla so far was that there was no simple, Joomla-certified way to update your site from 1.0 to 1.5. We have a LOT of content on our church website, and it took me MONTHS to figure out how to successfully transfer content across. I sincerely hope that they're not going to make the same mistake when they release 2.0.

On another note, I've been surprised to see how long 1.5.15 has lasted without a security update. Either they did a really good job of it or they are not updating like they should. In the past, updates have been rather frequent. But this particular release has stayed current for a long time now.
I luckily only ran into it post 1.0! :)

And since I'm a horrible webmaster I have weasel do all my security updates for me - I'm too lazy! :mrgreen:

KALSTER wrote:
Joomla Remote
Looks pretty interesting! Trying it out now.
It looks pretty interesting but it actually kinda sux. ;)
MOOD - Thirsty

A surprising amount of modern pseudoscience is coming out of the environmental sector. Perhaps it should not be so surprising given that environmentalism is political rather than scientific.
Timothy Casey
doo_much
Registered User
Posts: 26022
Joined: 13 May 2004, 02:00
Location: Getting there...
Contact:

Re: Joomla

Post by doo_much »

Stuart wrote: On another note, I've been surprised to see how long 1.5.15 has lasted without a security update. Either they did a really good job of it or they are not updating like they should. In the past, updates have been rather frequent. But this particular release has stayed current for a long time now.
It seem that your wish is their command!

Joomla! Security News


* [20100423] - Core - Negative Values for Limit and Offset
* [20100423] - Core - Installer Migration Script
* [20100423] - Core - Sessation Fixation
* [20100423] - Core - Password Reset Tokens

[20100423] - Core - Negative Values for Limit and Offset

Posted: 23 Apr 2010 10:31 AM PDT

* Project: Joomla!
* SubProject: All
* Severity: Moderate
* Versions: 1.5.15 and all previous 1.5 releases
* Exploit type: information Disclosure
* Reported Date: 2010-Feb-21
* Fixed Date: 2010-Apr-23

Description

If a user entered a URL with a negative query limit or offset, a PHP notice would display revealing information about the system.
Affected Installs

All 1.5.x installs prior to and including 1.5.15 are affected.
Solution

Upgrade to the latest Joomla! version (1.5.16 or later)

Reported by Security List
Contact

The JSST at the Joomla! Security Center.
MOOD - Thirsty

A surprising amount of modern pseudoscience is coming out of the environmental sector. Perhaps it should not be so surprising given that environmentalism is political rather than scientific.
Timothy Casey
User avatar
Stuart
Lead Forum Administrator
Posts: 38503
Joined: 19 May 2005, 02:00
Location: Home

Re: Joomla

Post by Stuart »

Woohoo. 1.5.15 introduced some other minor irritations for me. Let's hpe they're fixed now.
Image
doo_much
Registered User
Posts: 26022
Joined: 13 May 2004, 02:00
Location: Getting there...
Contact:

Re: Joomla

Post by doo_much »

Let me know.

I'm waaaay to lazy to do it myself! ;)
MOOD - Thirsty

A surprising amount of modern pseudoscience is coming out of the environmental sector. Perhaps it should not be so surprising given that environmentalism is political rather than scientific.
Timothy Casey
Post Reply