Akeeba Backup ist eine Komponente zum sichern einer kompletten Joomla! Installation incl. der Datenbank und der Dateien, die aus der altbekannten und bewährten Komponente Joomlapack hervorgegangen ist. So kann eine komplette Joomla! Webseite auf Mausklick zuverlässig gesichert und wieder hergestellt werden - auf dem gleichen Server oder einem beliebigen anderen, der die Voraussetzungen für den Betrieb von Joomla! erfüllt.
Dropbox ist ein Filehosting-Dienst, der bis zu 2 GB Speicherplatz im Internet kostenlos zur Verfügung stellt. Mit Akeeba Backup Professional können Sie ein Backupprofil einrichten und diesen Speicherplatz automatisch für Backups nutzen. Der von Dropbox zur Verfügung gestellte Desktop-Client ermöglicht zudem eine einfache Verwaltung Ihrer Backup-Dateien.
Dazu zählen z.B. Web Application Firewalls (WAF), die auch kostenlos erhältlich sind und durchaus einen sinnvollen, zusätzlichen Schutz bieten können. Zumindest kann sogenannten 'Script-Kiddies' der Spass deutlich erschwert werden.
Joomla (hervorgegangen aus dem Open Source Projekt Mambo) ist ein freies Content-Management-System (CMS) zur Erstellung von Webseiten und steht unter der GNU General Public License. Es ist in der aktuellen Version 3.6.5 in PHP 5 geschrieben und verwendet MySQL als Datenbank. Zusammen mit WordPress, TYPO3 und Drupal gehört es zu den bekanntesten und meistverwendeten Open-Source-Content-Management-Systemen.
Project: Joomla!SubProject: CMSImpact: LowSeverity: LowVersions:3.0.0 - 3.9.23Exploit type: Incorrect Access ControlReported Date: 2020-07-07Fixed Date: 2021-01-12CVE Number: CVE-2021-23123DescriptionLack of ACL checks in the orderPosition endpoint of com_modules leak names of unpublished and/or inaccessible modules.Affected InstallsJoomla! CMS versions 3.0.0 - 3.9.23SolutionUpgrade to version[…]
Read more...Project: Joomla!SubProject: CMSImpact: ModerateSeverity: LowVersions:3.9.0 - 3.9.23Exploit type: XSSReported Date: 2020-09-01Fixed Date: 2021-01-12CVE Number: CVE-2021-23124DescriptionLack of escaping in mod_breadcrumbs aria-label attribute allows XSS attacks.Affected InstallsJoomla! CMS versions 3.9.0 - 3.9.23SolutionUpgrade to version 3.9.24ContactThe JSST at the Joomla! Security Centre.Reported By: Šarūnas[…]
Read more...Project: Joomla!SubProject: CMSImpact: ModerateSeverity: LowVersions:3.1.0 - 3.9.23Exploit type: XSSReported Date: 2020-09-01Fixed Date: 2021-01-12CVE Number: CVE-2021-23125DescriptionLack of escaping of image-related parameters in multiple com_tags views cause lead to XSS attack vectors.Affected InstallsJoomla! CMS versions 3.1.0 - 3.9.23SolutionUpgrade to version 3.9.24ContactThe JSST[…]
Read more...
The performance of the default article system in Joomla really sucks big time, that's a well know fact.It''s actually one of the reasons we built K2 in the first place.And as we venture into Joomla 4 territory, instead of seeing[…]
Project: Joomla!SubProject: CMSImpact: ModerateSeverity: LowVersions: 2.5.0-3.9.22Exploit type: Information DisclosureReported Date: 2020-06-21Fixed Date: 2020-11-24CVE Number: CVE-2020-35610DescriptionThe autosuggestion feature of com_finder did not respect the access level of the corresponding terms.Affected InstallsJoomla! CMS versions 2.5.0 - 3.9.22SolutionUpgrade to version 3.9.23ContactThe JSST at the Joomla![…]
Read more...Project: Joomla!SubProject: CMSImpact: ModerateSeverity: LowVersions: 2.5.0-3.9.22Exploit type: Information DisclosureReported Date: 2020-09-23Fixed Date: 2020-11-24CVE Number: CVE-2020-35611DescriptionThe globlal configuration page does not remove secrets from the HTML output, disclosing the current values.Affected InstallsJoomla! CMS versions 2.5.0 - 3.9.22SolutionUpgrade to version 3.9.23ContactThe JSST at the[…]
Read more...Project: Joomla!SubProject: CMSImpact: ModerateSeverity: LowVersions: 2.5.0-3.9.22Exploit type: Path traversalReported Date: 2020-10-06Fixed Date: 2020-11-24CVE Number: CVE-2020-35612DescriptionThe folder parameter of mod_random_image lacked input validation, leading to a path traversal vulnerability.Affected InstallsJoomla! CMS versions 2.5.0 - 3.9.22SolutionUpgrade to version 3.9.23ContactThe JSST at the Joomla![…]
Read more...Project: Joomla!SubProject: CMSImpact: HighSeverity: LowVersions: 3.0.0-3.9.22Exploit type: SQL InjectionReported Date: 2020-10-13Fixed Date: 2020-11-24CVE Number: CVE-2020-35613DescriptionImproper filter blacklist configuration leads to a SQL injection vulnerability in the backend user list.Affected InstallsJoomla! CMS versions 3.0.0 - 3.9.22SolutionUpgrade to version 3.9.23ContactThe JSST at[…]
Read more...Project: Joomla!SubProject: CMSImpact: LowSeverity: LowVersions: 3.9.0-3.9.22Exploit type: User EnumerationReported Date: 2020-08-15Fixed Date: 2020-11-24CVE Number: CVE-2020-35614DescriptionImproper handling of the username leads to a user enumeration attack vector in the backend login page.Affected InstallsJoomla! CMS versions 3.9.0 - 3.9.22SolutionUpgrade to version 3.9.23ContactThe[…]
Read more...Project: Joomla!SubProject: CMSImpact: LowSeverity: LowVersions: 3.9.0-3.9.22Exploit type: CSRFReported Date: 2020-10-08Fixed Date: 2020-11-24CVE Number: CVE-2020-35615DescriptionA missing token check in the emailexport feature of com_privacy causes a CSRF vulnerability.Affected InstallsJoomla! CMS versions 3.9.0 - 3.9.22SolutionUpgrade to version 3.9.23ContactThe JSST at the Joomla![…]
Read more...Project: Joomla!SubProject: CMSImpact: HighSeverity: LowVersions:1.7.0 - 3.9.22Exploit type: ACL ViolationReported Date: 2018-11-04Fixed Date: 2020-11-24CVE Number: CVE-2020-35616DescriptionLack of input validation while handling ACL rulesets can cause write ACL violations.Affected InstallsJoomla! CMS versions 1.7.0 - 3.9.22SolutionUpgrade to version 3.9.23ContactThe JSST at the[…]
Read more...publisher, 3.0.19, 3rd party extension, XSS (Cross Site Scripting)
Read more...paGO Commerce, 2.5.9.0, 3rd party extension, SQL Injection
Read more...
The K2 Plugin for sh404SEF version 1.6.0 is now available to download for subscribers. This is a bug fix release that addresses compatibility with K2 v2.10.3+ and improves support for PHP 7.x in general.Here's what's been added or changed in the K2 Plugin[…]
A plugin for supporting K2 in sh404SEF.Use the plugin to configure K2 URLs when using sh404SEF in a multitude of options.Unlike the previous built-in implementation for sh404SEF, this new plugin provides new URL manipulation options and it has dual compatibility[…]
Social Chat, 1.5 and Below, 3rd party extension, SQL Injection Iacopo Guarneri
Read more...
SocialConnect is the only Joomla extension that allows you to integrate your Joomla site with social networks and identity providers for user authentication, posting content directly to social networks and 3rd-party comment system integration.FeaturesLet your users register to your website[…]
NEW VERSION 3.8 released in June 2020!Adding image galleries inside your Joomla articles has never been easier! Using the "Simple Image Gallery PRO" extension from JoomlaWorks you can quickly display a folder of images on your server as a stylish[…]
Simple Image Gallery Pro v3.8.0 is now available to download for subscribers. This new release improves upon existing features, extends Flickr support to galleries (beyond albums/sets) and adds PHP 7.4 & Postgres compatibility.Here's what's been added or changed in Simple Image[…]
AllVideos (by JoomlaWorks) is the universal media player for Joomla and a classic must-have extension for any Joomla based website.Use the plugin to easily embed video & audio content from all major 3rd party media providers (YouTube, Vimeo, Dailymotion, Twitch,[…]
Version 6.1.0 of AllVideos is now available. This new release introduces support for Mixcloud embeds and improves support for PHP 7.4.Here's what's been added or changed in this new release of AllVideos:Added support for Mixcloud embeds. Just use the pattern[…]
K2 is the popular powerful content extension for Joomla with CCK-like features. It provides an out-of-the box integrated solution featuring rich content forms for items (think of Joomla articles with additional fields for article images, videos, image galleries and attachments),[…]
K2 v2.10.3 is now available to download for Joomla versions 1.5 to 3.x. This is a maintenance & bugfix release, which refines the backend user interface (building upon the changes that were introduced with v2.10.0 to v2.10.2), improves client-size (frontend) caching & resolves broken auto-generated feeds[…]
hwdplayer,4.2,SQL InjectionPossible abandonware also
Read more...
I don't usually write similar blog posts, but I've been really enjoying Snowflake recently. What's Snowflake you ask? Well, it's a new open source graphical SSH/SFTP client which makes working with remote servers a breeze. It works like Panic's Coda when[…]
Adding image galleries inside your Joomla articles is now super-easy and simple, using the magical "Simple Image Gallery" plugin for Joomla. The plugin can turn any folder of images located inside your Joomla website into a grid-style image gallery with[…]
Simple Image Gallery (free) version 4.1.0 is now available to download. This is a maintenance release.Here's what's been added or changed in Simple Image Gallery (free) with the release of v4.1.0:Allow the plugin to accept WEBP images as source images[…]
Version 6.0.0 of AllVideos is now available. This is a feature release, which also introduces full support with the upcoming Joomla version 4 release.Here's what's been added or changed in this new release of AllVideos:Fully compatible with the upcoming Joomla[…]
Simple Image Gallery (free) version 4.0.0 is now available to download. This marks our first extension update that supports the upcoming Joomla version 4 (currently in "beta").Here's what's been added or changed in Simple Image Gallery (free) with the release[…]
RadioWave v1.2.0 has just been released. This is a bugfix and feature-improvement release.Here's what's been added or changed in RadioWave with the release of v1.2.0:Fixed time parsing for the OnAir template override (K2 Content module) which caused the module's output[…]
SocialConnect v1.10.0 is now available to download for subscribers. This new release improves compatibility with recent API changes in Facebook and LinkedIn.Here's what's been added or changed in SocialConnect with the release of v1.10.0:Facebook authorization in SocialConnect's settings will now[…]
K2 v2.10.2 is now available to download for Joomla versions 1.5 to 3.x. This is a maintenance & security release: it concludes the backend user interface changes that were introduced with v2.10.0 and is now 100% mobile-friendly and it also addresses[…]
As we're preparing to launch a new website for getk2.org, we have decided to make an important change in the K2 Extensions Directory (KED).We stopped accepting new entries for templates in the KED about 2 weeks ago and this week[…]
Now fully responsive & Joomla 1.5 - 3.x compatible! Frontpage SlideShow is the easiest & most eye-catching way to display your featured articles or products in your Joomla website. It creates an uber cool slideshow with text snippets laying on[…]
K2 v2.10.1 is now available to download for Joomla versions 1.5 to 3.x. This is a maintenance release that addresses a few bugs that were introduced with v2.10.0 released a couple weeks ago and we urge everyone using v2.10.0 to[…]
K2 v2.10.0 is now available to download for Joomla versions 1.5 to 3.x. This release introduces a refreshed backend design as well as feature improvements or additions (like Google Structured Data) and as always, performance improvements everywhere.To install K2 for[…]
Adding RSS/Atom syndicated content inside your Joomla website is now super-easy and simple with the 'Simple RSS Feed Reader' module from JoomlaWorks. All you have to do is add a few feeds to the module parameters, publish the module in[…]
K2 v2.9.0 is now available to download for Joomla 1.5 to 3.x. In short, this release improves compatibility with the latest releases of Joomla 3.8.x & improves frontend performance overall.To install K2 for the first time or update your existing[…]
Disqus Comments (for Joomla) integrates the Disqus comments system & service into any Joomla based website. Disqus (pronounced 'discuss') is a service and tool for web comments and discussions - currently the most popular comments-as-a-service provider worldwide. It makes commenting[…]
Rapicode, nultiple extensions, current versions, back doorExtensions affected are:-Rapi Content TickerRapi Content CarouselRapi Cookie ConsentRapi CountdownRapi PreloaderRapi Loading Progress BarRapi Page AnimateAt the moment the back door seems to be loading mining code, it can be used to load arbitrary[…]
Read more...Google Map Landkarten from joomla-24.de, versions 4.2.3 and previous, SQL Injection
Read more...Fastball by Fastball Productions, versions yet to be determined but probably all, SQL Injection
Read more...File Download Tracker by techsolsystem.com, 3.0, SQL Injection
Read more...SquadManagement by Lars Hildebrandt, versions 1.0.3 and previous, SQL Injection
Read more...JMS Music by Joomasters, versions 1.1.1 and previous, SQL Injection
Read more...
K2 v2.8.0 is now available to download for Joomla 1.5 to 3.x. This release improves the content management workflow and UI, is fully compatible with PHP 7.x and the latest Joomla 3.7.x, while at the same time addressing various issues from[…]
K2 v2.7.1 is now available to download for Joomla 1.5 to 3.x. This is a minor release addressing various issues from performance to UI, to bug fixes and security.To install K2 for the first time or update your existing K2[…]
Start your update engines! K2 v2.7.0 is now available to download for Joomla 1.5 to 3.x. With a new improved user interface for the component in the Joomla backend, updated and now responsive-friendly default HTML overrides, Joomla 3.5 support, PHP[…]
(originally posted in the JoomlaWorks blog) It's been a while, I know. You see, Joomla is not the only organization undergoing changes. So are we :)We are happy to announce that K2 Next will be officially presented in the upcoming JoomlaDay[…]
Aufgrund der Popularität und bekannter Sicherheitsprobleme werden Joomla-Installationen immer wieder zur Zielscheibe von Angriffen, insbesondere in Form sogenannter Defacements. Laut einer IBM-Studie aus dem Jahr 2008 ist die Zahl der Sicherheitslücken bei Webapplikationen allerdings generell drastisch angestiegen, so dass prinzipiell alle Systeme von diesem Problem betroffen sind. Insbesondere WordPress ist in dieser Hinsicht mindestens genauso gefährdet.