When running a site under SSL ONLY (the entire site was forced to be under ssl), Joomla! had not set the SSL flag on the cookie. This had allowed someone monitoring the network to find the cookie related to the session.

This vulnerability affects the following application versions:

  • Joomla 1.5.0
  • Joomla 1.5.1
  • Joomla 1.5.2
  • Joomla 1.5.3
  • Joomla 1.5.4
  • Joomla 1.5.5
  • Joomla 1.5.6
  • Joomla 1.5.7
  • Joomla 1.5.8

Skriv et svar

Din e-mailadresse vil ikke blive publiceret. Krævede felter er markeret med *