Session id doesn’t get modified when user logs in. A remote site may be able to forward a visitor to the Joomla! site and set a specific cookie. If the user then logs in, the remote site can use that cookie to authenticate as that user.

This vulnerability affects the following application versions:

  • Joomla 1.5.0
  • Joomla 1.5.1
  • Joomla 1.5.2
  • Joomla 1.5.3
  • Joomla 1.5.4
  • Joomla 1.5.5
  • Joomla 1.5.6
  • Joomla 1.5.7
  • Joomla 1.5.8
  • Joomla 1.5.9
  • Joomla 1.5.10
  • Joomla 1.5.11
  • Joomla 1.5.12
  • Joomla 1.5.13
  • Joomla 1.5.14
  • Joomla 1.5.15

Skriv et svar

Din e-mailadresse vil ikke blive publiceret. Krævede felter er markeret med *