|
VM Security Bulletin 2008-01-30-1 |
|
|
|
Written by Soeren Eberhardt-Biermann
|
|
Wednesday, 30 January 2008 02:00 |
Component Type: VirtueMart Core. The affected files are part of the standard VirtueMart Distribution.
Affected Versions: VirtueMart Version 1.0.13a and all versions below.
Vulnerability Type: File Contents Disclosure.
Severity: HIGH.
Problem Description: User-supplied input passed to VirtueMart when viewing a product is not properly sanitized before being used in the script to read a template file. This makes is possible to read and display arbitrary files on the Server.
Solution: An updated version is available from the VirtueMart Download Section. Patch Packages are avaiable for each previous version containing only those files which have changed to the latest version.
General advice:
Follow the recommendations from the Joomla! Administrator's Security Checklist and the Security & Performance FAQ for Joomla!. This way you get basic security for your Store.
Keep notice of the VirtueMart Security Bulletins.
Credits: The VirtueMart Team wishes to thank "Antoine T" for reporting the problem at the VirtueMart Bug Tracker.
|
|
Last Updated on Sunday, 03 February 2008 20:07 |