Top Sliding Window

Joomla In Libraries

  • Increase font size
  • Default font size
  • Decrease font size
Home Working with Joomla Joomla 1.5.17 Released

Joomla 1.5.17 Released

E-mail Print

Download JoomlaJOOMLA.ORG released its newest version 1.5.17. The new release included some minor bug fixes. The previous 1.5.15 version had no major security issues; however there are some moderate security concerns. If your website is running a ealier version of Joomla, test the upgrade first in a development enviornment or on a lesser important website before you upgrade your live site.

How to upgrade Joomla ?

  1. Download the needed patch file (according to the version you want to upgrade)
  2. Backup your site files and database
  3. Unpack the patch file
  4. Overwrite all files on your FTP
  5. Check that your website is working correctly

Minor security issues with Joomla 1.5.15

  • If a user entered a URL with a negative query limit or offset, a PHP notice would display revealing information about the system.
  • The migration script in the Joomla! installer does not check the file type being uploaded. If the installation application is present, an attacker could use it to upload malicious files to a server. (It is NEVER recommended to leave the installer script on a live server)
  • Session id doesn't get modified when user logs in.  A remote site may be able to forward a visitor to the Joomla! site and set a specific cookie.  If the user then logs in, the remote site can use that cookie to authenticate as that user.
  • When a user requests a password reset, the reset tokens were stored in plain text in the database. While this is not a vulnerability in itself, it allows user accounts to be compromised if there is an extension on the site with an SQL injection vulnerability.

Joomla 1.5.17 fixes in the core components:

  • contact
  • newsfeeds
  • media

Joomla 1.5.17 other fixes:

  • Fixed problem logging in when Session Handler is set to None
  • Fixed error message when running Joomla! in a PHP version prior to version 5.2
  • Reverted change to JFolder::makesafe method that introduced a bug
Comments (0)Add Comment

Write comment
smaller | bigger

security code
Write the displayed characters


busy
 

People

Total Members : 993
This Week : 14 Registers
This Month : 38 Registers
We have 9 guests online

SPONSOR LINKS
Arizona Landscaping - Credit Counseling - United Specialties - Renegade Motorhomes