Source |
Fortinet |
Identifiant |
230084 |
Date de publication |
2016-10-27 13:53:06 (vue: 2016-10-27 13:53:06) |
Titre |
Joomla – From No One to the Highest Privilege |
Texte |
Joomla, a popular free and open-source content management system, just released version 3.6.4 that fixed two critical vulnerabilities:
[CVE-2016-8870] - Core - Account Creation: attackers can exploit this vulnerability to create any account in a Joomla system regardless of whether its registration has been disabled.
[CVE-2016-8869] - Core - Elevated Privileges:Â with the vulnerability above, an attacker not only can register an account in a vulnerable system, but also register with the highest privilege – Administrator.
CVE-2016-8870... |
Notes |
|
Envoyé |
Oui |
Condensat |
2016 8869 8870 above account administrator also any attacker attackers been but can content core create creation: critical cve disabled elevated exploit fixed free from has highest its joomla just management not one only open popular privilege privileges:â regardless register registration released source system two version vulnerabilities: vulnerability vulnerable whether |
Tags |
|
Stories |
|
Move |
|