Bug#407997: CVE-2007-0374: joomla: SQL injection vulnerability

2007-01-23 Thread Martin Michlmayr
* Alex de Oliveira Silva <[EMAIL PROTECTED]> [2007-01-23 09:00]: > Joomla is a new package. > I do not know if was correct to open this bug. OK, thanks for the note. -- Martin Michlmayr http://www.cyrius.com/ -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Troubl

Bug#407997: CVE-2007-0374: joomla: SQL injection vulnerability

2007-01-23 Thread Alex de Oliveira Silva
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Martin Michlmayr escreveu: > * Alex de Oliveira Silva <[EMAIL PROTECTED]> [2007-01-22 17:50]: >> Package: joomla > > Is this package actually in Debian? What does > dpkg -p joomla | grep Maintainer > say? Hi Martin. Joomla is a new package. I do n

Bug#407997: CVE-2007-0374: joomla: SQL injection vulnerability

2007-01-23 Thread Martin Michlmayr
* Alex de Oliveira Silva <[EMAIL PROTECTED]> [2007-01-22 17:50]: > Package: joomla Is this package actually in Debian? What does dpkg -p joomla | grep Maintainer say? -- Martin Michlmayr http://www.cyrius.com/ -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe".

Bug#407997: CVE-2007-0374: joomla: SQL injection vulnerability

2007-01-22 Thread Alex de Oliveira Silva
Package: joomla Version: 1.0.12-1 Severity: important Tags: security SQL injection vulnerability in (1) Joomla! 1.0.11 and 1.5 Beta, and (2) Mambo 4.6.1, allows remote attackers to execute arbitrary SQL commands via the id parameter when cancelling content editing. I'am working in the new upstre