|
1 |
Yelp
Updated: 26 Sep 2011
SQLi - Unable to locate developer. Possibly a custom extension.
Feb 01
Not Known
Read more:
Read More
|
107 |
|
2 |
SqlReport
Updated: 26 Sep 2011
Sqlreport has a sql/RFI exploit. awaiting confirmation on exact developer.
Feb 20
Not Known
Read more:
Read More
|
89 |
|
3 |
heza content
Updated: 26 Sep 2011
SQLi heza content
13 march 2010
Read more:
Read More
|
161 |
|
4 |
gigcalender
Updated: 26 Sep 2011
SQLi gigcalender
13 march 2010
Read more:
Read More
|
147 |
|
5 |
econtentsite
|
99 |
|
6 |
JprojectMan
Updated: 26 Sep 2011
LFI http://extensions.joomla.org/extensions/communities-a-groupware/project-a-task-management/5676
110410
Read more:
Read More
|
89 |
|
7 |
Memory Book
Updated: 26 Sep 2011
http://dev.pucit.edu.pk/
120410
Read more:
Read More
|
98 |
|
8 |
diary
Updated: 26 Sep 2011
http://dev.pucit.edu.pk/
120410
Read more:
Read More
|
101 |
|
9 |
webtv
Updated: 26 Sep 2011
http://dev.pucit.edu.pk/
120410
Read more:
Read More
|
110 |
|
10 |
horoscope
Updated: 26 Sep 2011
http://dev.pucit.edu.pk/
120410
Read more:
Read More
|
103 |
|
11 |
advertising
Updated: 26 Sep 2011
http://dev.pucit.edu.pk/
Read more:
Read More
|
94 |
|
12 |
cvmaker
Updated: 26 Sep 2011
http://dev.pucit.edu.pk/
Read more:
Read More
|
86 |
|
13 |
worldrates
Updated: 26 Sep 2011
http://dev.pucit.edu.pk/
120410
Read more:
Read More
|
95 |
|
14 |
jvehicles
Updated: 26 Sep 2011
SQL Injection http://jvehicles.com
120410
Read more:
Read More
|
91 |
|
15 |
Sweetykeeper
Updated: 26 Sep 2011
Sweetykeeper Local File Inclusion Vulnerability http://www.joomlacorner.com/
120410
Read more:
Read More
|
110 |
|
16 |
MT Fire Eagle
Updated: 26 Sep 2011
LFI http://joomlacode.org/gf/project/jfireeagle/frs/ http://www.moto-treks.com
190410
product considered retired and to be replaced by dev
Read more:
Read More
|
96 |
|
17 |
jnewspaper
Updated: 26 Sep 2011
jnewspaper (cid) SQL Injection Vulnerability
Read more:
Read More
|
99 |
|
18 |
GBU FACEBOOK
Updated: 26 Sep 2011
GBU FACEBOOK SQL injection vulnerability http://www.gbugrafici.nl/gbufacebook/
Read more:
Read More
|
93 |
|
19 |
iF surfALERT
Updated: 26 Sep 2011
iF surfALERT Local File Inclusion Vulnerability
Read more:
Read More
|
98 |
|
20 |
Contact Us Draw Root Map
Updated: 26 Sep 2011
Draw Root Map Local File Inclusion Vulnerability joomlacomponent.inetlanka.com
Read more:
Read More
|
112 |
|
21 |
Multiple Map
Updated: 26 Sep 2011
Multiple Map Local File Inclusion Vulnerability joomlacomponent.inetlanka.com
Read more:
Read More
|
103 |
|
22 |
Multiple Root
Updated: 26 Sep 2011
Multiple Root Local File Inclusion Vulnerability http://joomlacomponent.inetlanka.com/
Read more:
Read More
|
99 |
|
23 |
Matamko
Updated: 26 Sep 2011
Matamko Local File Inclusion Vulnerability
210410
Read more:
Read More
|
104 |
|
24 |
ZiMB Manager
Updated: 26 Sep 2011
Joomla Component ZiMB Manager Local File Inclusion Vulnerability
210410
Read more:
Read More
|
97 |
|
25 |
Archery Scores
Updated: 26 Sep 2011
Archery Scores (com_archeryscores) v1.0.6 LFI Vulnerability
210410
Read more:
Read More
|
99 |
|
26 |
Ultimate Portfolio
Updated: 26 Sep 2011
Ultimate Portfolio Local File Inclusion Vulnerability
Read more:
Read More
|
105 |
|
27 |
htmlcoderhelper graphics
Updated: 26 Sep 2011
htmlcoderhelper graphics v1.0.6 LFI Vulnerability
Read more:
Read More
|
95 |
|
28 |
SmartSite
Updated: 26 Sep 2011
SmartSite com_smartsite Local File Inclusion Vulnerability
Read more:
Read More
|
99 |
|
29 |
Noticeboard
Updated: 26 Sep 2011
Noticeboard for Joomla "controller" Local File Inclusion Vulnerability
Read more:
Read More
|
106 |
|
30 |
JE Property
Updated: 26 Sep 2011
JE Property Finder Upload Vulnerability
Read more:
Read More
|
98 |
|
31 |
Camp26 Visitor
Updated: 26 Sep 2011
RFI www.camp26.biz
Read more:
Read More
|
97 |
|
32 |
Seber Cart
Updated: 26 Sep 2011
Local File Disclosure Vulnerability
Developer Update 140510
Read more:
Read More
|
108 |
|
33 |
konsultasi
Updated: 26 Sep 2011
SQL Injection Vulnerability
Read more:
Read More
|
96 |
|
34 |
JE Quotation Form
Updated: 26 Sep 2011
http://joomlaextensions.co.in/free-download/doc_download/11-je-quotation-form.html LFI
developers statement of resolution note, now known as JE Quote Form
Read more:
Read More
|
143 |
|
35 |
ActiveHelper LiveHelp
Updated: 26 Sep 2011
XSS in LiveHelp
200510
Read more:
Read More
|
109 |
|
36 |
SectionEx
Updated: 26 Sep 2011
Stack Ideas section Ex LFI
Read more:
Read More
|
90 |
|
37 |
JE Job
Updated: 26 Sep 2011
http://joomlaextensions.co.in/ LFI SQLi
Read more:
Read More
|
88 |
|
38 |
MediQnA
Updated: 26 Sep 2011
MediQnA LFI vulnerability version : v1.1
Read more:
Read More
|
158 |
|
39 |
JE Poll
Updated: 26 Sep 2011
http://slideshow.joomlaextensions.co.in/ SQL Injection Vulnerability
Read more:
Read More
|
226 |
|
40 |
jsjobs
Updated: 26 Sep 2011
jsjobs SQL Injection Vulnerability
Read more:
Read More
|
93 |
|
41 |
Gallery 2 Bridge
Updated: 26 Sep 2011
g2bridge LFI vulnerability
Read more:
Read More
|
109 |
|
42 |
djartgallery
Updated: 26 Sep 2011
http://www.design-joomla.eu Multiple Vul
05/06/10
Read more:
Read More
|
97 |
|
43 |
lead article
Updated: 26 Sep 2011
http://www.leadya.co.il/ SQLi
050610
Read more:
Read More
|
97 |
|
44 |
Ads manager Annonce
Updated: 26 Sep 2011
http://joomla.clubnautiquemarine.fr/
Upload Vulnerability
05/06/10
Read more:
Read More
|
109 |
|
45 |
Info Line (MT_ILine)
Updated: 26 Sep 2011
http://extensions.joomla.org/extensions/news-display/news-tickers-a-scrollers/8425 reports of shell scripts in download file
120610
Read more:
Read More
|
108 |
|
46 |
recruitmentmanager
Updated: 26 Sep 2011
http://recruitment.focusdev.co.uk Upload Vulnerability
130610
Read more:
Read More
|
103 |
|
47 |
Alpha User Points
Updated: 26 Sep 2011
www.alphaplug.com LFI
180610
Read more:
Read More
|
175 |
|
48 |
Listbingo 1.3
Updated: 26 Sep 2011
Multiple Vulnerabilities
http://extensions.joomla.org/extensions/ads-a-affiliates/classified-ads/12062
180610
Read more:
Read More
|
104 |
|
49 |
JFaq 1.2
Updated: 26 Sep 2011
JFaq 1.2 Multiple Vulnerabilities
180610
Read more:
Read More
|
115 |
|
50 |
Gallery XML 1.1
Updated: 26 Sep 2011
Multiple Vulnerabilities
http://extensions.joomla.org/extensions/photos-a-images/photo-gallery/12504
180610
Read more:
Read More
|
88 |
|
51 |
Answers v2.3beta
Updated: 26 Sep 2011
Multiple Vulnerabilities http://extensions.joomla.org/extensions/communication/forum/12652
180610
Read more:
Read More
|
93 |
|
52 |
RSMonials
Updated: 26 Sep 2011
http://www.rswebsols.com/downloads/category/14-download-rsmonials-all?download=23%3Adownload-rsmonials-component XSS Exploit
190610
Believed to be 1.5.1 version
Read more:
Read More
|
105 |
|
53 |
MisterEstate
Updated: 26 Sep 2011
http://www.misterestate.com/ Blind SQL Injection Exploit
190610
Read more:
Read More
|
102 |
|
54 |
BF Survey Pro Free
Updated: 26 Sep 2011
BF Survey Pro Free SQL Injection Exploit
190610
Product marker as retired by the developer
Read more:
Read More
|
230 |
|
55 |
Turtushout 0.11
Updated: 26 Sep 2011
http://www.turtus.org.ua/files?func=fileinfo&id=13 SQL Injection (again)
190610
Read more:
Read More
|
94 |
|
56 |
Live Chat
Updated: 26 Sep 2011
http://www.joompolitan.com/livechat.html Multiple Remote Vulnerabilities
190610
Read more:
Read More
|
89 |
|
57 |
joomdocs
Updated: 26 Sep 2011
http://joomclan.com/index.php/JoomDocs/ xss vulnerability
190610
Read more:
Read More
|
103 |
|
58 |
Jreservation
Updated: 26 Sep 2011
http://jforjoomla.com/ SQLi Vulnerability
190610
Read more:
Read More
|
160 |
|
59 |
cinema
Updated: 26 Sep 2011
SQL injection
190610
Read more:
Read More
|
99 |
|
60 |
real estate
Updated: 26 Sep 2011
http://www.opensourcetechnologies.com/demos/real-estate.html RFI
210610
Read more:
Read More
|
103 |
|
61 |
date converter
Updated: 26 Sep 2011
http://sourceforge.net/projects/date-converter/ sqli
010710
Read more:
Read More
|
105 |
|
62 |
eventcal 1.6.4
Updated: 26 Sep 2011
http://joomlacode.org/gf/project/eventcal/frs/ SQL I last update 2006-12-31 on joomlacode
040710
Read more:
Read More
|
105 |
|
63 |
autartimonial
Updated: 26 Sep 2011
autartica.be Sqli Vulnerability
060710
Read more:
Read More
|
107 |
|
64 |
ArtForms
Updated: 26 Sep 2011
http://joomlacode.org/gf/project/jartforms/ ArtForms 2.1b7.2 RC2 Multiple Remote Vulnerabilities
090710
Old beta extension
Read more:
Read More
|
96 |
|
65 |
PaymentsPlus
Updated: 26 Sep 2011
http://paymentsplus.com.au/ 2.1.5 Blind SQL Injection Vulnerability
090710
current version 2.20, 2.1.5 not listed on dev site
Read more:
Read More
|
101 |
|
66 |
IXXO Cart
Updated: 26 Sep 2011
http://www.php-shop-system.com/ SQLi LFI XSS Vulnerability
Read more:
Read More
|
107 |
|
67 |
Minify4Joomla
Updated: 26 Sep 2011
http://waltercedric.com/ LFI and xss
090710
No longer available to download
Read more:
Read More
|
167 |
|
68 |
quickfaq
Updated: 26 Sep 2011
http://www.schlu.net sqli
090710
Read more:
Read More
|
102 |
|
69 |
staticxt
Updated: 26 Sep 2011
http://extensions.joomla.org/extensions/edition/custom-code-in-content/2184 no version number provided
Read more:
Read More
|
91 |
|
70 |
Health & Fitness Stats
Updated: 26 Sep 2011
http://joomla-extensions.instantiate.co.uk/jcomponents/healthstats Persistent XSS Vulnerability july 10,2010
Read more:
Read More
|
100 |
|
71 |
Rapid Recipe
Updated: 26 Sep 2011
http://www.rapid-source.com Persistent XSS Vulnerability last known fix version 1.7.2
july 10,2010
Read more:
Read More
|
111 |
|
72 |
Jomtube
Updated: 26 Sep 2011
http://www.jomtube.com/ SID
220710
Read more:
Read More
|
147 |
|
73 |
wmtpic
Updated: 26 Sep 2011
www.webmaster-tips.net various
010710
Read more:
Read More
|
99 |
|
74 |
Amblog
Updated: 26 Sep 2011
Amblog SQLi
120810
Read more:
Read More
|
98 |
|
75 |
Team's
Updated: 26 Sep 2011
Teams extension SQL Injection
120810
Read more:
Read More
|
93 |
|
76 |
zina
Updated: 26 Sep 2011
SQL Injection
020910
Read more:
Read More
|
108 |
|
77 |
Zoom Portfolio
|
96 |
|
78 |
PicSell
Updated: 26 Sep 2011
LFD, 777
020910
Read more:
Read More
|
109 |
|
79 |
jphone
Updated: 26 Sep 2011
jphone LFI
090910
Read more:
Read More
|
109 |
|
80 |
Clantools
Updated: 26 Sep 2011
http://www.joomla-clantools.de/downloads/doc_download/7-clantools-123.html clantool sqli
090910
Read more:
Read More
|
98 |
|
81 |
iJoomla Magazine 3.0.1
Updated: 26 Sep 2011
iJoomla Magazine 3.0.1 RFI
090910
Read more:
Read More
|
117 |
|
82 |
Freestyle FAQ 1.5.6
Updated: 26 Sep 2011
http://freestyle-joomla.com/fssdownloads/viewcategory/2 Freestyle FAQ 1.5.6 ?SQL Injection
Read more:
Read More
|
113 |
|
83 |
Flip wall
Updated: 26 Sep 2011
SQL injection pulseextensions.com
011110
developer http://demo.pulseextensions.com/flip-wall.html update notice link title
Read more:
Read More
|
145 |
|
84 |
sponsorwall
Updated: 26 Sep 2011
SQL injection pulseextensions.com
011110
developer resolution notice
Read more:
Read More
|
103 |
|
85 |
ProDesk v 1.5
|
110 |
|
86 |
ccboard
Updated: 26 Sep 2011
ccboard XSS and SQLi
131110
on my site at [1] Please find the respective update information
Read more:
Read More
|
98 |
|
87 |
alfurqan
Updated: 26 Sep 2011
alfurqan 1.5 sqli
151110
Read more:
Read More
|
97 |
|
88 |
Maian Media SILVER
Updated: 26 Sep 2011
Maian Media SQLi
151110
Developer states unproven in free edition, paid/SILVER version is being upgraded. dev article
Read more:
Read More
|
126 |
|
89 |
Jimtawl
Updated: 26 Sep 2011
Jimtawl LFI
251110
Read more:
Read More
|
112 |
|
90 |
People Component
Updated: 26 Sep 2011
People component http://www.ptt-solution.com/vmchk/people-component.html sqli
150111
Read more:
Read More
|
203 |
|
91 |
allcinevid
Updated: 26 Sep 2011
SQLI http://extensions.joomla.org/extensions/multimedia/multimedia-players/video-players-a-gallery/15367
220111
Developers resolution notice
Read more:
Read More
|
112 |
|
92 |
B2 Portfolio
Updated: 26 Sep 2011
B2 portfolio 1.0 SQLi pulseextensions.com
250111
Read more:
Read More
|
106 |
|
93 |
com properties 7134
Updated: 26 Sep 2011
http://com-property.com/ malicious files in script
Dev update statement
Read more:
Read More
|
107 |
|
94 |
Frontend-User-Access 3.4.1
Updated: 26 Sep 2011
Frontend-User-Access 3.4.1 from http://www.pages-and-items.com LFI
030211
update to Frontend-User-Access 3.4.2
Read more:
Read More
|
129 |
|
95 |
xmap 1.2.10
Updated: 26 Sep 2011
Malicious payload in zip
230211
developer resolution notice Clean version available from joomlacode
Read more:
Read More
|
112 |
|
96 |
smartformer
Updated: 26 Sep 2011
RFI
230211 (repeat of 041110)
v2.4.1 security fix for Joomla 1.5.x
Read more:
Read More
|
98 |
|
97 |
xcloner
Updated: 26 Sep 2011
Unspecified
260211
dev announcement of security release
Read more:
Read More
|
110 |
|
98 |
jLabs Google Analytics Counter
Updated: 26 Sep 2011
jLabs Google Analytics Counter SID
Read more:
Read More
|
97 |
|
99 |
flexicontent
Updated: 26 Sep 2011
forced 777, malicious files
250311
devs resolve statement, Changelog
Read more:
Read More
|
111 |
|
100 |
JOMSOCIAL 2.0.x 2.1.x
Updated: 26 Sep 2011
SID, open folders
120311
Read more:
Read More
|
94 |
|
101 |
semantic
Updated: 26 Sep 2011
com semantic http://www.scms.es/joomla creates hidden admin users
150311
Read more:
Read More
|
93 |
|
102 |
booklibrary
Updated: 26 Sep 2011
SQLi ordasoft booklibrary
180311
developer upgrade instructions
Read more:
Read More
|
92 |
|
103 |
Facebook Graph Connect
Updated: 26 Sep 2011
SID. call home device with user credentials
120411
dev update notice
Read more:
Read More
|
94 |
|
104 |
Akeeba
Updated: 26 Sep 2011
akkeba backup and joomlapack
170411
dev update to 3.2.7
Read more:
Read More
|
100 |
|
105 |
Newsletter Subscriber
Updated: 26 Sep 2011
XSS
120511
Deveopler update
Read more:
Read More
|
92 |
|
106 |
docman
Updated: 26 Sep 2011
com-docman Input Validation Error
160511
devs resolution statement, report for old version
Read more:
Read More
|
104 |
|
107 |
com_google
Updated: 26 Sep 2011
LFI com_google
080511
devs update to 1.5.1
Read more:
Read More
|
108 |
|
108 |
Global Flash Gallery
Updated: 26 Sep 2011
flash-gallery.com xss
130511
dev release 0.5.0 statement
Read more:
Read More
|
144 |
|
109 |
Ask A Question AddOn v1.1
|
93 |
|
110 |
KeyCaptcha
|
381 |
|
111 |
FCKeditor
Updated: 26 Sep 2011
File Upload Vulnerability
230511
Read more:
Read More
|
116 |
|
112 |
JE Story submit
Updated: 26 Sep 2011
LFI/RFI
developer states Version 1.8
Read more:
Read More
|
113 |
|
113 |
sh404SEF
Updated: 26 Sep 2011
low-level XSS security issue
300511
Dev upgrade statement to 2.2.6
Read more:
Read More
|
93 |
|
114 |
JMS fileseller
Updated: 26 Sep 2011
LFI
0611
developer upgrade announcement to v1.1
Read more:
Read More
|
114 |
|
115 |
Joomnik Gallery
Updated: 26 Sep 2011
SQLi
developer update to 0.9.1
Read more:
Read More
|
109 |
|
116 |
Scriptegrator Plugin 1.5.5
Updated: 26 Sep 2011
LFI
140611
Update - Core Design Scriptegrator plugin 2.0.9 & 1.5.6
Read more:
Read More
|
132 |
|
117 |
Cool Debate
Updated: 26 Sep 2011
Cool Debate 1.03 LFI
Read more:
Read More
|
104 |
|
118 |
Calc Builder
Updated: 26 Sep 2011
sqli + ID
180611
dev security release 0.0.2
Read more:
Read More
|
148 |
|
119 |
mdigg
Updated: 26 Sep 2011
SQL I (not listed in JED)
020711
Read more:
Read More
|
118 |
|
120 |
myApi
Updated: 26 Sep 2011
ID Contains "Call-Home" function. Sends private user information to developer.
020711
Developer states Use version 1.3.4.1
Read more:
Read More
|
164 |
|
121 |
Atomic Gallery
Updated: 26 Sep 2011
Creates 777 folders Atomic gallery
110711
Read more:
Read More
|
189 |
|
122 |
xmap
Updated: 26 Sep 2011
sqli 1.2.11
120711
upgrade to 1.2.12
Read more:
Read More
|
117 |
|
123 |
fabrik
Updated: 26 Sep 2011
sqli
120711
Developers Update statement 2.1
Read more:
Read More
|
100 |
|
124 |
Sobi
Updated: 26 Sep 2011
SQLI -
130711
developer fix and update statement
Read more:
Read More
|
98 |
|
125 |
AVreloaded
Updated: 26 Sep 2011
SQLi - version 1.2.6
150711
1.2.7 released developer release statement 160711
Read more:
Read More
|
118 |
|
126 |
Flash Magazine Deluxe Joomla
Updated: 26 Sep 2011
ID multiple vulnerabilities
170711
developer release 2.1.4
Read more:
Read More
|
227 |
|
127 |
Jforce
Updated: 26 Sep 2011
DT -
170711
developer states The new version number v1.5r1362 resolves the problem
Read more:
Read More
|
97 |
|
128 |
alpharegistration
Updated: 26 Sep 2011
http://www.alphaplug.com/ Please contact the developer for any questions on this extension
170711 220711
Read more:
Read More
|
96 |
|
129 |
gTranslate
Updated: 26 Sep 2011
ID -
220711
developer security release 1.5 x.25 and 1.6 x.26.
Read more:
Read More
|
144 |
|
130 |
acajoom
Updated: 26 Sep 2011
xss (admin permission required)
220711
updated to 5.20
Read more:
Read More
|
108 |
|
131 |
appointment booking pro
Updated: 26 Sep 2011
LFI 22071
developer update security announcement Current 2.0.1 and 1.4.x versions, are not vulnerable,
Read more:
Read More
|
146 |
|
132 |
JE Story
Updated: 26 Sep 2011
LFI
230711
devloper security update notice to ver 1.9
Read more:
Read More
|
106 |
|
133 |
Simple Page
|
103 |
|
134 |
obSuggest
|
99 |
|
135 |
V-portfolio
Updated: 26 Sep 2011
DT - open folders
110811
developer resolution statement
Read more:
Read More
|
86 |
|
136 |
RAXO All-mode PRO
Updated: 26 Sep 2011
Timthumb RFI
110811
developer upgrade 1.5.0 statement
Read more:
Read More
|
249 |
|
137 |
joomtouch
Updated: 26 Sep 2011
LFI/RFI
180811
developers resolution notice 1.0.3
Read more:
Read More
|
109 |
|
138 |
Almond Classifieds
Updated: 26 Sep 2011
777 Folder settings (all folders it uses are set to 777 including previously 755 locked folders)
260811
developer resolution notice
Read more:
Read More
|
134 |
|
139 |
Google Website Optimizer
Updated: 26 Sep 2011
Numerous vulnerabilities. Website Optimizer, Pearl Group
290811
Read more:
Read More
|
91 |
|
140 |
Joomla content editor
Updated: 26 Sep 2011
JCE lfi/rfi vulnerability
JCE 2.0.11 and JCE 1.5.7.14 have been released
Read more:
Read More
|
102 |
|
141 |
Jumi
Updated: 26 Sep 2011
LFI
300811
Developer states proper use of joomla administration/extension documentation reading
Read more:
Read More
|
107 |
|
142 |
Simple File Upload
Updated: 26 Sep 2011
LFI
300811
developer advice page
Read more:
Read More
|
98 |