Security Release: Joomla! 1.5.9 Is Ready For Free Download
The PHP / MySQL based open source content management system, Joomla! was updated to version 1.5.9 [Vatani], after the recent release on November 10, 2008 of Joomla! 1.5.8 coded name Wohnaiki. This security release solves two security issues of high and respectively low severity: directory traversal and SSL session token disclosure which affected all of the Joomla! 1.5.x installations, including version 1.5.8.
The first exploit type, directory traversal, could allow to an attacker to display the directory trees existing on the web server. The second exploit deals with the possibility of getting the session token by an attacker in case of non-SSL requests performed for websites running as SSL (Transport Layer Security, formerly Secure Sockets Layer) only, while the entire data transfer is still safe.
The minimum requirements for
In Joomla! 1.5.9 version, several bugs were solved in case of components, modules, plugins, templates, language, administrator and system, such as the invalid XHTML 1.0 Transitional issues for the Contact Form, Media Manager JavaScript errors, Tool Tip corrections, OpenID Transition and more.
The
Related Articles



























































February 6th, 2009 at 9:01 am
[...] Starting with version 1.5.8, as a security measure a default filtering rule for custom code content was implemented to prevent possible XSS attacks. As a consequence, if you are using certain HTML tags or JavaScript code into the published articles, the resulting browser output could not be always the expected result because of the default Blacklist filter. (related article: Security Release: Joomla! 1.5.9 Is Ready For Free Download) [...]