Lightquick Web Design - High Quality, Low Cost

LightQuick Web Design - Latest News

We have just won a new contract to supply a new site design for ProSonix.co.uk. The new site will feature a very modern and technical Joomla 1.5 template which will match the technological nature of ProSonix at prosonix.co.uk. The site will be easy to modify to ensure on-going costs are minimised. We look forward to working with Graham Ruecroft on the new site.
You are here:
  • Decrease font size
  • Default font size
  • Increase font size
Simple Page Options (SPO) Vulnerability Fixed PDF Print
Written by Dean Beedell   
Monday, 31 October 2011

pen-and-paper.pngI have been advised by the hosting company of a vulnerability in an extension we had been using on one of our sites which allows information to be obtained which could be used in a future attack on the site. The extension is the Simple Page Options Module for Joomla 1.5 which allows you to add a variety of extra functions via a very simple front end interface, what does this module do? It does the following things:

It enhances Site Title.
Replaces the Default Joomla! Generator.
Forces Compatibility View for IE8 Users.
Adds a contact and referral form.
Adds twelve social bookmarking icons.
Adds a note to users of the obsolete browser IE6.
Allows you turn off right clicking.

This is useful functionality that I don't want to lose especially when it is wrapped in such a pretty and compact package. The problem is that hackers have found that the email forms do not fully sanitise their input and on a system that is not protected by su_php it could allow some commands to be run to divulge information about the server. It is possible that it could also allow injected code to be run.

I have been in touch with the developer and I have fixed the vulnerability with his help. He has now fixed the vulnerability world wide as 10,000+ sites also use it. The vulnerability was discovered by us when someone tried to exploit the vulnerability to insert some nasty code on one of our systems. They failed of course as the system is far too secure for that to happen. Just letting you know!

The JED had already had someone flag the problem and had marked the module as being insecure...

With the new version of simple page options (SPO 1.5.17) you can now safely upgrade the module on your Joomla 1.5 site. It is available here.

Comments (0)Add comments

Write comment

busy
Last Updated ( Wednesday, 16 November 2011 )
 
< Prev   Next >

Steampunk Yahoo Widget

How about something special for the weekend sir?

Steampunk Yahoo clock/calendar widget download

Lightquick have a nice little Yahoo widget for you to download. Steampunk Stamp WidgetClick on the image above.

Do you need a stamp with that madam?

Yahoo Widget Downloads

Download the Joomla Multi-Sit... here

Joomla Multi-Sit...

Downloads: 32
Avg. Rating:
StarStarStarStarStar(5)

Download the Steampunk Orrery... here

Steampunk Orrery...

Downloads: 1160
Avg. Rating:
StarStarStarStarStar(2)

Download the Steampunk Weathe... here

Steampunk Weathe...

Downloads: 48182
Avg. Rating:
StarStarStarStarStar(38)

Download the Cyberpunk Yahoo ... here

Cyberpunk Yahoo ...

Downloads: 3301
Avg. Rating:
StarStarStarStarStar(15)

Download the Steampunk CPU / ... here

Steampunk CPU / ...

Downloads: 7906
Avg. Rating:
StarStarStarStarStar(26)

Virtuemart Assistance

If you require assistance regarding VM or Joomla then please contact lightquick here...

Contact me here

Site Total Page Views

mod_vvisit_countermod_vvisit_countermod_vvisit_countermod_vvisit_countermod_vvisit_countermod_vvisit_countermod_vvisit_counter
mod_vvisit_counterToday506
mod_vvisit_counterYesterday756
mod_vvisit_counterThis week506
mod_vvisit_counterThis month19158
mod_vvisit_counterAll Visitors484109

Site Last Modified

Site Last Modified:Monday 21 May 2012, 11:30

Secure Login Form

Log In / Sign Up

Find us on the FreeIndex directory under Web Designers