An urgent, high-level security threat has been identified in Joomla 1.5. This exploit allows someone to gain full access to your joomla web site with little or no knowledge. The official announcement can be found below
The Joomla! community is pleased to announce the immediate availability of Joomla! 1.5.6 [Vusani]. This is a quick turnaround security release to address a high level security issue and it is recommended all users upgrade immediately.
For more information about this exploit, visit the
Instructions
* New installation
* Upgrade from an existing Joomla! 1.5 version
* Migration from Joomla! 1.0.x
* See below for manual installation instructionsDownload the Joomla 1.5.6 full package now
Release Notes
* SECURITY [HIGH] Fixed security hole in reset logic to check for proper token length.
All users of Joomla 1.5 should IMMEDIATELY upgrade to 1.5.6 or apply a simple patch.
Related Articles
Tags:

August 14, 2008



1 person has left a comment
[...] Go to the author’s original blog: Joomla 1.5.6 Security Release [...]