cPanel to End Support for PHP 4 cPanel announces that EasyApache will no longer support PHP 4 beginning May, 2012. PHP 4 has not been actively developed, or supported by the PHP developers, for several years. Many CVEs reported against…
Archive for CMS
The Joomla! project is proud to announce that our application has been accepted to be a mentoring organization for the 2012 Google Summer of Code™ program (GSoC). The GSoC helps support university level students who get the opportunity to work with mentors on a variety of coding projects that will all be contributed back to the student’s mentoring organization.
This year’s Joomla! GSoC application was led by Chad Windnagle (Primary Administrator), Andrea Tarr (Secondary Administrator), and Elin Waring. Key supporters and contributors to the application process include Michael Babker, Robert Deutz, Andrew Eddie, Louis Landry, Jacques Rentzke, and Matt Thomas.
After learning of Joomla!’s acceptance into GSoC, Chad had this to say:
I’m really proud of the community effort that got put forth to be successfully accepted into GSoC this year. When I first found out that we were working on the application, and we had a week to go, I was really worried we wouldn’t make it in time. A lot of really great people have put their heads together to make this opportunity possible, and the project can’t thank those folks enough.
We have gotten accepted into the Google program, but now the fun is just beginning. This is a major win, and now we have a whole summer to mentor students and run this program successfully. I hope when we reach the end of the summer we can all feel just as successful about Joomla!’s participation in GSoC as we do right now.
Those interested in serving as a mentor for a Joomla! 2012 GSoC student project may register here:
http://www.google-melange.com/gsoc/org/google/gsoc2012/joomla
Here is the Frequently Asked Questions page for the 2012 GSoC:
http://www.google-melange.com/gsoc/document/show/gsoc_program/google/gsoc2012/faqs
- Project: Joomla!
- SubProject: All
- Severity: High
- Versions: 2.5.2, 2.5.1, 2.5.0, and all 1.7.x and 1.6.x releases
- Exploit type: Password Change
- Reported Date: 2012-March-8
- Fixed Date: 2012-March-15
Description
Insufficient randomness leads to password reset vulnerability.
Affected Installs
Joomla! versions 2.5.2, 2.5.1, 2.5.0, and all 1.7.x and 1.6.x versions
Solution
Upgrade to version 2.5.3
Reported by George Argyros and Aggelos Kiayias
Contact
The JSST at the Joomla! Security Center.
At cPanel Conference 2011, cPanel announced the upcoming launch of Attracta SEO tool features within cPanel & WHM. cPanel and Attracta have launched a special site ( go.cpanel.net/attracta/ ) dedicated to partners wishing to gain full access to the upcoming…
- Project: Joomla!
- SubProject: All
- Severity: High
- Versions: 2.5.2, 2.5.1, 2.5.0, and all 1.7.x and 1.6.x releases
- Exploit type: Privilege Escalation
- Reported Date: 2012-March-12
- Fixed Date: 2012-March-15
Description
Programming error allows privilege escalation in some cases.
Affected Installs
Joomla! versions 2.5.2, 2.5.1, 2.5.0, and all 1.7.x and 1.6.x versions
Solution
Upgrade to version 2.5.3
Reported by Jeff Channel
Contact
The JSST at the Joomla! Security Center.
Joomla 2.5.3 Released
The Joomla Project is pleased to announce the immediate availability of Joomla 2.5.3. This is a security release. The Production Leadership Team’s goal is to continue to provide regular, frequent updates to the Joomla community. Learn more about Joomla! developement at the Developer Site.
The update process is very simple, and complete instructions are available here. Note that there are now easier and better ways of updating than FTPing the files.
Download
New Installations: Click here to download Joomla 2.5.3 (Full package) »
Update Package: Click here to download Joomla 2.5.3 (Update package) »
Note: Please read the update instructions before updating.
Instructions
Want to test drive Joomla? Try the online demo or the Joomla JumpBox. Documentation is available for beginners.
Please note that you should always backup your site before upgrading.
Release Notes
Check the Joomla 2.5.3 Post-Release FAQs to see if there are important items and helpful hints discovered after the release.
Statistics for the 2.5.3 release
- Joomla 2.5.3 contains:
- 2 security issues fixed
Security Issues Fixed
- High Priority – Core – Privilege Escalation. More information »
- High Priority – Core – Password Change. More information »
Joomla! Bug Squad
Thanks to the Joomla Bug Squad for their dedicated efforts investigating reports, fixing problems, and applying patches to Joomla. If you find a bug in Joomla, please report it on the Joomla! CMS Issue Tracker.
Active members of the Joomla Bug Squad during this last release cycle include: A Firoozmandan, Akarawuth Tamrareang, Alain Rivest, Andrea Tarr, Andrew Eddie, Bill Richardson, Brian Teeman, Chris Davenport, Christophe Demko, Denise McLaurin, Dennis Hermacki, Elin Waring, Emerson Rocha Luiz, Francisco Marzoa, Ian MacLennan, Jacob Waisner, Jacques Rentzke, James Brice, Janich Rasmussen, Jean-Marie Simonet, Jennifer Marriott, Jeremy Wilken, Kevin Griffiths, Loyd Headrick, Mark Dexter, Matt Thomas, Michael Babker, Mutuga Kigumi, Neil McNulty, Nikolai Plath, Ofer Cohen, Prasit Gebsaap, Rachmat Wakjaer, Rob Clayburn, Roland Dalmulder, Rouven Weßling, Rune Sjøen, Samuel Moffatt, Shaun Maunder, Sudhi Seshachala, Tim Plummer, Tom Fuller, Troy Hall, Viet Hoang Vu.
Bug Squad Leadership: Mark Dexter Coordinator; Elin Waring and Marijke Stuivenberg, Team Leaders.
Joomla! Security Strike Team
A big thanks to the Joomla! Security Strike Team for their ongoing work to keep Joomla secure. Members include: Airton Torres, Alan Langford, Bill Richardson, Elin Waring, Jason Kendall, Marijke Stuivenberg, Mark Dexter, Michael Babker, Rouven Weßling, Samuel Moffatt.
On Monday, March 12, 2012, cPanel will travel to Austin, Texas and join a number of Partners, industry friends, and hosting guru’s at this year’s South by Southwest 2012 (SxSW) conference. cPanel & WHM powers some of the largest and most…
The South by Southwest Interactive Festival (SXSW) holds a special place in the history and heart of WordPress. Though the conference has changed in the years since I first met Matt in the hallway in 2003 — before WordPress even had a name — it’s still arguably one of the most influential events in our […]
Joomla 2.5.2 Released
The Joomla Project is pleased to announce the immediate availability of Joomla 2.5.2. This is a security release. The Production Leadership Team’s goal is to continue to provide regular, frequent updates to the Joomla community. Learn more about Joomla! developement at the Developer Site.
The update process is very simple, and complete instructions are available here. Note that there are now easier and better ways of updating than FTPing the files.
Download
New Installations: Click here to download Joomla 2.5.2 (Full package) »
Update Package: Click here to download Joomla 2.5.2 (Update package) »
Note: Please read the update instructions before updating.
Instructions
Want to test drive Joomla? Try the online demo or the Joomla JumpBox. Documentation is available for beginners.
Please note that you should always backup your site before upgrading.
Release Notes
Check the Joomla 2.5.2 Post-Release FAQs to see if there are important items and helpful hints discovered after the release.
Statistics for the 2.5.2 release
- Joomla 2.5.2 contains:
- 2 security issues fixed
Security Issues Fixed
- High Priority – Core – SQL Injection. More information »
- Medium Priority – Core – XSS Vulnerability. More information »
Joomla! Bug Squad
Thanks to the Joomla Bug Squad for their dedicated efforts investigating reports, fixing problems, and applying patches to Joomla. If you find a bug in Joomla, please report it on the Joomla! CMS Issue Tracker.
Active members of the Joomla Bug Squad during this last release cycle include: A Firoozmandan, Akarawuth Tamrareang, Alain Rivest, Andrea Tarr, Andrew Eddie, Ashwin Date, Bill Richardson, Brian Teeman, Chris Davenport, Christophe Demko, Denise McLaurin, Dennis Hermacki, Elin Waring, Emerson Rocha Luiz, Francisco Marzoa, Ian MacLennan, Jacob Waisner, Jacques Rentzke, James Brice, Janich Rasmussen, Jean-Marie Simonet, Jennifer Marriott, Jeremy Wilken, Kevin Griffiths, Loyd Headrick, Mark Dexter, Matt Thomas, Michael Babker, Mutuga Kigumi, Neil McNulty, Nikolai Plath, Ofer Cohen, Prasit Gebsaap, Rachmat Wakjaer, Rob Clayburn, Roland Dalmulder, Rouven Weßling, Rune Sjøen, Samuel Moffatt, Shaun Maunder, Sudhi Seshachala, Tim Plummer, Tom Fuller, Troy Hall, Viet Hoang Vu.
Bug Squad Leadership: Mark Dexter Coordinator; Elin Waring and Marijke Stuivenberg, Team Leaders.
Joomla! Security Strike Team
A big thanks to the Joomla! Security Strike Team for their ongoing work to keep Joomla secure. Members include: Airton Torres, Alan Langford, Bill Richardson, Elin Waring, Jason Kendall, Marijke Stuivenberg, Mark Dexter, Omar Ramos, Rouven Weßling, Samuel Moffatt.
The Joomla! project is submitting an application to Google to participate in this year’s Google Summer of Code™ (GSoC) program. To be an applicant we need to have some help from our community. We are looking for talented individuals who are able to work well with students to be mentors, as well as for the community to generate ideas for the GSoC students to build.
For Mentors:
Participating in GSoC is a great opportunity for the Joomla community to collect some energy from new blood in the Joomla project, pairing talented individuals eager to learn with skilled mentors, community members who can guide and assist navigating the seas of Open Source Development in the Joomla Project.
If you would like to mentor projects this year please visit the Mentor page where we will be posting up mentor information. This will be a short list of requirements from you, as well as an application form that you will need to fill out. We welcome anyone to submit to be a mentor.
For Ideas
There are two major categories in the Joomla! Project where students will be able to contribute to this year. Unlike past Programs where there was only the CMS to work on, this year students can choose between working on the Joomla CMS itself or the Joomla Platform Project that the CMS is based on.
If you’re a developer who has some time this summer to help out, we invite and encourage you to add an idea to the Joomla GSOC Idea Page for 2012, as well as add to the discussions in the Joomla GSOC Google Group.
- Project: Joomla!
- SubProject: All
- Severity: High
- Versions: 2.5.1, 2.5.0 and 1.7.0 – 1.7.5
- Exploit type: SQL Injection
- Reported Date: 2012-February-29
- Fixed Date: 2012-March-05
Description
Inadequate escaping leads to SQL injection vulnerability.
Affected Installs
Joomla! version 2.5.1, 2.5.0, 1.7.4, and all earlier 1.7.x versions
Solution
Upgrade to version 2.5.2
Reported by Ching Shiong Sow, Stratsec
Contact
The JSST at the Joomla! Security Center.
- Project: Joomla!
- SubProject: All
- Severity: Moderate
- Versions: 2.5.1 and 2.5.0
- Exploit type: XSS Vulnerability
- Reported Date: 2012-February-29
- Fixed Date: 2012-March-05
Description
Inadequate filtering leads to XSS vulnerability.
Affected Installs
Joomla! version 2.5.1 and 2.5.0.
Solution
Upgrade to version 2.5.2
Reported by Phil Purviance
Contact
The JSST at the Joomla! Security Center.
For continued compatibility with the latest versions of cPanel & WHM, please update your server to CentOS 6 or RHEL 6.CentOS and Red Hat discontinued support for version 4 of their respective operating systems on February 29, 2012. cPanel & WHM version 11.32 will…
The March issue of the Joomla Community Magazine is here!
Our stories this month:
EDITOR’S INTRODUCTION
If You Want To Build A Lighthouse…, by Paul Orwig
FEATURE STORIES
Interview with Steve Burge of OSTraining, by Alice Grevet
Meet Paul Orwig: An Interview with the New OSM President, by Gabe Wahhab
Best Ukrainian sites made on Joomla CMS, by Denys Nosov
PROJECT NEWS
Leadership Highlights from February 2012, by Alice Grevet
SITEBUILDERS
Joomla and Smartphones, by Hagen Graf
DESIGNERS
No Programming? No Worries!, by Graeme King
ADMINISTRATORS
Joomla ACL: Improving usability by customizing the login screen for different access levels, by Jen Kramer
DEVELOPERS
Managing Your Modules Has Never Been So Easy, by Ofer Cohen
HELP WANTED
The Joomla! Project Wants You – March 2012, by Paul Orwig
Help Wanted: International Joomla! Shop Team Members, by Dianne Henning
BUSINESS MATTERS
Make More Money By Properly Setting Your Hourly Rate, by Gabe Wahhab
Releasing A Commercial Extension? Top 5 Things Every Developer Must Know, by Gabe Wahhab
Why Your Clients Need a Mobile Joomla Site and How to Sell it To Them, by Luke Summerfield
EVENTS
2012 J!OSCAR Awards Announced – Nominations close April 27, by Victor Drover
JoomlaDay events in March 2012, by Jacques Rentzke
Joomla Groups Enhance Your Exposure to the Community Worldwide, by Tuan Bui
THE JOOMLA! HAIKUS
Post your haikus for March, by Paul Orwig
In our next issue
We want to publish your Joomla! story in the next JCM issue! So take a look at our Author Resources content to get a better idea of what we are looking for, and then register to become a JCM author and submit your Joomla! story!
cPanel, Inc., announced that its subsidiary, Hostbed, L.L.C., has acquired Siteocity.com, a small website hosting solutions provider. The purchase gives cPanel a direct platform for real-world testing of its products. Siteocity.com will continue to operate under its current name. cPanel…
Houston, TX — cPanel & WHM version 11.32, which released today to the edge tier, offers numerous updates, including enhancements to mail functionality and login screens. It also officially supports DKIM and includes the Logaholic web analytics application. Enhanced Mail…
Improvements were made to the Sever Administrator Interface, Website Owner Interface and to the product as a whole. Some Improvements to Sever Administrator Interface (SAI) include: Resellers can create IIS shared application pools with the new Application Pool Manager…
- Project: Joomla!
- SubProject: All
- Severity: Low
- Versions: 2.5.0 and 1.7.0 – 1.7.4
- Exploit type: Information Disclosure
- Reported Date: 2012-January-29
- Fixed Date: 2012-February-02
Description
Inadequate validation leads to path disclosure in administrator.
Affected Installs
Joomla! version 2.5.0, 1.7.4, and all earlier 1.7.x versions
Solution
Upgrade to version 2.5.1 or 1.7.5 or higher
Reported by Jakub Galczyk
Contact
The JSST at the Joomla! Security Center.
- Project: Joomla!
- SubProject: All
- Severity: Low
- Versions: 2.5.0 and 1.7.0 – 1.7.4
- Exploit type: Information Disclosure
- Reported Date: 2012-January-29
- Fixed Date: 2012-February-02
Description
Inadequate validation leads to information disclosure in administrator.
Affected Installs
Joomla! version 2.5.0, 1.7.4, and all earlier 1.7.x versions
Solution
Upgrade to version 1.7.5 or 2.5.1 or higher
Reported by Jakub Galczyk
Contact
The JSST at the Joomla! Security Center.
- Project: Joomla!
- SubProject: All
- Severity: Moderate
- Versions: 1.7.4 and all earlier 1.7.x versions
- Exploit type: Information Disclosure
- Reported Date: 2012-January-06
- Fixed Date: 2012-February-02
Description
On some servers the error log could be read by unauthorised users.
Affected Installs
Joomla! version 1.7.4 and all earlier 1.7.x versions
Solution
Upgrade to version 2.5.1 or 1.7.5 or higher
Reported by Alain Rivest
Contact
The JSST at the Joomla! Security Center.
Year of the Meetup
We hereby declare 2012 as the Year of the WordPress Meetup. You’ll want to get in on this action. So what is a WordPress Meetup? Basically, it’s people in a community getting together — meeting up — who share an interest in WordPress, whether they be bloggers, business users, developers, consultants, or any other category of person able to say, “I use WordPress in some way and I like it, and I want to meet other people who can say the same.
Install WordPress
# Download and unzip wordpress cd /home/$USER/public_html wget http://wordpress.org/latest.zip unzip latest.zip rm latest.zip # remove superfluous directory mv wordpress/* ./ rmdir wordpress/ # Make wordpress writeable by the webserver/or USER mkdir wp-content/uploads wp-content/cache chown apache:apache wp-content/uploads wp-content/cache chown -R $USER. […] ↓ Read the rest of this entry…
- Project: Joomla!
- SubProject: All
- Severity: Low
- Versions: 1.7.3 and all earlier 1.7 and 1.6 versions
- Exploit type: Information Disclosure
- Reported Date: 2012-January-07
- Fixed Date: 2012-January-24
Description
Inadequate filtering leads to information disclosure.
Affected Installs
Joomla! version 1.7.3 and all earlier versions
Solution
Upgrade to version 1.7.4 or 2.5.0 or higher
Reported by Erwan Peton – Intrinsec
Contact
The JSST at the Joomla! Security Center.
- Project: Joomla!
- SubProject: All
- Severity: Moderate
- Versions: 1.7.3 and all earlier 1.7 and 1.6 versions
- Exploit type: XSS Vulnerability
- Reported Date: 2011-November-16
- Fixed Date: 2012-January-24
Description
Inadequate filtering leads to XSS vulnerability.
Affected Installs
Joomla! version 1.7.3 and all earlier versions
Solution
Upgrade to version 1.7.4 or 2.5.0 or higher
Reported by Ankita Kapadia
Contact
The JSST at the Joomla! Security Center.
- Project: Joomla!
- SubProject: All
- Severity: Low
- Versions: 1.7.3 and all earlier 1.7 and 1.6 versions
- Exploit type: Information Disclosure
- Reported Date: 2011-December-19
- Fixed Date: 2012-January-24
Description
Inadequate filtering leads to information disclosure.
Affected Installs
Joomla! version 1.7.3 and all earlier versions
Solution
Upgrade to version 1.7.4 or 2.5.0 or higher
Reported by Jean-Marie Simonet
Contact
The JSST at the Joomla! Security Center.
- Project: Joomla!
- SubProject: All
- Severity: Moderate
- Versions: 1.7.3 and all earlier versions
- Exploit type: XSS Vulnerability
- Reported Date: 2012-January-22
- Fixed Date: 2012-January-24
Description
Inadequate filtering leads to XSS vulnerability.
Affected Installs
Joomla! version 1.7.3 and all earlier 1.7 and 1.6 versions
Solution
Upgrade to version 1.7.4 or 2.5.0 or higher
Reported by David Jardin
Contact
The JSST at the Joomla! Security Center.
The newest cPanel & WHM release, 11.30.5.6, improves Google Chrome support. This update for cPanel & WHM resolves an issue with handling form submissions by newer versions of Google Chrome. The error affected file uploads in the cPanel File Manager…
WordPress.org is officially joining the protest against Senate Bill 968: the Protect IP Act that is coming before the U.S. Senate next week. As I wrote in my post a week ago, if this bill is passed it will jeopardize internet freedom and shift the power of the independent web into the hands of corporations. […]
Help Stop SOPA/PIPA
You are an agent of change. Has anyone ever told you that? Well, I just did, and I meant it. Normally we stay away from from politics here at the official WordPress project — having users from all over the globe that span the political spectrum is evidence that we are doing our job and […]
Dear Hosting Providers, We believe the Stop Online Piracy Act (SOPA) and the Protect IP Act (PIPA) bills recently introduced by the U.S. Congress pose severe threats to the hosting industry as a whole and we ask that you take…