Release of version 1.4.3
Written by Administrator   
Friday, 05 December 2008
On 4 December 2008, a security hole was detected in version 1.4.2. It was posted on the forums of the environment. It is an SQL injection flaw. In other words, the password cracker voluntarily incorrect settings in the form of an SQL query in the browser's address bar. This allows it to run the code it wants.

This loophole that I tested to understand in 2 allows actions to change the password of the administrator and take control of Joomla.

This made me drop all my current projects to devote myself to a quick fix.

It is the release of version 1.4.3.

You must make an update.

 

Go check the forum for more detail or this site to download the latest version.

I will in future not to let this type of flaw. This will not prevent hackers lack of imagination.

Sincerely yours.

Jerome Lamiot
Last Updated ( Friday, 05 December 2008 )