A critical update fixes a “trivial exploit” that enables users to inject malicious content onto Joomla sites
Joomla released a critical update at the end of July that fixes a “trivial exploit” that enables users to inject malicious content onto Joomla sites, according to a report by Krebs on Security on Monday.
Web security firm Versafe discovered the exploit that enabled users to hijack Joomla sites for use in malware payload and phishing attacks. It also found a zero-day attack in the wild, which enabled attackers to gain control over the compromised systems.
Versafe released a report on Monday, summarizing its discovery of the vulnerability as well as providing a step-by-step description of how the attacks played out.
“What brought this vulnerability to our attention was that we noticed a sharp increase in the number of phishing and malware attacks being hosted from legitimate Joomla-based sites,” Eyal Gruner, CEO of Versafe said in a statement. ”The series of attacks exploiting this vulnerability were particularly aggressive and widespread — involved in over 50 percent of the attacks targeting our clients and others in EMEA — and ultimately successful in infecting a great many unsuspecting visitors to genuine websites. Versafe is committed to helping Joomla protect its large community of platform users and end-users, through having shared key findings specific to this exploit.”
The patch released by Joomla on July 31 applies to Joomla 2.5.13 and earlier 2.5.x versions, as well as Joomla 3.1.4 and earlier 3.x versions. Applied to Joomla versions 2.5.14 and 3.1.5, the patch remedies a bug that allows unprivileged users to upload arbitrary .PHP files by adding a period to the end of the filenames, Krebs says.
Versafe tells Krebs that of the thousands of attacks on its clients in the first half of 2013, 57 percent were hosted on Joomla-based sites.
Earlier in the year, web hosts including Go Daddy were rocked by Joomla attacks.
