Possible extension vulnerability - Joomla! Forum - community, help and support


today have received higher average number of phising emails utilising hacked joomla sites target pages. sites on different hosts, , can tell 2 things have in common running joomla, , using ag google analytics plugin:

http://extensions.joomla.org/extensions ... ased/12097

i not going post links domains themselves, since delivering viruses in cases, can provide them via pm if wants investigate deeper. end urls this:

domain.com/components/com_ag_google_analytics2/purchaseinfo.html
domain.com/components/com_ag_google_analytics2/amazonorderdetails.html

doing search on url snippet of extension seem show particular extension has been target directory hacked sites while:

http://www.google.com/search?num=100&hl ... 2%22+virus

i know doesn't prove extension blame, figured maybe more familiar joomla take closer , see if there going on there.

-michael

please report vulnerable extensions, along poc vel team @ vel email address





Comments

Popular posts from this blog

How to change text Component easybook reloaded *newbee* - Joomla! Forum - community, help and support

After Effect warning: A problem occurred when processing OpenGL commands

Preconditions Failed. - Joomla! Forum - community, help and support