Multiple Vulnerabilities in Joomla! 1.6 and 1.6.1
Joomla!® is a content management system with more than 200,000 users and contributors.
Affected Application: Joomla! 1.6 and 1.6.1.
Issue: On 07/27/11, information disclosure and clickjacking vulnerabilities were reported for multiple versions of Joomla! The information disclosure vulnerability lets attackers use the index.php script to discover the absolute path to Joomla! The clickjacking vulnerability lets attackers display pages from a Joomla! 1.6 or 1.6.1 site in frames on a specially crafted third-party website.
Resolution: Joomla! 1.7 is available. For more information, visit the vendor's website: http://www.joomla.org/.
This information was compiled using information in the National Vulnerability Database. For more information about this issue, see the following summaries:
CVE-2011-2891
CVE-2011-2892
Website Protection Site Scanner scans for this vulnerability, and many more. To learn about Site Scanner, see Getting Started with Website Protection Site Scanner.