Niels Braczek From Germany Joomla! Community has released a patch:<br><br>
<a href="http://www.joomlaportal.de/sicherheit/241658-joomla-1-0-x-1-0-15-cross-site-scripting-xss-vulnerability.html">http://www.joomlaportal.de/sicherheit/241658-joomla-1-0-x-1-0-15-cross-site-scripting-xss-vulnerability.html</a><br>
<br>It uses the same Joomla! filtering function and thus it's supposed to safe. <br><br><br>For your convenience, download the patched file from <br><a href="http://yehg.net/lab/pr0js/advisories/joomla/core/patched_com_search.zip">http://yehg.net/lab/pr0js/advisories/joomla/core/patched_com_search.zip</a> 5368aa00b2d4746e025baa030babc888<br>
<br><br><br><br><br>Updated advisory.<br><br><br>==============================================================================<br> Joomla! 1.0.x ~ 1.0.15 | Cross Site Scripting (XSS) Vulnerability<br>==============================================================================<br>
<br><br>1. OVERVIEW<br><br>The Joomla! 1.0.x series are currently vulnerable to Cross Site Scripting.<br>CVE ID, CVE-2011-0005, has been assigned for it. <br><br><br>2. BACKGROUND<br><br>Joomla! is a free and open source content management system (CMS) for publishing content on the World Wide Web and intranets. <br>
<br><br>3. VULNERABILITY DESCRIPTION<br><br>The "ordering" parameter in a core module,com_search, is not properly sanitized and thus vulnerable to XSS. <br>By leveraging this vulnerability, attackers can compromise currently logged-in user/administrator session and impersonate arbitrary user actions available under /administrator/ functions. As the vulnerability is based on the core module, it affects both classic and customized Joomla! 1.0.x based web sites. <br>
<br><br>4. VERSIONS AFFECTED<br><br>Joomla! 1.0.x ~ 1.0.15 series<br><br><br>5. PROOF-OF-CONCEPT/EXPLOIT<br><br><a href="http://attacker.in/joomla1015/index.php?option=com_search&searchword=xss&searchphrase=any&ordering=newest%22%20onmousemove=alert%28document.cookie%29%20style=position:fixed;top:0;left:0;width:100%;height:100%;%22">http://attacker.in/joomla1015/index.php?option=com_search&searchword=xss&searchphrase=any&ordering=newest%22%20onmousemove=alert%28document.cookie%29%20style=position:fixed;top:0;left:0;width:100%;height:100%;%22</a><br>
<br><br>6. SOLUTION<br><br>Joomla 1.0.x series has been at end of life since 2009-07-22.<br><br>Upgrade to Joomla! 1.5.x family (1.5.22 as of 2011-01-06)<br><br>Apply the third-party patch:<br><a href="http://www.joomlaportal.de/sicherheit/241658-joomla-1-0-x-1-0-15-cross-site-scripting-xss-vulnerability.html">http://www.joomlaportal.de/sicherheit/241658-joomla-1-0-x-1-0-15-cross-site-scripting-xss-vulnerability.html</a><br>
<br><br>7. VENDOR<br><br>Joomla! Developer Team<br><a href="http://www.joomla.org">http://www.joomla.org</a><br><br><br>8. CREDIT<br><br>This vulnerability was discovered by Aung Khant, <a href="http://yehg.net">http://yehg.net</a>, YGN Ethical Hacker Group, Myanmar.<br>
<br><br>9. DISCLOSURE TIME-LINE<br><br>2011-01-03: notified Joomla! Security Strike Team regardless of EOL status<br>2011-01-06: vulnerability disclosed<br>2011-01-07: vendor confirmed that they would not release patch<br>
<br><br>10. VENDOR RESPONSE<br><br>>> While noted, your exploit report does not fall within the JSST remit as <br>>> we no longer support J1.0.x branch (as you are aware and indicate).<br>>> The vulnerability mentioned is not known to exist in any current supported release. <br>
>> Please ensure you are using the latest version of Joomla!<br><br><br>11. REFERENCES<br><br>Original Advisory URL: <a href="http://yehg.net/lab/pr0js/advisories/joomla/core/[joomla_1.0.x~15]_cross_site_scripting">http://yehg.net/lab/pr0js/advisories/joomla/core/[joomla_1.0.x~15]_cross_site_scripting</a><br>
Patched File: <a href="http://yehg.net/lab/pr0js/advisories/joomla/core/patched_com_search.zip">http://yehg.net/lab/pr0js/advisories/joomla/core/patched_com_search.zip</a><br>Joomla! 1.0.x End of Life - <a href="http://community.joomla.org/blogs/community/509-an-old-friend-comes-of-age.html">http://community.joomla.org/blogs/community/509-an-old-friend-comes-of-age.html</a><br>
OWASP Top 10: <a href="http://www.owasp.org/index.php/Category:OWASP_Top_Ten_Project">http://www.owasp.org/index.php/Category:OWASP_Top_Ten_Project</a><br>CWE-79: <a href="http://cwe.mitre.org/data/definitions/79.html">http://cwe.mitre.org/data/definitions/79.html</a><br>
<br><br>#yehg [2011-01-06]<br><br>#updated - 2011-01-14<br> - added patched link<br>#updated - 2011-01-07<br> - added VENDOR RESPONSE, CVE ID <br>