SECUNIA ADVISORY ID:
Cross Site Scripting
Cindy Chee has discovered a vulnerability in Joomla!, which can be
exploited by malicious people to conduct cross-site scripting
Input passed to the "Title" and "Section Name" form fields when
creating new sections in Section Manager is not properly sanitised
before being stored. This can be exploited to insert arbitrary HTML
and script code, which is executed in a user's browser session in
context of an affected site when the data is viewed.
Successful exploitation requires that the target user has valid
The vulnerability is confirmed in version 1.0.12. Other versions may
also be affected.
Do not browse untrusted sites when logged in as administrator.
PROVIDED AND/OR DISCOVERED BY: