Joomla! 2.5.x before 2.5.4 does not properly check permissions, which allows attackers to obtain sensitive "administrative back end" information via unknown attack vectors. NOTE: this might be a duplicate of CVE-2012-1599.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://www.openwall.com/lists/oss-security/2012/04/03/5 | mailing list |
http://www.openwall.com/lists/oss-security/2012/04/03/3 | mailing list |
http://developer.joomla.org/security/news/398-20120307-core-information-disclosure.html | vendor advisory |
http://secunia.com/advisories/48683 | third party advisory vendor advisory |