{"id":875,"date":"2016-10-27T11:45:00","date_gmt":"2016-10-27T16:45:00","guid":{"rendered":"https:\/\/cert.pa\/?p=875"},"modified":"2016-10-27T11:48:47","modified_gmt":"2016-10-27T16:48:47","slug":"csirt-panama-aviso-2016-10-27-joomla-lanza-actualizacion-de-seguridad-para-cms","status":"publish","type":"post","link":"https:\/\/cert.pa\/?p=875","title":{"rendered":"CSIRT Panam\u00e1 Aviso 2016-10-27 \u2013Joomla &#8211; Lanza actualizaci\u00f3n de seguridad para CMS"},"content":{"rendered":"<p>CSIRT Panam\u00e1 Aviso 2016-27 \u2013Joomla &#8211; Lanza actualizaci\u00f3n de seguridad para CMS<br \/>\nGravedad: Cr\u00edtica<br \/>\nFecha de publicaci\u00f3n: Octubre 25, 2016<br \/>\nFecha de modificaci\u00f3n: Octubre 27, 2016<br \/>\n\u00daltima revisi\u00f3n: Revisi\u00f3n A.<br \/>\nFuente: www.joomla.org\/announcements.html<\/p>\n<p>Sistemas Afectados<br \/>\nSerie 3.x de Joomla.<\/p>\n<p>I. Descripci\u00f3n<br \/>\nJoomla! ha lanzado la versi\u00f3n 3.6.4 de su software de sistema de gesti\u00f3n de contenido (CMS) para resolver varias vulnerabilidades. La explotaci\u00f3n de algunas de estas vulnerabilidades podr\u00eda permitir a un atacante remoto tomar el control de un sitio afectado.<\/p>\n<p>II. Impacto<br \/>\nEl impacto al no estar actualizado a la versi\u00f3n 3.6.4 seria:<br \/>\n\u2022 La falta de control permite a los usuarios registrarse en un sitio cuando el registro se ha desactivado.<br \/>\n\u2022 El uso incorrecto de los datos sin filtrar permite a los usuarios registrarse en un sitio con privilegios elevados.<\/p>\n<p>III. Referencia a soluciones, herramientas e informaci\u00f3n<br \/>\nJoomla recomienda que actualice sus sitios inmediatamente a la versi\u00f3n 3.6.4.<br \/>\nhttps:\/\/www.joomla.org\/announcements.html<\/p>\n<p>IV. Informaci\u00f3n de contacto<br \/>\nCSIRT PANAMA<br \/>\nAutoridad Nacional para la Innovaci\u00f3n Gubernamental<br \/>\nE-Mail: info@cert.pa<br \/>\nWeb: http:\/\/www.cert.pa<br \/>\n\u2014\u2013BEGIN PGP PUBLIC KEY BLOCK\u2014\u2013<br \/>\nVersion: GnuPG v2.0.17 (MingW32)<br \/>\nmQENBE8C9KoBCAClkvrtdD08B1YgIntnK241GmWY7fRWtPn\/QIEG1+TLokEuOhw+<br \/>\nGq\/lK\/4NP9RzqpD57LcRUBiGgTmO\/5C9xkhVmxz2jid0h03fLorC84rAk2pOjr0i<br \/>\npbltETq9RCGhOWp13OV22x2yiIedBi05bzw3F+uLHhn9xKjmpBuZB6WO\/TuD52DH<br \/>\nKRZtwSvoaa61vL0bGnIf3lNGWkALWEC3lGBppby4D05N2FNfgfOFr1yOpxTaRaDh<br \/>\n4kOnoAEWVzppkTPyqSOkwXmgdma8D9yqD41Ffu8ypGTv+OOVO7jDq8tx9wVZEU+w<br \/>\npqBTzQcf0P0K7qO3igdHQxqHmqXsaJpbmvCBABEBAAG0KkNTSVJUIFBhbmFtYSAo<br \/>\nQ1NJUlQgUGFuYW1hKSA8aW5mb0BjZXJ0LnBhPokBOAQTAQIAIgUCTwL0qgIbDwYL<br \/>\nCQgHAwIGFQgCCQoLBBYCAwECHgECF4AACgkQ2YlXchbysSSPSQgAooUy3qSR\/YX2<br \/>\nH3USJ5VzrmnraHg5LIWRPIBD1PGrswjLE8hxdobPU\/uzi9LWnEcDscfFVKM\/K0Jt<br \/>\nbjeoESqCVFlpE0YXJWdDhy0m2WM410sDE2HVXbPhWGqrNeDb0VUV\/LWag1yYTj5w<br \/>\nkkxma4Tk5TqlhgL5su2PpjtTdFSHYD4N+4mu7g1GhRrrpz+u7ZRm3b\/WkAJg5FIg<br \/>\nU0MpPqUGAF5\/pc02ZB10FdxDwWyXAkwYUN+zfLiKzKOrBGkEw9+jvFGU+z76P9Zk<br \/>\n1XJIexpmkBYTxc+TOclhAp\/3HP4taoBHRMoR1q1YhdC++UgRSLmPLGn\/AB707JzN<br \/>\nQ80++q2kWQ==<br \/>\n=JUYg<\/p>\n","protected":false},"excerpt":{"rendered":"<p>CSIRT Panam\u00e1 Aviso 2016-27 \u2013Joomla &#8211; Lanza actualizaci\u00f3n de seguridad para CMS Gravedad: Cr\u00edtica Fecha de publicaci\u00f3n: Octubre 25, 2016 Fecha de modificaci\u00f3n: Octubre 27, 2016 \u00daltima revisi\u00f3n: Revisi\u00f3n A. Fuente: www.joomla.org\/announcements.html Sistemas Afectados Serie&#8230;<\/p>\n","protected":false},"author":4,"featured_media":594,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"om_disable_all_campaigns":false,"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"_uf_show_specific_survey":0,"_uf_disable_surveys":false,"footnotes":""},"categories":[4],"tags":[],"class_list":["post-875","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-avisos-de-seguridad"],"_links":{"self":[{"href":"https:\/\/cert.pa\/index.php?rest_route=\/wp\/v2\/posts\/875","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cert.pa\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cert.pa\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cert.pa\/index.php?rest_route=\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/cert.pa\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=875"}],"version-history":[{"count":4,"href":"https:\/\/cert.pa\/index.php?rest_route=\/wp\/v2\/posts\/875\/revisions"}],"predecessor-version":[{"id":879,"href":"https:\/\/cert.pa\/index.php?rest_route=\/wp\/v2\/posts\/875\/revisions\/879"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cert.pa\/index.php?rest_route=\/wp\/v2\/media\/594"}],"wp:attachment":[{"href":"https:\/\/cert.pa\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=875"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cert.pa\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=875"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cert.pa\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=875"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}