logo
 
  1. Webseiten erstellen >
  2. Joomla

EnglishFrenchGermanItalianPortugueseRussianSpanish

Was ist Joomla?

Joomla dient in erster Linie der Erstellung von Webseiten mit veränderlichen, d. h. dynamischen Inhalten, die von mehreren Personen ohne vertiefte Kenntnisse über Webseitenerstellung editiert werden können. Dabei wird innerhalb von Joomla zwischen drei Ebenen streng unterschieden: der funktionellen Struktur, den eigentlichen Seiteninhalten und dem Layout.

Die Einrichtung der funktionellen Struktur, häufig mit dem englischen Begriff management bezeichnet, ist aufwändig und setzt profunde Kenntnisse voraus. Sie liegt daher häufig in den Händen einer entsprechend ausgebildeten Einzelperson, die als Administrator bezeichnet wird. Dieser muss Joomla auf einem Webserver installieren, üblicherweise einem Apache-Webserver, außerdem wird ein MySQL-Datenbank-Server benötigt.

Joomla Webseitenerstellung

Wir bieten Joomla Dienstleistungen an für 30,- Euro.

Joomla Webseite erstellen. Webseitenerstellung Kosten zwischen 500- Euro und 900,- Euro inkl. Schulung über die Grundlagen der Bedienung.

Nehmen Sie Kontakt mit uns über Telefon 0441-2333305 (Mo. - Fr. 9 Uhr - 17 Uhr) in Oldenburg auf, oder per Email an info@php-consulting.com (24/7).

Joomla News

Joomla 4.0 Alpha 1 Released for Testing

joomla 4 alpha 1

The Joomla Project is pleased to announce the availability of Joomla 4.0 Alpha 1 for download.

Datum: 17.11.2017 | 16:00

Joomla! 3.8.2 Release

Joomla 3.8.2

Joomla! 3.8.2 is now available. This is a security release for the 3.x series of Joomla addressing three security vulnerabilities and fixing several bugs which were reported after the previous Joomla releases.

Datum: 7.11.2017 | 16:00

Joomla! 3.8.1 Release

Joomla 3.8.1

Joomla! 3.8.1 is now available. This is a bug fix release for the 3.x series of Joomla fixing bugs which were reported after the 3.8.0 release.

Datum: 4.10.2017 | 15:45

Joomla! 3.8.0 Release

Joomla 3.8.0

The Joomla! Project is proud to announce the release of Joomla! 3.8, the latest in the Joomla! 3 series. This new release features over 300 improvements to the popular CMS, with two primary major features aimed at developers: the new routing system and the beginning of a forward compatibility layer with Joomla! 4.0. Additionally, two security issues have been resolved.

Datum: 19.09.2017 | 16:00

Joomla! in Rome

Joomla World Conference 2017

With one of the largest user bases, Italy is a natural choice for this year’s Joomla! World Conference Venue. For the first time the JWC is coming to Europe and will take place at the Sheraton Roma Conference Centre between 17th and 19th November, 2017.

Datum: 6.09.2017 | 15:00

Joomla! 3.7.5 Release

Joomla 3.7.5

Joomla! 3.7.5 is now available. This is a bug fix release for the 3.x series of Joomla! which addresses a single bug that prevents new installations of Joomla! 3.7.4 with remote databases.

Datum: 17.08.2017 | 08:00

Joomla! 3.7.4 Release

Joomla 3.7.4

Joomla! 3.7.4 is now available. This is a security release for the 3.x series of Joomla! which includes two security vulnerability fixes and over 50 bug fixes and improvements. We strongly recommend that you update your sites immediately.

Datum: 25.07.2017 | 08:00

Joomla! 3.7.3 Release

Joomla 3.7.3

Joomla! 3.7.3 is now available. This is a security release for the 3.x series of Joomla! which includes security vulnerabilities and over 230 bug fixes and improvements. We strongly recommend that you update your sites immediately.

Datum: 4.07.2017 | 08:00

Joomla Security

[20171103] - Core - Information Disclosure

  • Project: Joomla!
  • SubProject: CMS
  • Severity: Low
  • Versions: 3.7.0 through 3.8.1
  • Exploit type: Information Disclosure
  • Reported Date: 2017-May-17
  • Fixed Date: 2017-November-07
  • CVE Number: CVE-2017-16633

Description

A logic bug in com_fields exposed read-only information about a site's custom fields to unauthorized users.

Affected Installs

Joomla! CMS versions 3.7.0 through 3.8.1

Solution

Upgrade to version 3.8.2

Contact

The JSST at the Joomla! Security Centre.

Reported By: Internal JSST audit

Datum: 7.11.2017 | 16:00

[20171102] - Core - 2-factor-authentication bypass

  • Project: Joomla!
  • SubProject: CMS
  • Severity: Medium
  • Versions: 3.2.0 through 3.8.1
  • Exploit type: 
  • Reported Date: 2017-October-31
  • Fixed Date: 2017-November-07
  • CVE Number: CVE-2017-16634

Description

A bug allowed third parties to bypass a user's 2-factor-authentication method.

Affected Installs

Joomla! CMS versions 3.2.0 through 3.8.1

Solution

Upgrade to version 3.8.2

Contact

The JSST at the Joomla! Security Centre.

Reported By: Yarince

Datum: 7.11.2017 | 16:00

[20171101] - Core - LDAP Information Disclosure

  • Project: Joomla!
  • SubProject: CMS
  • Severity: Medium
  • Versions: 1.5.0 through 3.8.1
  • Exploit type: Information Disclosure
  • Reported Date: 2017-October-06
  • Fixed Date: 2017-November-07
  • CVE Number: CVE-2017-14596

Description

Inadequate escaping in the LDAP authentication plugin can result in disclosure of username and password.

Affected Installs

Joomla! CMS versions 1.5.0 through 3.8.1

Solution

Upgrade to version 3.8.2

Contact

The JSST at the Joomla! Security Centre.

Reported By: Dr. Johannes Dahse, RIPS Technologies GmbH

Datum: 7.11.2017 | 16:00

[20170901] - Core - Information Disclosure

  • Project: Joomla!
  • SubProject: CMS
  • Severity: Low
  • Versions: 3.7.0 through 3.7.5
  • Exploit type: Information Disclosure
  • Reported Date: 2017-August-4
  • Fixed Date: 2017-September-19
  • CVE Number: CVE-2017-14595

Description

A logic bug in a SQL query could lead to the disclosure of article intro texts when these articles are in the archived state.

Affected Installs

Joomla! CMS versions 3.7.0 through 3.7.5

Solution

Upgrade to version 3.8.0

Contact

The JSST at the Joomla! Security Centre.

Reported By: Michal Prochaczek

Datum: 19.09.2017 | 16:00

[20170902] - Core - LDAP Information Disclosure

  • Project: Joomla!
  • SubProject: CMS
  • Severity: Medium
  • Versions: 1.5.0 through 3.7.5
  • Exploit type: Information Disclosure
  • Reported Date: 2017-July-27
  • Fixed Date: 2017-September-19
  • CVE Number: CVE-2017-14596

Description

Inadequate escaping in the LDAP authentication plugin can result into a disclosure of username and password.

Affected Installs

Joomla! CMS versions 1.5.0 through 3.7.5

Solution

Upgrade to version 3.8.0

Contact

The JSST at the Joomla! Security Centre.

Reported By: Dr. Johannes Dahse, RIPS Technologies GmbH

Datum: 19.09.2017 | 16:00

[20170705] - Core - XSS Vulnerability

  • Project: Joomla!
  • SubProject: CMS
  • Severity: Low
  • Versions: 1.5.0 through 3.7.3
  • Exploit type: XSS
  • Reported Date: 2017-April-26
  • Fixed Date: 2017-July-25
  • CVE Number: CVE-2017-11612

Description

Inadequate filtering of potentially malicious HTML tags leads to XSS vulnerabilities in various components.

Affected Installs

Joomla! CMS versions 1.5.0 through 3.7.3

Solution

Upgrade to version 3.7.4

Contact

The JSST at the Joomla! Security Centre.

Reported By: Beat B, JSST

Datum: 25.07.2017 | 02:00

[20170704] - Core - Installer: Lack of Ownership Verification

  • Project: Joomla!
  • SubProject: CMS Installer
  • Severity: High
  • Versions: 1.0.0 through 3.7.3
  • Exploit type: Lack of Ownership Verification
  • Reported Date: 2017-Apr-06
  • Fixed Date: 2017-July-25
  • CVE Number: CVE-2017-11364

Description

The CMS installer application lacked a process to verify the users ownership of a webspace, potentially allowing users to gain control.

Please note: Already installed sites are not affected, as this issue is limited to the installer application!

Affected Installs

Joomla! CMS versions 1.0.0 through 3.7.3

Solution

Upgrade to version 3.7.4

Contact

The JSST at the Joomla! Security Centre.

Reported By: Hanno Böck

Datum: 25.07.2017 | 02:00

[20170702] - Core - XSS Vulnerability

  • Project: Joomla!
  • SubProject: CMS
  • Severity: High
  • Versions: 1.7.3 - 3.7.2
  • Exploit type: XSS
  • Reported Date: 2017-June-04
  • Fixed Date: 2017-July-04
  • CVE Number: CVE-2017-9934

Description

Missing CSRF token checks and improper input validation lead to an XSS vulnerability.

Affected Installs

Joomla! CMS versions 1.7.3-3.7.2

Solution

Upgrade to version 3.7.3

Contact

The JSST at the Joomla! Security Centre.

Reported By: Envo

Datum: 4.07.2017 | 14:00

[20170701] - Core - Information Disclosure

  • Project: Joomla!
  • SubProject: CMS
  • Severity: High
  • Versions: 1.7.3 - 3.7.2
  • Exploit type: Information Disclosure
  • Reported Date: 2016-Feb-05
  • Fixed Date: 2017-July-04
  • CVE Number: CVE-2017-9933

Description

Improper cache invalidation leads to disclosure of form contents.

Affected Installs

Joomla! CMS versions 1.7.3-3.7.2

Solution

Upgrade to version 3.7.3

Contact

The JSST at the Joomla! Security Centre.

Reported By: Jeff Channell

Datum: 4.07.2017 | 14:00

[20170703] - Core - XSS Vulnerability

  • Project: Joomla!
  • SubProject: CMS
  • Severity: Low
  • Versions: 1.5.0 through 3.7.2
  • Exploit type: XSS
  • Reported Date: 2017-June-22
  • Fixed Date: 2017-July-04
  • CVE Number: CVE-2017-7985

Description

Inadequate filtering of multibyte characters leads to XSS vulnerabilities in various components.

Affected Installs

Joomla! CMS versions 1.5.0 through 3.6.5

Solution

Upgrade to version 3.7.3

Contact

The JSST at the Joomla! Security Centre.

Reported By: Fortinet's FortiGuard Labs

Datum: 4.07.2017 | 14:00