Forum Moderators: not2easy
This is again a rather severe security issue related to Mambo/Jomlaa, which makes me wonder if this CMS should be used for serious projects. But keep in mind that I am biased since I favour Typo3.
Your allegations in relation to version 1.0.7 of Joomla! are entirely unfounded, as the code has been hardened relating to all identified security threats. At the present time, there are no known exploits.
The Joomla! team monitors and fixes security issues as they arise, just as the team at Typo3 does the same. There are members of the Joomla! team who keep in close contact with other open source project teams who face similar ongoing security risks, the Typo3 team being one of those.
In reality, most of the exploits cannot be executed if the hosting provider has an adequately secure server. It is heartening to see open source projects collaborating on security issues, knowing that many users are on shared hosting - which makes ongoing security patches more critical.
As I mentioned earlier, the vulnerabilities are not an issue if the server is properly secured. Much of the media hype has, I suspect, come about due to the recently publicised hacking of Mambo sites. This has not been the case with sites using Joomla!
Also lost in translation is the word "bugs", which in German appears as "errors"!
Moral of the story, take what you read/hear in the news with a pinch of salt :)