Description
Joomla! Core is prone to a session fixation vulnerability. An attacker may leverage this issue to hijack an arbitrary session and gain access to sensitive information, which may help in launching further attacks. Joomla! Core versions 1.0.x ranging from 1.0.0 and up to and including 1.0.12 are vulnerable.
Remediation
Update to Joomla! Core version 1.0.13 or latest
References
http://www.securityfocus.com/archive/1/archive/1/476017/100/0/threaded
https://www.joomla.org/announcements/release-news/3677-joomla-1013-released.html
Related Vulnerabilities
WordPress Plugin EventCommerce WP Event Calendar Cross-Site Scripting (1.0)
WordPress Plugin WP e-Commerce-Store Toolkit Privilege Escalation (2.0)
Joomla! Core Information Disclosure (2.5.0 - 3.9.22)
WordPress Plugin WordPress Infinite Scroll-Ajax Load More SQL Injection (5.3.1)
WordPress Plugin Wp-ImageZoom 'file' Parameter Information Disclosure (1.0.3)