A previously unknown injection vulnerability exists in Joomlas LDAP (Lightweight Directory Access Protocol) authentication code. Because affected versions of the software does not properly sanitise user input, the vulnerability can be exploited through the CMS login page. A successful attack can lead to hackers stealing administrator login credentials, and gaining complete control over a website. The serious security hole was discovered by German security firm RIPS Tech. It took eight years for the software to be discovered, and well never know if malicious hackers exploited it in the meantime.”]

