We are running Joomla 1.5 with the Joomla2SMF component.
We have had spammers register at the site, not activate their account, and post spam to the forums.
In the User Manager, the username appears, but they are listed as "Never Visited" and the account was never enabled.
I have tried to register for an account, not activate it, and post a message, and this test fails. I am guessing that there is a vulnerability that is being exploited.
Has anyone had this problem?
-- Charlie
Joomla2SMF vulnerability






