Matomo 0.5, response to « Shocking News in PHP Exploitation »

The Matomo (Piwik) project acknowledges its exposure to the cookie exploit vulnerability described in Stefan Esser’s presentation, « Shocking News in PHP Exploitation« . The potential security vulnerability exists in all versions of Matomo prior to version 0.5. While no exploit code …

Read More

Matomo 0.4.4, response to Secunia Advisory SA37078

The Matomo (Piwik) project confirms that a potential vulnerability exists due to a file included in a third-party library. The vulnerability is exploitable whether or not the web site has the PHP configuration directive register_globals=On. The list of affected Matomo …

Read More

Matomo 0.2.33, response to CVE-2009-1085

Reference: CVE-2009-1085 dated 03/25/2009 Contrary to the advisory, the Matomo (Piwik) project did not « confirm » this « vulnerability ». We have classified this issue as user error. The subject file, « misc/cron/archive.sh », was intended to be a sample shell script. By default, archiving …

Read More