Since March 15th, 2012, there is a known exploit which affects all Joomla! 1.6 and 1.7 releases, as well as Joomla! 2.5.0, 2.5.1 and 2.5.2. It was fixed in 2.5.3. The exploit allows an attacker to create a Super Administrator account by abusing the user creation form in the front-end. Since the attack is TRIVIAL to perform and does not trigger any kind of security alert (it looks like a legitimate user registration attempt), neither Admin Tools nor any other security component can protect you. As a result, we consider using Joomla! 1.6.x, 1.7.x or 2.5.0-2.5.2 EXTREMELY INSECURE and therefore ceased supporting those Joomla! versions effective the same day this vulnerability was discovered.
In other words, if you are using Joomla! 1.6.0 up to and including 2.5.2, a hacker can hack your site in about 2 minutes. You MUST upgrade IMMEDIATELY to Joomla! 2.5.3. Anything else will not work and you WILL be hacked.
Nicholas K. Dionysopoulos
Lead Developer and Director
🇬🇷Greek: native 🇬🇧English: excellent 🇫🇷French: basic • 🕐 My time zone is Europe / Athens
Please keep in mind my timezone and cultural differences when reading my replies. Thank you!