Joomla! 2.5.x before 2.5.25, 3.x before 3.2.4, and 3.3.x before 3.3.4 allows remote attackers to authenticate and bypass intended access restrictions via vectors involving LDAP authentication.
https://euvd.enisa.europa.eu/vulnerability/EUVD-2014-6511
http://secunia.com/advisories/61638
http://secunia.com/advisories/61606
http://developer.joomla.org/security/594-20140902-core-unauthorised-logins.html