Mar 16, 2010 | 01:48 AM  
Welcome

Don't have an account yet? You can create one, it is free, just click here

as a registered user you have some advantages like free downloads, comments and posting on our forums, depending upon this site's configuration and options.

 • •  Control Panel - Register - Login  • • 
Current Stable MDPro Lite 1.0821 Download
Latest Comments
  Re: Have you receive...
العاب ون - &#...
odai

  Re: MDContact 3
We will release a new version in next days, we are work...
TiMax

  Re: MDContact 3
Mdpro is great, I can't find these features anywhere el...
irmadilley

Posted by : TiMax - Thursday, June 30, 2005
Security

Thanks to Andreas Krapohl [larsneo] of Postnuke Dev team we was notified about a security issue within the current MD-Pro and xmlrpc library.VULNERABILTIES- remote code injection via xml rpc library



SOLUTIONIt is recommended that all admins deactivate and remove the 'xmlrpc' module within administration-modules and additionaly remove /xmlrpc.php and and the /modules/xmlrpc folder completly from the filesystem.We highly recommends to *not* use the xml rpc library until the maintainers [1] provide a secure solution. Once an updated version is available a modularized version will be provided for download as an additional module.CREDITSThe exploit has been originally found by James from GulfTech Security Research and was reported via security contact. Additionally the maintainers of the xml rpc library were contacted.[1] phpxmlrpc.sourceforge.net

   Printer friendly page  

Remote Code Injection via xml rpc (third party library used in MD-Pro CMS) | Login/Create an account | 1 Comment
Comments are owned by their poster. We aren't responsible for their content.
Re: Remote Code Injection via xml rpc (third party library used in MDPro CMS) (Score: 1)
by terryg on July 03, 2005 - 12:30 AM
(User information | Send a Message) http://www.westacres.net)
Looks like an updated version is now available at http://phpxmlrpc.sourceforge.net/.