| |

Security Security fix's for MD, modules and blocks. Following are the News Items published under this Topic.
Topic name: Security
Number of page: 1 Go to page 1
I'm disgusted, very disgusted, to see that, we have received some blackmails to ask us money to know a vulnerability with SQL Injection afflict MDPro otherwise, if we don't pay, they will share this bug with some groups hackers, then today we have found some MD sites defaced, MAXdev.com, MAXdevitalia.com, site of our no profit association gpldev.org ..... yes I'm very disgusted because we work for free, we work for open source community and these people ask us money to let us know about bug, how you want call this persons ?? hackers ?? men ?? or what ? We are under police investigation, we already know some identities and we will provide with all steps needed to punish these people, we will keep you informed about that. You can read about this bug here We invite all admins to update all MDPro web sites ASAP, you can get temporary fix in our Areafiles area, or you can click here, you just need to overwrite file included, we don't guarantee but it should work with MDPro 1.076 TiMax Project Manager
1 Comment
|
Security fix for MDPro 1.076, please update your sitea as soon as possible. You can download this fix here just overwrite all files
Post comments
|
The MAXdev team has been notified of a security issue, the problem was found to be due to directory traversal vulnerability in error.php in MDPro 1.076 and earlier allows remote attackers to include and execute arbitrary local files under certain circumstances via the PNSVlang session variable which is included by error.php. The patch is available from HERE this affects all versions of MDPro released up until this point. Many thanks go to Larsneo for his help and collaboration We strongly recommend all users apply this patch to their sites ASAP, all MDPro 1.0.76 packages have been updated to include this fix as from the 21-Nov-06 07:00 GMT
5 Comments
|
The MAXdev team has been notified of a security issue with Lost Password function you can read about this exploit here Another small bug was found with insertion of objects code, flash, video etc. This is not a security issue but we take this occasion to release this fix also. We still recommend having the AntiCracker feature enabled.
The patch is available from HERE to apply this fix just replace files Please note that the MDStaff works always to keep MDPro stable and secure and another time we release a fix less than 24 hours after we have notice about it. We strongly recommend all users apply this patch to their sites ASAP, all MDPro 1.0.76 packages have been updated to include this fix as from 30/10/2006
TiMax
Post comments
|
Security fixes for MDPro
The MAXdev team has been notified of a security issue by http://www.jpcert.or.jp the problem was found to be due to poor performance of the pnVarCleanFromInput function at removing potentially harmful input that may result in XSS injection attacks
Another small bug was found with the AntiCracker which may have made it partially ineffective. We still recommend having the AntiCracker enabled, as it would have blocked against the majority of these attacks prior to the patch
The patch is available from HERE this affects all versions of MDPro released up until this point. For MDLite RC testers, MDLite is still marginally affected, the changes to MDPro 1.0.76 have already been backported in CVS and will be included with the next release
Many thanks go to Masaki Kubo from JPCERT/CC for their assistance in bringing this issue to our attention and testing the patch prior to release
We strongly recommend all users apply this patch to their sites ASAP, all MDPro 1.0.76 packages have been updated to include this fix as from the 18-Sep-06 09:00 GMT
PeteBest
Post comments
|
The MAXdev CMS Development Team was notified by Andreas Krapohl [larsneo] about an exploit discovered by secunia.com that is a vulnerability in the adodb database abstraction layer. VULNERABILTIES Arbitrary SQL code execution via adodb (when db-user is 'root' without password)
Read more... (485 bytes more) 1 Comment
|
As we have already said in our news: http://www.maxdev.com/Article492.phtml It is recommended that all admins deactivate and completely remove from the filesystem the xmlrpc module within administration-modules, /xmlrpc.php and the /modules/xmlrpc folder.
2 Comments
|
Thanks to Andreas Krapohl [larsneo] we was notified about a security issue within the current Messages module.
VULNERABILTIES- missing input validation within /modules/Messages/readpmsg.php and /modules/Messages/readpmsgob.php
SOLUTION- It is recommended that all admins update these files as soon as possible, to do that, just download fix and replace both files.
All MD-Pro 1.0.72 downloads from this site have now had this update already applied to them, including the 1.0.72 upgrade release. You only need this security fix if you downloaded MD-Pro before the date on this announcement. If in doubt, please overwrite your existing files, just to be sure
MD Staff
Post comments
|
Thanks to Andreas Krapohl [larsneo] of Postnuke Dev team we was notified about a security issue within the current MD-Pro and xmlrpc library.VULNERABILTIES- remote code injection via xml rpc library
Read more... (877 bytes more) 1 Comment
|
|
Number of page: 1 Go to page 1
|
|