MAXdev

Security fixes for MDPro 1.0.76

Support and security / Security
Posted by TiMax on Oct 31, 2006 - 07:17 AM

The MAXdev team has been notified of a security issue with Lost Password function you can read about this exploit here [1]


Another small bug was found with insertion of objects code, flash, video etc. This is not a security issue but we take this occasion to release this fix also.


We still recommend having the AntiCracker feature enabled.

The patch is available from HERE [2] to apply this fix just replace files


Please note that the MDStaff works always to keep MDPro stable and secure and another time we release a fix less than 24 hours after we have notice about it.


We strongly recommend all users apply this patch to their sites ASAP, all MDPro 1.0.76 packages have been updated to include this fix as from 30/10/2006

TiMax



This story comes from MAXdev
  http://www.maxdev.com/

The URL for this story is:
  http://www.maxdev.com/modules.php?op=modload&name=News&file=article&sid=608

Links in this article
  [1] http://www.securityfocus.com/bid/20752/discuss
  [2] http://www.maxdev.com/modules.php?op=modload&name=Downloads&file=index&req=dldet&lid=497&ttitle=Security_fix_for_MDPro_1.076_-_30/10