Elxis CMS Forum
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Do you know that Elxis CMS supports subscriptional content?
 
Pages: [1]
  Print  
Author Topic: Local file disclosure vulnerability on Feedcreator  (Read 2615 times)
datahell
Elxis Team
Hero Member
*****
Offline Offline

Posts: 5781



WWW
« on: January 16, 2010, 10:56:50 PM »

A local file disclosure vulnerability discovered on a third party class Elxis CMS uses to create RSS feeds.
This vulnerability affects all Elxis versions prior to 2009.2.
Elxis 2009.1 Hecate was patched against this vulnerability and you can download the patched release from the Elxis Downloads Center.

To fix this security issue on existing installations replace the file bellow with the one attached in this post.

includes/feedcreator.class.php


ALL elxis sites hosted on exidna and hades web servers were patched against this vulnerability by Is Open Source.

* patched_feedcreator_class_.zip (12.36 KB - downloaded 128 times.)
« Last Edit: January 16, 2010, 11:29:52 PM by datahell » Logged

Elxis Team | Is Open Source | IOS Reservations | IOS Eshop
Coursar
Elxis Community
Full Member
*****
Offline Offline

Posts: 225



WWW
« Reply #1 on: January 17, 2010, 12:41:43 AM »

Thanks
Logged

http://www.elxis.ru - russian elxis community - Российское сообщество Elxis
supernet
Elxis Community
Hero Member
*****
Offline Offline

Posts: 2671


::: Rentasite Web Services :::


WWW
« Reply #2 on: January 17, 2010, 11:38:08 AM »


Thanks Gianni.
Logged

Sirigos
CreativeOptions - Solutions for Businesses
Elxis Community
Hero Member
*****
Offline Offline

Posts: 1845


The first member of Elxis


WWW
« Reply #3 on: January 17, 2010, 12:10:41 PM »

Thank you Gianni !
Logged

WebGift
Web Services
Elxis Community
Hero Member
*****
Online Online

Posts: 1414



WWW
« Reply #4 on: January 27, 2010, 10:09:58 AM »

Thanks a lot Gianni!
Logged

jimmyz
Full Member
***
Offline Offline

Posts: 134



WWW
« Reply #5 on: January 27, 2010, 02:21:01 PM »

Thanks Johnnie.
Does the vulnerability affect the 2009.0 version of Elxis as well?
Do I need to do something immediately? Upgrading the whole site takes precius time, that I can not afford right now.  Huh
Logged

Dirty Deeds Done Dirt Cheap
supernet
Elxis Community
Hero Member
*****
Offline Offline

Posts: 2671


::: Rentasite Web Services :::


WWW
« Reply #6 on: January 27, 2010, 02:31:55 PM »

Thanks Johnnie.
Does the vulnerability affect the 2009.0 version of Elxis as well?
Do I need to do something immediately? Upgrading the whole site takes precius time, that I can not afford right now.  Huh

Datahell is rather clear  This vulnerability affects all Elxis versions prior to 2009.2.

To fix this security issue on existing installations replace the file bellow with the one attached in this post.
includes/feedcreator.class.php
Logged

jimmyz
Full Member
***
Offline Offline

Posts: 134



WWW
« Reply #7 on: January 27, 2010, 05:14:59 PM »

I guess that I missed "prior".
Replacement done smoothly. All OK now I think.  Smiley
Logged

Dirty Deeds Done Dirt Cheap
datahell
Elxis Team
Hero Member
*****
Offline Offline

Posts: 5781



WWW
« Reply #8 on: January 27, 2010, 07:10:55 PM »

Just replace one file (feedcreator.class.php).
elxis.org lately receives many XSS and SQL injection attacks and today a large scale attack occurred against the elxis server. Some people don't like elxis...  Grin
Logged

Elxis Team | Is Open Source | IOS Reservations | IOS Eshop
WebGift
Web Services
Elxis Community
Hero Member
*****
Online Online

Posts: 1414



WWW
« Reply #9 on: January 27, 2010, 07:16:19 PM »

Some people don't like elxis...  Grin

We have already understood that !
Logged

Pages: [1]
  Print  
 
Jump to: