Elxis CMS Forum

Support => Security => Topic started by: datahell on January 16, 2010, 22:56:50

Title: Local file disclosure vulnerability on Feedcreator
Post by: datahell on January 16, 2010, 22:56:50
A local file disclosure vulnerability discovered on a third party class Elxis CMS uses to create RSS feeds.
This vulnerability affects all Elxis versions prior to 2009.2.
Elxis 2009.1 Hecate was patched against this vulnerability and you can download the patched release from the Elxis Downloads Center (http://www.elxis-downloads.com).

To fix this security issue on existing installations replace the file bellow with the one attached in this post.

includes/feedcreator.class.php


ALL elxis sites hosted on exidna and hades web servers were patched against this vulnerability by Is Open Source.

[attachment deleted by admin]
Title: Re: Local file disclosure vulnerability on Feedcreator
Post by: Coursar on January 17, 2010, 00:41:43
Thanks
Title: Re: Local file disclosure vulnerability on Feedcreator
Post by: rentasite on January 17, 2010, 11:38:08

Thanks Gianni.
Title: Re: Local file disclosure vulnerability on Feedcreator
Post by: CREATIVE Options on January 17, 2010, 12:10:41
Thank you Gianni !
Title: Re: Local file disclosure vulnerability on Feedcreator
Post by: webgift on January 27, 2010, 10:09:58
Thanks a lot Gianni!
Title: Re: Local file disclosure vulnerability on Feedcreator
Post by: jimmyz on January 27, 2010, 14:21:01
Thanks Johnnie.
Does the vulnerability affect the 2009.0 version of Elxis as well?
Do I need to do something immediately? Upgrading the whole site takes precius time, that I can not afford right now.  ???
Title: Re: Local file disclosure vulnerability on Feedcreator
Post by: rentasite on January 27, 2010, 14:31:55
Thanks Johnnie.
Does the vulnerability affect the 2009.0 version of Elxis as well?
Do I need to do something immediately? Upgrading the whole site takes precius time, that I can not afford right now.  ???

Datahell is rather clear  This vulnerability affects all Elxis versions prior to 2009.2.

To fix this security issue on existing installations replace the file bellow with the one attached in this post.
includes/feedcreator.class.php
Title: Re: Local file disclosure vulnerability on Feedcreator
Post by: jimmyz on January 27, 2010, 17:14:59
I guess that I missed "prior".
Replacement done smoothly. All OK now I think.  :)
Title: Re: Local file disclosure vulnerability on Feedcreator
Post by: datahell on January 27, 2010, 19:10:55
Just replace one file (feedcreator.class.php).
elxis.org lately receives many XSS and SQL injection attacks and today a large scale attack occurred against the elxis server. Some people don't like elxis...  ;D
Title: Re: Local file disclosure vulnerability on Feedcreator
Post by: webgift on January 27, 2010, 19:16:19
Some people don't like elxis...  ;D

We have already understood that !