Elxis CMS Forum
Support => Security => Topic started by: datahell on January 16, 2010, 22:56:50
-
A local file disclosure vulnerability discovered on a third party class Elxis CMS uses to create RSS feeds.
This vulnerability affects all Elxis versions prior to 2009.2.
Elxis 2009.1 Hecate was patched against this vulnerability and you can download the patched release from the Elxis Downloads Center (http://www.elxis-downloads.com).
To fix this security issue on existing installations replace the file bellow with the one attached in this post.
includes/feedcreator.class.php
ALL elxis sites hosted on exidna and hades web servers were patched against this vulnerability by Is Open Source.
[attachment deleted by admin]
-
Thanks
-
Thanks Gianni.
-
Thank you Gianni !
-
Thanks a lot Gianni!
-
Thanks Johnnie.
Does the vulnerability affect the 2009.0 version of Elxis as well?
Do I need to do something immediately? Upgrading the whole site takes precius time, that I can not afford right now. ???
-
Thanks Johnnie.
Does the vulnerability affect the 2009.0 version of Elxis as well?
Do I need to do something immediately? Upgrading the whole site takes precius time, that I can not afford right now. ???
Datahell is rather clear This vulnerability affects all Elxis versions prior to 2009.2.
To fix this security issue on existing installations replace the file bellow with the one attached in this post.
includes/feedcreator.class.php
-
I guess that I missed "prior".
Replacement done smoothly. All OK now I think. :)
-
Just replace one file (feedcreator.class.php).
elxis.org lately receives many XSS and SQL injection attacks and today a large scale attack occurred against the elxis server. Some people don't like elxis... ;D
-
Some people don't like elxis... ;D
We have already understood that !