CMS Made Simple 'cms_language' Cookie Parameter Directory Traversal Vulnerabilit

General project discussion. NOT for help questions.
Post Reply
User avatar
johnbmcdonald
Forum Members
Forum Members
Posts: 60
Joined: Mon May 14, 2007 8:01 pm
Location: Edmond, OK, USA

CMS Made Simple 'cms_language' Cookie Parameter Directory Traversal Vulnerabilit

Post by johnbmcdonald »

Just ran across this, thought you'd like to know:

http://www.securityfocus.com/bid/32535

John
RonnyK
Support Guru
Support Guru
Posts: 4962
Joined: Wed Oct 25, 2006 8:29 pm
Location: Raalte, the Netherlands

Re: CMS Made Simple 'cms_language' Cookie Parameter Directory Traversal Vulnerabilit

Post by RonnyK »

Thanks John,

will pass it on for examination....

Ronny
Dee
Power Poster
Power Poster
Posts: 1197
Joined: Sun Mar 19, 2006 8:46 pm
Location: the Netherlands

Re: CMS Made Simple 'cms_language' Cookie Parameter Directory Traversal Vulnerabilit

Post by Dee »

Has already been picked up by calguy.

Replace admin/lang.php with the latest revision to fix.

Regards,
D
User avatar
johnbmcdonald
Forum Members
Forum Members
Posts: 60
Joined: Mon May 14, 2007 8:01 pm
Location: Edmond, OK, USA

Re: CMS Made Simple 'cms_language' Cookie Parameter Directory Traversal Vulnerabilit

Post by johnbmcdonald »

Thanks!  :)
michi1979

Re: CMS Made Simple 'cms_language' Cookie Parameter Directory Traversal Vulnerabilit

Post by michi1979 »

Hello,
is this fix also included in 1.5 ?

Greetings,
Michael
alby

Re: CMS Made Simple 'cms_language' Cookie Parameter Directory Traversal Vulnerabilit

Post by alby »

michi1979 wrote: is this fix also included in 1.5 ?
yes

Alby
Post Reply

Return to “General Discussion”