Bugtraq report of security issues in 1.6.6

Talk about writing modules and plugins for CMS Made Simple, or about specific core functionality. This board is for PHP programmers that are contributing to CMSMS not for site developers
Post Reply
User avatar
Peripatetic
New Member
New Member
Posts: 2
Joined: Wed Sep 24, 2008 3:38 pm

Bugtraq report of security issues in 1.6.6

Post by Peripatetic »

Just came across this on Bugtraq:

cmsmadesimple Multiple Security Issues : XSS+ LFI
http://seclists.org/bugtraq/2010/Feb/133

I tried the proof of concept code on my own non-public 1.6.6 installation but couldn't get it to work.  Maybe it only works on a default installation or it's configuration dependent.  I didn't want to file a bug until it can be reproduced.  Can anyone with more in-depth CMSMS knowledge check this out and see if these are real vulnerabilities?
calguy1000
Support Guru
Support Guru
Posts: 8169
Joined: Tue Oct 19, 2004 6:44 pm
Location: Fernie British Columbia, Canada

Re: Bugtraq report of security issues in 1.6.6

Post by calguy1000 »

It's been dealt with, we're waiting for confirmation from the original hacker that the bug is fixed, and then 1.6.7 will be released,.
Follow me on twitter
Please post system information from "Extensions >> System Information" (there is a bbcode option) on all posts asking for assistance.
--------------------
If you can't bother explaining your problem well, you shouldn't expect much in the way of assistance.
User avatar
Peripatetic
New Member
New Member
Posts: 2
Joined: Wed Sep 24, 2008 3:38 pm

Re: Bugtraq report of security issues in 1.6.6

Post by Peripatetic »

Great.  Nice to hear it's been so quickly dealt with.
Wishbone
Power Poster
Power Poster
Posts: 1368
Joined: Tue Dec 23, 2008 8:39 pm

Re: Bugtraq report of security issues in 1.6.6

Post by Wishbone »

What was exploiting this vulnerability supposed to be able to do?
tyman00
Power Poster
Power Poster
Posts: 906
Joined: Tue Oct 24, 2006 5:59 pm

Re: Bugtraq report of security issues in 1.6.6

Post by tyman00 »

We found where the concern came from, but we honestly could not replicate the issue. However, we made a change to be proactive. Once we hear back the confirmation a 1.6.7 will go out.
If all else fails, use a bigger hammer.
M@rtijn wrote: This is a community. This means that we work together and have the same goal (a beautiful CMS), not that we try to put people down and make their (voluntary) job as difficult as can be.
Post Reply

Return to “Developers Discussion”