Just came across this on Bugtraq:
cmsmadesimple Multiple Security Issues : XSS+ LFI
http://seclists.org/bugtraq/2010/Feb/133
I tried the proof of concept code on my own non-public 1.6.6 installation but couldn't get it to work. Maybe it only works on a default installation or it's configuration dependent. I didn't want to file a bug until it can be reproduced. Can anyone with more in-depth CMSMS knowledge check this out and see if these are real vulnerabilities?
Bugtraq report of security issues in 1.6.6
- Peripatetic
- New Member
- Posts: 2
- Joined: Wed Sep 24, 2008 3:38 pm
-
- Support Guru
- Posts: 8169
- Joined: Tue Oct 19, 2004 6:44 pm
- Location: Fernie British Columbia, Canada
Re: Bugtraq report of security issues in 1.6.6
It's been dealt with, we're waiting for confirmation from the original hacker that the bug is fixed, and then 1.6.7 will be released,.
Follow me on twitter
Please post system information from "Extensions >> System Information" (there is a bbcode option) on all posts asking for assistance.
--------------------
If you can't bother explaining your problem well, you shouldn't expect much in the way of assistance.
Please post system information from "Extensions >> System Information" (there is a bbcode option) on all posts asking for assistance.
--------------------
If you can't bother explaining your problem well, you shouldn't expect much in the way of assistance.
- Peripatetic
- New Member
- Posts: 2
- Joined: Wed Sep 24, 2008 3:38 pm
Re: Bugtraq report of security issues in 1.6.6
Great. Nice to hear it's been so quickly dealt with.
Re: Bugtraq report of security issues in 1.6.6
What was exploiting this vulnerability supposed to be able to do?
Re: Bugtraq report of security issues in 1.6.6
We found where the concern came from, but we honestly could not replicate the issue. However, we made a change to be proactive. Once we hear back the confirmation a 1.6.7 will go out.
If all else fails, use a bigger hammer.
M@rtijn wrote: This is a community. This means that we work together and have the same goal (a beautiful CMS), not that we try to put people down and make their (voluntary) job as difficult as can be.