The ChangeLog looks a little something like this:
Version 1.1.4.1 "Taga" -- October 07 2007
-----------------
- Fix one issue in adodb_lite that cropped up after release
Version 1.1.4 "Taga" -- October 07 2007
-----------------
- Fixes an XSS issue in the anchor tag
- Fixes an XSS issue in listtags
- Adds a permission check to adduser.php
- More fixes for potential security issues with adodb_lite
- Added a permission check to view the admin log
Sorry for everyone that got 1.1.4. Sometimes we jump the gun a little bit when there is pressure to get a security release out into everyone's hands. It's best that it was on a Sunday (and a holiday in some areas of the world), so hopefully not too many people were affected. If you were, I apologize.
Thanks!
Ted
Announcing CMS Made Simple 1.1.4.1
Re: Announcing CMS Made Simple 1.1.4.1
Hello,
is there any information about the security breaches ? I'd like to know if some filtering rules can prevent them or if there is a way to improve the filter.
Of course I can wait for people having upgraded before exploits are revealed.
Pierre M.
is there any information about the security breaches ? I'd like to know if some filtering rules can prevent them or if there is a way to improve the filter.
Of course I can wait for people having upgraded before exploits are revealed.
Pierre M.
Re: Announcing CMS Made Simple 1.1.4.1
Fantastic! CMS Made Simple just keeps getting better and better.
Props to Ted and the rest of the development team - Safety & security are crucial for content-managed sites, so I can't say enough how greatly I appreciate everyone behind CMSMS taking the time & consideration to address issues and release updates.
Again, fantastic work... keep it up!
Props to Ted and the rest of the development team - Safety & security are crucial for content-managed sites, so I can't say enough how greatly I appreciate everyone behind CMSMS taking the time & consideration to address issues and release updates.

Re: Announcing CMS Made Simple 1.1.4.1
so far so good, but since several days I've installed 1.1.3.1 and filled in a lot of content-pages.Ted wrote: The ChangeLog looks a little something like this:
Version 1.1.4.1 "Taga" -- October 07 2007
-----------------
- Fix one issue in adodb_lite that cropped up after release
What should I do now? Is there any instruction, which files have to be changed, because I'm afraid to destroy my content, my database or installation. On the other hand I like to be update with any security patches.
Re: Announcing CMS Made Simple 1.1.4.1
Knuzen,
the diff-file to go from 1.1.3.1 to 1.1.4.1 is just a file-release, no DB-changes are made. Even if that was the case, the upgrade-script wouldnt destroy content.
After having made a BACKUP, you can just transfer the files of the diff-version over your files and you're on 1.1.4.1.
Ronny
the diff-file to go from 1.1.3.1 to 1.1.4.1 is just a file-release, no DB-changes are made. Even if that was the case, the upgrade-script wouldnt destroy content.
After having made a BACKUP, you can just transfer the files of the diff-version over your files and you're on 1.1.4.1.
Ronny
Re: Announcing CMS Made Simple 1.1.4.1
Ronny,
I didn't see or know about the diff-Upgrade 1.1.3.1 to 1.1.4.1, I'm sorry for that,
I was just a little confused this morning.
Now I have transfered the diff-files over my content and everythings works well, like before,
which makes me glad.
Thanks!
I didn't see or know about the diff-Upgrade 1.1.3.1 to 1.1.4.1, I'm sorry for that,
I was just a little confused this morning.
Now I have transfered the diff-files over my content and everythings works well, like before,
which makes me glad.
