Welcome, Guest. Please login or register.
March 18, 2010, 06:22:58 PM

Login with username, password and session length
Search:     Advanced search
Wollen Sie dem Website Baker Team beitreten?
Nähere Informationen finden Sie unter hier und auf unserer neuen Webseite .
110391 Posts in 15940 Topics by 9294 Members
Latest Member: net4my
* Home Help Search Login Register
+  WebsiteBaker Community Forum
|-+  General
| |-+  Security Announcements
| | |-+  Security Patch for WB 2.8.0 available
Pages: [1] Go Down Print
Author Topic: Security Patch for WB 2.8.0 available  (Read 10106 times)
FrankH

Offline Offline

Posts: 522


WWW
« on: October 06, 2009, 08:01:56 PM »

A Security related bug has been found in the Website Baker CMS.

Affected systems
    * Only Website Baker version 2.8.0
    * Only installations which have enabled the options to sign in or to change user settings in the frontend

Vulnerability Impact
    * Spamming, annoying and impersonating registered users
    * To protect still unpatched systems, no further details will be published during the next 3 months

Maximum Severity Rating
    * High (for systems matching all of the conditions under the Affected Systems section)
    * None (for all other systems)

Instructions how to patch
  • Just download the patched file attached to this message
  • Unzip this file
  • Replace the file /framework/class.wb.php with the patched version by ftp

Acknowledgements
We want to thank the users Chio, Thorn and Stefek for reporting this bug in an appropriate manner.

Frank Heyne (Website Baker Security Team)

* patch-for-2.8.0.zip (3.97 KB - downloaded 307 times.)
Logged
kweitzel
Forum administrator
*****
Offline Offline

Posts: 5555


WWW
« Reply #1 on: October 07, 2009, 12:43:34 AM »

Dear all,

there was a misconfiguration in the board which prevented everybody from seeing the attachment. This has been changed now, the attachment should be available to every member and visitor of this forum now!

cheers

Klaus
Logged

http://www.weitzel.biz
PM has been disabled
Pages: [1] Go Up Print 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.11 | SMF © 2006-2009, Simple Machines LLC Valid XHTML 1.0! Valid CSS!