Welcome, Guest. Please login or register.
Did you miss your activation email?
May 26, 2012, 01:46:36 PM

Login with username, password and session length
Search:     Advanced search
Wollen Sie dem WebsiteBaker Team beitreten?
Nähere Informationen finden Sie unter hier und auf unserer neuen Webseite.
155538 Posts in 21712 Topics by 7737 Members
Latest Member: deanmacullam
* Home Help Search Login Register
Pages: [1]   Go Down
Print
Author Topic: Security patch for module csvexport - new Version 1.3  (Read 227 times)
FrankH

Offline Offline

Posts: 735


WWW
« on: December 15, 2010, 06:31:52 PM »

Module:      
csvexport

Patched Version:
1.3

Download Link:  
http://www.websitebakers.com/pages/modules/various/csvexport.php

Risks:           
Information disclosure, Elevation of priviledges, Data loss

Description:    
Only installations with different user groups, where at least one group has only write rights to at least one out of many existing pages of this module, are at risk. Wait at least until 15. January 2011 for exact description of the vulnerabilities (until most systems are patched).

Risk level:       
Low if your system does not belong to the group on risk, high otherwise

Suggestions:    
In case your system is at risk (see above) patch it as soon as possible!

Important hint
Most other WB modules are at risk as well, because they contain exactly the same bugs. Ask their authors for a fix if you need it!
If you are an module author, check the source code of your modules!
Error classification: http://cwe.mitre.org/data/definitions/285.html
By the way, it would have been totally unnecessary to patch this small module if the core of WB 2.8 would make a better job when checking the access rights of a user for a page in the backend!
Logged

Ochs und Esel in ihrem Lauf
halt ich leider auch nicht auf
Pages: [1]   Go Up
Print
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.16 | SMF © 2011, Simple Machines Valid XHTML 1.0! Valid CSS!