Subtext Security Issue and Patch

Posted by: youve been HAACKED, on 28 Jul 2009 | View original | Bookmarked: 0 time(s)

A member of the Subtext team discovered a security vulnerability due to our integration with the FCKEditor control as well as the FreeTextBox control. This vulnerability would potentially allow unauthenticated users to upload files using the file upload tools included with these editors. The Fix If youre running the latest version of Subtext (Subtext 2.1.1), the quickest way to patch your installation is to copy the following web.config file <configuration> <system.web> ...

Advertisement
Free Agile Project Management Tool from Telerik
TeamPulse Community Edition helps your team effectively capture requirements, manage project plans, assign and track work, and most importantly, be continually connected with each other.
Category: Security | Other Posts: View all posts by this blogger | Report as irrelevant | View bloggers stats | Views: 907 | Hits: 8

Similar Posts

  • SimplePatch My Patching Tool more
  • Responsible Disclosure, Irresponsible Patching? more
  • CounterSoft Releases Gemini Issue Tracker 3.5 more
  • How to completely process and filter all bounced e-mail messages and get a notification via email when it's completed! more
  • Updating ACS Samples for the March CTP more
  • Running DotNetNuke With Limited SQL Permissions more
  • Vulnerability in Windows Server service Fixed with Update more
  • Subtext 2.1 Released! Contains Security Update more
  • Subtext 2: OpenID Login Support more
  • Upgrading to subtext 2.0-fail more

News Categories

.NET | Agile | Ajax | Architecture | ASP.NET | BizTalk | C# | Certification | Data | DataGrid | DataSet | Debugger | DotNetNuke | Events | GridView | IIS | Indigo | JavaScript | Mobile | Mono | Patterns and Practices | Performance | Podcast | Refactor | Regex | Security | Sharepoint | Silverlight | Smart Client Applications | Software | SQL | VB.NET | Visual Studio | W3 | WCF | WinFx | WPF | WSE | XAML | XLinq | XML | XSD