Subtext Security Issue and Patch
Posted by: youve been HAACKED,
on 28 Jul 2009 |
View original | Bookmarked: 0 time(s)
A member of the Subtext team discovered a security vulnerability due to our integration with the FCKEditor control as well as the FreeTextBox control. This vulnerability would potentially allow unauthenticated users to upload files using the file upload tools included with these editors. The Fix If youre running the latest version of Subtext (Subtext 2.1.1), the quickest way to patch your installation is to copy the following web.config file <configuration>
<system.web>
...