|
Freitag, 03 Juni 2005 |
|
Dieser Patch behebt eine bekannt gewordene Sicherheitslücke von Mambo. Zur Installation einfach die vorhandenen Dateien durch die des Patches ersetzen.
-------------------- 4.5.2.2 Patch Released ----------------------
04-May-2005 Andrew Eddie
# Fixed vulnerability with bind method in mosDBTable class
# Fixed session id spoofing via administrator/index3.php
# Fixed bug in mosAbstractTasker redirect method
# Prevented attacks via injection of POST variables through GET
# Fix injection bugs in various class 'check' methods
+ Added input filter class (replacement for built-in strip tags)
- Removed vulnerable file in DOMIT library
4-Mar-2005 Rey Gigataras
# Fixed [#4642] Can't login to ADMINISTATION
# Fixed [#4768] emailCloaking() doesn't completely combine parts of mail address
# Fixed [#4972] Truncated email address in Contacts
# Fixed [#4607] admin.typedcontent.php missing $lists['_caption_align'] initialisation code
# Fixed [#4610] MOSimage doesn't work in static content manager
# Fixed [#4586] `List Length` is ignored
|