Page 2 of 2 FirstFirst 12
Results 11 to 17 of 17

osCMax Security Update - Arbitrary Upload Exploit

This is a discussion on osCMax Security Update - Arbitrary Upload Exploit within the Announcement Discussions forums, part of the osCmax News and Announcements category; Michael, Thank-you very much for the reply...as I wasn't sure....so if a back up DB was done, on it...and reload ...

      
  1. #11
    Active Member
    Join Date
    Jun 2008
    Posts
    195
    Rep Power
    4


    Default Re: osCMax Security Update - Arbitrary Upload Exploit

    Michael,

    Thank-you very much for the reply...as I wasn't sure....so if a back up DB was done, on it...and reload .2, all would be fine?

    Jim

  2. #12
    osCMax Developer

    michael_s's Avatar
    Join Date
    Jul 2002
    Location
    Phoenix, AZ
    Posts
    19,501
    Rep Power
    567


    Default Re: osCMax Security Update - Arbitrary Upload Exploit

    I do not recommend reinstalling all files. The updated download is primarily for new installs and the only difference is that it removes the insecure files.

    The easiest way to do it would be to just delete the listed files. Second easiest would be to download the new package. Then, delete the FCKeditor dir from your live site, and upload the new FCKeditor dir from the download.

    No installer needed, no messing with the database or any of your other files.
    Michael Sasek
    osCMax Developer


    osCmax installation service - Have our professionals install osCmax on your server - same day service!
    osCmax 2.0 User Manual - the must have beginners guide to osCmax v2.0

    Stay Up To Date with everything osCMax:
    Free osCMax Newsletters - Security notices, New Releases, osCMax News
    osCMax on Twitter - Up to the minute info as it happens. Know it first.

    osCmax Documentation

  3. #13
    New Member
    Join Date
    Aug 2007
    Posts
    14
    Rep Power
    0


    Default Re: osCMax Security Update - Arbitrary Upload Exploit

    I don't seem to be able to create links from images to pages within my site using the FCK editor within the Define Mainpage module since deleting the files/directories recommended to patch this security issue (I'm running osCMax v2.0 RC3-0-1). Has anyone else run into this?

    Bob

  4. #14
    Active Member
    Join Date
    Jun 2008
    Posts
    195
    Rep Power
    4


    Default Re: osCMax Security Update - Arbitrary Upload Exploit

    FWIW, I also ran into a problem...as I was using the CSS-Fluid template.. I left my database, removed the old version, used the new version...and some of it broke...So I reverted back to what I had.... and haven't "messed" with the manual deletion deal as of yet.

    If anything, I think my way of going about it will be process of elimination, and just turning off folder/file permissions....one at a time...check the site after each...and go from there...instead of doing a MASS DELETE, etc.

    Jim

  5. #15
    osCMax Developer

    michael_s's Avatar
    Join Date
    Jul 2002
    Location
    Phoenix, AZ
    Posts
    19,501
    Rep Power
    567


    Default Re: osCMax Security Update - Arbitrary Upload Exploit

    The changes have no effect on define_mainpage or the function of fckeditor. If you are having problems, it is not related to removing the files.

    The files that are removed are never used by osCMax (ever) or any of the fckeditor functions that osCMax uses, so they have no effect on anything other than being a security hole.
    Michael Sasek
    osCMax Developer


    osCmax installation service - Have our professionals install osCmax on your server - same day service!
    osCmax 2.0 User Manual - the must have beginners guide to osCmax v2.0

    Stay Up To Date with everything osCMax:
    Free osCMax Newsletters - Security notices, New Releases, osCMax News
    osCMax on Twitter - Up to the minute info as it happens. Know it first.

    osCmax Documentation

  6. #16
    Active Member
    Join Date
    Jun 2008
    Posts
    195
    Rep Power
    4


    Default Re: osCMax Security Update - Arbitrary Upload Exploit

    Hi Michael, I am just reporting what happened to me..

    1) Using FTP I deleted the DIR that cat was in.

    2) I downloaded the latest, unzipped and wnet thru the install rouitine, using the existing DB still up there.

    I thought about sending you a pm, but didn't want to bother you., but if time permits... I might for the heck of it...do it a again to see if the above process duplicates itself....and report back...as I couldn't figure out what effect it would have, other than I noticed difference in folder names as I reported/questioned earlier.

    Jim

  7. #17
    osCMax Developer

    michael_s's Avatar
    Join Date
    Jul 2002
    Location
    Phoenix, AZ
    Posts
    19,501
    Rep Power
    567


    Default Re: osCMax Security Update - Arbitrary Upload Exploit

    Via FTP, just delete the FCKeditor directory. Then upload the new FCKeditor directory. In my above post I recommended AGAINST doing what you describe. There is NO reason to reinstall the shop.

    All you needed to do was remove the FCKeditor dir, then upload the new FCKeditor dir. That is it, a 2 minute operation.
    Michael Sasek
    osCMax Developer


    osCmax installation service - Have our professionals install osCmax on your server - same day service!
    osCmax 2.0 User Manual - the must have beginners guide to osCmax v2.0

    Stay Up To Date with everything osCMax:
    Free osCMax Newsletters - Security notices, New Releases, osCMax News
    osCMax on Twitter - Up to the minute info as it happens. Know it first.

    osCmax Documentation

Page 2 of 2 FirstFirst 12

Similar Threads

  1. Possible security exploit
    By brendanl79 in forum osCmax v2 Customization/Mods
    Replies: 0
    Last Post: 10-13-2006, 04:11 PM
  2. Security Update HELP
    By inmotion in forum osCmax v1.7 Discussion
    Replies: 0
    Last Post: 05-08-2006, 06:06 PM
  3. osCMax 2.0RC2 Security Patch/Update 051112
    By wilde-uk in forum osCmax v2 Installation issues
    Replies: 5
    Last Post: 04-12-2006, 08:45 PM
  4. osCMax 2.0RC2 Security Patch/Update 051112
    By michael_s in forum Announcements
    Replies: 0
    Last Post: 11-27-2005, 10:12 AM
  5. use bts update,i cant use WYSIWYG upload any picture????????
    By Anonymous in forum osCmax v1.7 Discussion
    Replies: 1
    Last Post: 11-27-2004, 05:08 PM

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •