Home

New Tech Heroes

New Media and Social Publishing

Navigation

  • Home
  • About
    • Site rules
    • Privacy policy
    • Contact
    • About Tom Kephart
Home

Thought provoking

  • Joomla! 1.5.4 Released
  • Ira Glass on Getting Creative Work Done
  • Get Productive with Social Media (and Stay Sane)
  • What Social Media Does Best
  • Could Your Google Search Indict You?
  • The end of SEO?
  • It's All Too Much
  • 20+ Must-Have WordPress 2.5 Compatible Plugins
more

Tag cloud

Adobe AIR amateurs Apple blog blogger blogging blogs browsers buyout CMS content management development Drupal Facebook Firefox flashback friendfeed funny Gmail Google history Internet Internet Explorer jobs Joomla Mahalo marketing Microsoft new media online Open Source patch Plone privacy radio reputation Safari Scoble security SEO SharePoint SilverStripe social social networking social publishing spam TechCrunch Tom Kephart upgrade venture capital video virtual conversation Vista vulnerability web Web 2.0 web design WordPress Yahoo

vulnerability

JavaScript vulnerability in Drupal prompts 6.1 release

Submitted by Tom Kephart on Wed, 02/27/2008 - 6:43pm.
  • Drupal
  • JavaScript
  • patch
  • upgrade
  • vulnerability

A "moderately critical" ECMAScript/JavaScript vulnerability in Drupal has been fixed in the latest release, version 6.1. All users of the 6.0 version of Drupal are encouraged to patch their current installations or install the complete version 6.1 files.

A potential cross-site scripting (XSS) vulnerability (SA-2008-018) existed in the handling of titles on content edit forms. A JavaScript function used to escape text wasn't working correctly, and is fixed in the latest version.

The legacy 5.x line of Drupal remains at version 5.7, and is not affected by this vulnerability.

Drupal 6.1 is available for download from the main Drupal website.

Bookmark/Search this post with:
  • Delicious
  • Digg
  • StumbleUpon
  • Reddit
  • Magnoliacom
  • Newsvine
  • Google
  • Technorati
  • Icerocket
  • 4 comments

Plone vulnerability being exploited on unpatched installations

Submitted by Tom Kephart on Sun, 02/24/2008 - 7:38pm.
  • AusCERT
  • Doorway Pages
  • patch
  • Plone
  • vulnerability

Trend Micro's Juan Castro reports today that a vulnerability in Plone, discovered in November 2007 by AusCERT, has cropped up on a number of sites. The exploit uses a technique called "Doorway Pages" and redirects visitors to pages that then download malware to the visitor's computer. Castro's analysis is that someone is using the vulnerability discovered by AusCERT as a redirector to hijack traffic and possibly infect computers.

The vulnerability was addressed in Plone's version 3.0.3 and legacy version 2.5.5. If you're using Plone for any of your CMS-based websites, make sure your installation is patched to the current version, which is 3.0.6, or to the latest legacy version, which is 2.5.5.

Bookmark/Search this post with:
  • Delicious
  • Digg
  • StumbleUpon
  • Reddit
  • Magnoliacom
  • Newsvine
  • Google
  • Technorati
  • Icerocket
  • Add a comment

Joomla patches to 1.0.15 to fix a "security vulnerability"

Submitted by Tom Kephart on Fri, 02/22/2008 - 11:20pm.
  • Joomla
  • patch
  • security
  • vulnerability

Open source CMS Joomla issued a security patch for its legacy 1.0.x branch today. The latest version, 1.0.15 (Daytime), addresses a security vulnerability, according to the project's website. All users of 1.0.14 or earlier are encouraged to upgrade to version 1.0.15 as soon as possible.

Joomla also has a newer version available, which is currently at 1.5.1. This site runs on Drupal, but I have other client sites we've built and maintain on Joomla, and I'm planning on upgrading to the 1.5.x branch soon. When I do, I'll include a post describing my impressions of the new version.

Bookmark/Search this post with:
  • Delicious
  • Digg
  • StumbleUpon
  • Reddit
  • Magnoliacom
  • Newsvine
  • Google
  • Technorati
  • Icerocket
  • Add a comment

New Tech Heroes

Editor: Tom Kephart

Grab the RSS feed
or subscribe by email

Add to Technorati Favorites

View Tom Kephart's profile on LinkedIn

Lijit Search


follow TomKephart at http://twitter.com

Popular content

Today's:

  • [flashback] The Spot - lonelygirl15's beach party ancestors
  • Drupal 6.2 release fixes bugs and security issues
  • Wednesday's featured links - March 12, 2008

All time:

  • Drupal issues maintenance upgrade to 5.7
  • Scoble cries; blogosphere freaks; Jesus returns
  • Google Sites: Stone Cold Killa? Perhaps not.

Blogroll

CMS versions

  • Drupal 6.2
    (legacy 5.7)
  • Joomla! 1.5.4
    (legacy 1.0.15)
  • WordPress 2.5.1
    (legacy 2.0.11)
  • Movable Type 4.12
  • Plone 3.1.2
  • CMS Made Simple 1.3.1
  • MODx 0.9.6.1
  • SilverStripe 2.2.2
  • ExpressionEngine 1.6.4
  • Alfresco Community 2.9B
  • Midgard CMS 1.8.8

Creative Commons License

This work is licensed under a Creative Commons Attribution-Share Alike 3.0 United States License.

© 2008 Kephart & Associates, Marine City, Michigan. Our privacy policy.
Powered by Drupal. Customized theme based on Tapestry by RoopleTheme.
Web hosting by pair Networks.

Kephart & Associates