PHP Web Host - Quality Web Hosting For All PHP Applications $35/month $250/year (Unlimited) - $25/month - 200,000 impressions - Your Ad Could be Here - Click For Details
  Login or Register
 • Home • Downloads • Your Account • Forums • 

View next topic
View previous topic


Google
 
Web RavenPHPScripts (This Site)
Post new topic   Reply to topic
Author Message
PHrEEkie
Subject Matter Expert


Joined: Feb 23, 2004
Posts: 358

PostPosted: Wed Jan 26, 2005 8:09 pm Reply with quote Back to top

A security flaw was found in Menalto Gallery 1.4.4 pl-4.

Info link
Only registered users can see links on this board!
Get registered or login to the forums!


Menalto Gallery wrote:
Several days ago, Rafel Ivgi informed us of a possible cross site scripting (definition) problem in current versions of Gallery. The problem and some similar problems discovered by our team has been addressed in Gallery 2 CVS as well as in this release of 1.4.4-pl5.

As with most other cross site scripting problems, No risk is posed to the webserver itself or any non-Gallery data, but a Gallery install could be compromised using appropriate code.

In addition to the security fix, Gallery 1.4.4-pl5 uses the proper parameters for new versions of ImageMagick and fixes some small issues with PHP 5.

All Gallery users are strongly urged to upgrade to 1.4.4-pl5 immediately, which fixes this problem and will secure your system.

Gallery 1.4.4-pl5 can be downloaded from the
Only registered users can see links on this board!
Get registered or login to the forums!
.


If you use Gallery, please update your software. I've upgraded Menalto before, and it literally only takes a few mins of your time.

PHrEEk
View user's profile Send private message
dean
Worker
Worker


Joined: Apr 14, 2004
Posts: 193

PostPosted: Thu Jan 27, 2005 11:13 am Reply with quote Back to top

Hmm, I just installed gallery last week, the version ported for nuke from nukedgallery.net. Nothing has been said at their site and am wondering, would I be wrong to use the download from the main site like you suggested?
View user's profile Send private message
PHrEEkie
Subject Matter Expert


Joined: Feb 23, 2004
Posts: 358

PostPosted: Thu Jan 27, 2005 4:35 pm Reply with quote Back to top

I don't know what you mean by 'ported', as Menalto Gallery doesn't require a port. You download the filesystem, uncompress to {nuke_root}/modules/gallery and run the install. Upgrading is as simple as downloading the upgrade and overwriting your old filesystem. Version number is maintained in the filesystem, not the DB, so your version will reflect your current filesystem.

Does yours say 1.4.4-pl4 or 1.4.4-pl5?

If it's pl4, your software is vulnerable to the new XSS attack. Download the pl5 upgrade and follow the upgrade instructions.

PHrEEk
View user's profile Send private message
Display posts from previous:       
Post new topic   Reply to topic

View next topic
View previous topic
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
Forums ©
 

All logos and trademarks in this site are property of their respective owner.
The comments are property of their posters, all the rest © 2002-2011 by Raven

You can syndicate our news using the file xml

CSE HTML Validator Helped Clean up This Page! [Valid RSS] valid RSS 2.0 Valid robots.txt Stop Spam Harvesters, Join Project Honey Pot

Website engines core code is © copyright by PHP-Nuke but has been heavily patched and modified by myself and others.
PHP-Nuke is a free software released under the GNU/GPL.


:: fisubice phpbb2 style by Daz :: PHP-Nuke theme by www.nukemods.com ::
:: fisubice Theme Modified by the RavenNuke™ Team ::

:: W3C CSS Compliance Validation :: W3C HTML 4.01 Transitional Compliance Validation ::

zerosum