Rainforest

Sankuru

Implémenter, personaliser, étendre et réparer Joomla/Virtuemart

Views: 1585

Nous vous aidons avec ...

Virtuemart
Joomfish
Autres extensions
SocialTwist Tell-a-Friend

Traduction automatique

English Arabic Chinese (Simplified) German Japanese Russian Spanish



Re-utilisons des sources libres

Les logiciels dont vous avez besoin, éxistent souvent déjà en source libre, et couvrent vos besoins à 80%. Nous ajouterons pour vous les 20% qui manquent.

Devis gratuit

Demandez gratuitement un devis aujourd'hui.

RsMonials security and vulnerabilities PDF Imprimer E-mail
Note des utilisateurs: / 1
MauvaisTrès bien 
Écrit par erik   
Jeudi, 07 Mai 2009 03:46
There are no translations available.

 

On April 13, I wrote the following email to RsWebsols:

 

RsMonials, mods, internationalization & localization FR/NL, security issues

Erik < Cette adresse email est protégée contre les robots des spammeurs, vous devez activer Javascript pour la voir. >     Mon, Apr 13, 2009 at 8:35 PM
To: "Support Team (RS Web Solutions)" < Cette adresse email est protégée contre les robots des spammeurs, vous devez activer Javascript pour la voir. >
Hi

>>    OK, send the script too.

It is your rsmonial scripts but simply i18n.

But then again, I also made a few small changes that just reflect my preferences. You should probably not publish those changes.

Last but not least, I've fixed a few SQL injection and XS scripting attack vulnerabilities too. I would definitely look into them.

I don't write about this in my blog posting about RsMonials, because the accepted convention is not to do that until the author makes a fix available. But then again, the tacic understanding is that in such case the author does effectively fix the vulnerabilities.

Greetings
Erik

 

Unfortunately, RsWebsols did not act upon my email. In the meanwhile, RsMonials has already been reported having vulnerabilities elsewhere.

 

Exploit dissemination sites:

 

Security advisory sites:

 

Concerning the i18n version of RsMonials that can be downloaded at this site:

  • I have fixed (probably) all the SQL injection vulnerabilities. (They are seriously worse and more dangerous than the XS Scripting issues!)
  • If you do not publish testimonials automatically, you should not be affected by the XS Scripting issues;
  • I did not meticulously fix all the XS Scripting issues, because it is the responsibility of the original author to spend time doing that;
  • So, even with the i18n version, do not publish testimonials automatically, and you should be ok.

 

 


blog comments powered by Disqus
 
 
Joomla 1.5 Templates by Joomlashack