Geeklog France

Open Source Content Management System

Geeklog 1.5.2sr2

Nouvelle faille de sécurité et nouvelle security release Geeklog 1.5.2sr2 pour les versions 1.5.0 à 1.5.2.



Bookoo of the Nine Situations Group posted an SQL injection exploit for glFusion that also works with Geeklog. This issue allowed an attacker to extract the password hash for any account and is fixed with this release. Please note that this problem exists in all Geeklog versions prior to 1.5.2sr2.

You can download an upgrade archive for Geeklog 1.5.2sr1 or the complete 1.5.2sr2 tarball to upgrade from any previous version.

The upgrade tarball contains only one file (a drop-in replacement for lib-sessions.php) and can also be used to fix the issue on Geeklog 1.4.1, 1.5.0, and 1.5.1.

As a temporary measure (and to secure older Geeklog releases that are not supported any more), you can also make the following configuration change, at the risk of inconveniencing some of your users:

In Geeklog 1.5.x, go to Configuration > Geeklog > Miscellaneous > Cookies and change the option "Cookies embed IP?" to "True". On older Geeklog releases, open your config.php file, find the option $_CONF['cookie_ip'] and change the value to = 1; (from = 0). The downside of this configuration change is that the long-term cookie won't work any more for users with changing IP addresses, i.e. they will have to log in again more often.

 

 

Geeklog 1.5.2sr2
commentaires (0)
Les commentaires permettent à chacun d'enrichir le web.

Trackback

URL de Trackback : http://geeklog.fr/trackback.php/Geeklog-1.5.2sr2

Aucun Trackback pour l'instant.

Demo Random Product

Product test 2

Product test 2 | 94.51 EUR

Demo paypal cart

Votre panier (0 article)

Votre panier est vide!

0.00 EUR

Catégories

GeekLog (29)
Plugins (33)
Thèmes (11)

Espace Membre

What's new

COMMENTAIRES

Aucun

MEDIA GALLERY Last 14 Days

No new media items

No new media comments

NEW FILES last 14 days

En ligne

Visiteurs: 8