Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Editor Blogs > Security

December 21st, 2011, 09:31 GMT · By Eduard Kovacs

BLOG

XSS Vulnerabilities Fixed in Fork CMS 3.1.7

SHARE:

Adjust text size:

Fork CMS admin dashboard Enlarge picture - Fork CMS admin dashboard
Multiple reflective cross-site scripting (XSS) vulnerabilities were found in the 3.1.5 version of Fork CMS, the open-source PHP and MySQL content management system.

The flaws, tested on Windows XP and Windows Vista using Internet Explorer 9, were present in both the front end and the administrator panel.

In the 3.1.7 variant some changes were made in the form.php file found in the backend, the frontend and the library folders. The header.php file from the frontend is also modified to make sure XSS attacks are no longer possible.

The security holes were uncovered by Avram Marius Gabriel (d3vil) on December 13 and they were patched up the next day.

Users are advised to update Fork CMS to the latest variant to make sure they don’t allow cybercriminals to execute arbitrary code.

Fork CMS 3.1.7 is available for download here.
FILED UNDER:
CMS
XSS
security update

TELL US WHAT YOU THINK:

758 hits · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


Adobe Closes Security Holes with the Release of Reader and Acrobat 9.4.7

Advanced Onion Router 0.3.0.5 Fixes Buffer Overflow and More

Pidgin 2.10.1 Fixes Denial-of-Service Vulnerabilities

Google Chrome 16 Comes with 15 Security Fixes

Microsoft Releases December Security Updates, Fix for Duqu Vulnerability Included

READER COMMENTS:



No user comments yet.
Be the first to express your opinion!
Copyright © 2001-2012 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM