XOOPS 2.2.5 Security Fix Release

Date 2007/12/22 2:35:47 | Topic: XOOPS

An XSS vulnerability in XOOPS 2.2* was reported by Omer Singer from The Digi Trust Group, LLC.

All XOOPS 2.2* users are urged to apply the attached patch.

Implementation Guide:
Step 1: uncompress the package
Step 2: upload the /html/class/xoopsform/form.php file to your XOOPSROOT/class/xoopsform/

Note:
1 XOOPS 2.2.6 RC is released at the same time with a more comprehensive solution. Do NOT apply this patch if you use 2.2.6 RC package instead.
2 XOOPS 2.0* sites are not affected directly, however the relevant improvements have been available in XOOPS 2.0.18 RC.

Download: xoops-2.2.5-security.tar.gz | xoops-2.2.5-security.zip


This article comes from XOOPS Web Application System
https://xoops.org

The URL for this story is:
https://xoops.org/modules/news/article.php?storyid=4073