Bug#444928: CVE-2007-5156 remote php file inclusion vulnerability in fckeditor

2007-10-08 Thread Nico Golde
Hi Frank, * Frank Habermann <[EMAIL PROTECTED]> [2007-10-08 23:59]: > thanks for the link! > > Sorry for my mistake. I have tested it again and it works now. I dont know > why > my first test does not work. But that does not matter now. I hope to fix this > tomorrow for stable and for unstable

Bug#444928: CVE-2007-5156 remote php file inclusion vulnerability in fckeditor

2007-10-08 Thread Frank Habermann
Hi, thanks for the link! Sorry for my mistake. I have tested it again and it works now. I dont know why my first test does not work. But that does not matter now. I hope to fix this tomorrow for stable and for unstable. Thanks. Frank pgpUoF7bZhps0.pgp Description: PGP signature

Bug#444928: CVE-2007-5156 remote php file inclusion vulnerability in fckeditor

2007-10-08 Thread Nico Golde
Hi, please also see: http://dev.fckeditor.net/ticket/1325 Kind regards Nico -- Nico Golde - http://ngolde.de - [EMAIL PROTECTED] - GPG: 0x73647CFF For security reasons, all text in this mail is double-rot13 encrypted. pgpaDmAelcLTx.pgp Description: PGP signature

Bug#444928: CVE-2007-5156 remote php file inclusion vulnerability in fckeditor

2007-10-07 Thread Nico Golde
Hi Frank, * Frank Habermann <[EMAIL PROTECTED]> [2007-10-08 00:08]: > this bug does not exists in Knowledgeroot. So it will be closed here. > > 1. The problem in SiteX CMS is that they make it possible to say where to > save > uploaded files bei get parameters. Knowledgeroot does not make this.

Bug#444928: CVE-2007-5156 remote php file inclusion vulnerability in fckeditor

2007-10-07 Thread Frank Habermann
Hi, this bug does not exists in Knowledgeroot. So it will be closed here. 1. The problem in SiteX CMS is that they make it possible to say where to save uploaded files bei get parameters. Knowledgeroot does not make this. 2. The problem that apache will try to interpret unknowl filetypes is a a

Bug#444928: CVE-2007-5156 remote php file inclusion vulnerability in fckeditor

2007-10-01 Thread Nico Golde
Package: knowledgeroot Severity: grave Tags: security Hi, the following CVE (Common Vulnerabilities & Exposures) id was published for knowledgeroot. CVE-2007-5156[0]: | Incomplete blacklist vulnerability in | editor/filemanager/upload/php/upload.php in FCKeditor, as used in | SiteX CMS 0.7.3.beta