PhotoPost Photo Gallery Sales PhotoPost Sales Toll Free Phone Number
Mon-Fri 9am-4pm EST
  PhotoPost Photo Sharing Photo Gallery    Visualize community tm
| | | | | | | | |

Go Back   PhotoPost Community > PhotoPost Support > PhotoPost Pro Support Forums > Photopost Pro How Do I...?

Photopost Pro How Do I...? Wondering how to do things in PhotoPost?

Reply
 
LinkBack Thread Tools Rate Thread Display Modes
Old September 26th, 2006, 12:43 PM   #1 (permalink)
Member
Verified Customer
 
Join Date: May 2004
Posts: 35
Security Issue??

any official word on this?

Quote:
Source: National Cyber-Alert System
Vulnerability Summary CVE-2006-4990
Original release date: 9/25/2006
Source: US-CERT/NIST


This vulnerability is currently undergoing analysis and not all information is available.
Please check back soon to view the completed vulnerability summary.


Overview

Multiple PHP remote file inclusion vulnerabilities in PhotoPost allow remote attackers to execute arbitrary PHP code via a URL in the PP_PATH parameter in (1) addfav.php, (2) adm-admlog.php, (3) adm-approve.php, (4) adm-backup.php, (5) adm-cats.php, (6) adm-cinc.php, (7) adm-db.php, (8) adm-editcfg.php, (9) adm-inc.php, (10) adm-index.php, (11) adm-modcom.php, (12) adm-move.php, (13) adm-options.php, (14) adm-order.php, (15) adm-pa.php, (16) adm-photo.php, (17) adm-purge.php, (18) adm-style.php, (19) adm-templ.php, (20) adm-userg.php, (21) adm-users.php, (22) bulkupload.php, (23) cookies.php, (24) comments.php, (25) ecard.php, (26) editphoto.php, (27) register.php, (28) showgallery.php, (29) showmembers.php, (30) useralbums.php, (31) uploadphoto.php, (32) search.php, or (33) adm-menu.php, different vectors than CVE-2006-4828.


References to Advisories, Solutions, and Tools

External Source: BUGTRAQ (disclaimer)

Name: 20060918 PhotoPost PHP 4.6 - 4.5 [PP_PATH] >> Remote File Include Vulnerability

Hyperlink: http://www.securityfocus.com/archive...100/0/threaded


Technical Details

CVE Standard Vulnerability Entry:
http://cve.mitre.org/cgi-bin/cvename...=CVE-2006-4990
mkdevo is offline   Reply With Quote
Old September 26th, 2006, 01:02 PM   #2 (permalink)
PhotoPost Developer
Verified Customer
 
Join Date: Jan 2002
Posts: 11,834
It's the same report getting recirculated every few months on a very old version of PhotoPost.

PhotoPost 4.6 was released back in 12/2003 - almost three years ago (and there have been many releases since that time); if you are running any version prior to 5.1, then you should upgrade to the latest code.
__________________
Please do not PM me for support or sales questions. Thank you for your understanding.
Michael P is offline   Reply With Quote
Old September 26th, 2006, 10:15 PM   #3 (permalink)
Member
Verified Customer
 
mtha's Avatar
 
Join Date: May 2005
Location: OK, US
Posts: 107
Send a message via Yahoo to mtha
Quote:
Originally Posted by Michael P View Post
It's the same report getting recirculated every few months on a very old version of PhotoPost.

PhotoPost 4.6 was released back in 12/2003 - almost three years ago (and there have been many releases since that time); if you are running any version prior to 5.1, then you should upgrade to the latest code.
... there're many releases since that time, doesnt alway mean it is fixed.

just want to confirm if those mentioned vulnerabilities holes were fixed on the current version?
mtha is offline   Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
Security issue? d3nnis Photopost Pro Installation & Upgrades 2 January 17th, 2006 08:08 PM
ReviewPost Security WB ReviewPost Bug Reports 24 August 22nd, 2005 08:05 AM
Security Announcement: PhotoPost Immune from EXIF PHP Security Flaw Michael P General Discussion 0 December 22nd, 2004 08:10 AM
Security ? NotInUse General Discussion 1 August 10th, 2004 11:39 PM


All times are GMT -5. The time now is 10:07 PM.

Powered by vBulletin® Version 3.8.1
Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Search Engine Friendly URLs by vBSEO 3.2.0