| Quote:: |
| #8 --- After installing, delete install.php and the /install directory! |
| Code:: |
|
| Code:: |
|
| PHP: |
|
| Jeruvy wrote: |
| Yes, the install.php is mandatory. The error.php and/or the malicious upload can cause the exploit. Sorry I wasn't clearer. |
| Code:: |
|
| Jeruvy wrote: |
| Just to add...a good idea would be in cmsinit.ini to check for the presence of the install dir, and load a page instead of main to remind the user to delete this. Prevent them from using the site proper while it exists. |
| DJMaze wrote: | ||
| Here are the official 9.0.6.1 SF1 branch files: dragonflycms.org/cvs/h...hp?b=9.6.2 dragonflycms.org/cvs/h...p?b=9.12.2 dragonflycms.org/cvs/h...p?b=9.15.2 dragonflycms.org/cvs/h...p?b=9.19.2 To get the full branch use:
[edit] Also added a previous found XSS fix in there [/edit] |
All times are GMT