กรุณาปิด โปรแกรมบล๊อกโฆษณา เพราะเราอยู่ได้ด้วยโฆษณาที่ท่านเห็น
Please close the adblock program. Because we can live with the ads you see


thxf.org

ข่าว XenForo Media Gallery 1.0.10 Released (Security Fix)

In order to apply the security fix included in XenForo 1.4.13 or 1.5.10 to XenForo Media Gallery 1.0, XenForo Media Gallery 1.0.10 has been released.

This fixes the server-side request forgery (SSRF) security issue. This could allow an attacker to use your server to bypass your server's firewall and make internal requests. Depending on the services found, this could lead to privilege escalation or remote code execution.

This is a potentially serious issue and we strongly recommend all customers running XenForo Media Gallery 1.0 follow one of the below methods to fix this security issue. You must also follow the instructions in the XenForo 1.4.13 or 1.5.10 release announcements for this patch to be effective.

Please note that XenForo Media Gallery 1.1.5 and newer will automatically be secured from this issue if you follow the instructions in the XenForo 1.5.10 release announcement.

If you have any questions relating to installing this patch or upgrading to the new version, please post in the Media Gallery Support forum.

Method 1: Upgrade to the New Version (Recommended)

The security fix can be applied by downloading XenForo Media Gallery 1.0.10 from your customer area and upgrading XenForo Media Gallery as normal.

You must also follow the instructions in the XenForo 1.4.13 or 1.5.10 release announcements to fully fix this issue.

Method 2: Install the Patch

Download the patch zip file attached to the end of this message. It contains 4 files:
  • library/XenGallery/Helper/String.php
  • library/XenGallery/Model/File.php
  • library/XenGallery/Thumbnail/Abstract.php
  • library/XenGallery/ViewPublic/Media/PreviewVideo.php
These 4 files should be uploaded to your server, overwriting the existing files of the same names.

You must also follow the instructions in the XenForo 1.4.13 or 1.5.10 release announcements to fully fix this issue.

Note that with this method there is no outward indication that the patch has been applied. We recommend upgrading if possible.
 

ไฟล์แนบ

  • xfmg_patch_1010.zip
    xfmg_patch_1010.zip
    9.7 กิโลไบต์ · จำนวนการดู: 296

กระทู้ที่คล้ายกัน

  • บทความ บทความ
Today, we are releasing XenForo 2.2.17 to address a potential security vulnerability. We recommend that all customers running XenForo 2.2 upgrade to 2.2.17 or use the patch instructions below as...
ตอบกลับ
0
จำนวนการดู
470
thxf.org 
  • บทความ บทความ
XenForo Media Gallery 2.3.5 is now available for all licensed customers to download. We strongly recommend that all customers running previous versions of XenForo Media Gallery 2.3 upgrade to this...
ตอบกลับ
0
จำนวนการดู
254
thxf.org 
  • บทความ บทความ
XenForo Media Gallery 2.3.4 is now available for all licensed customers to download. We strongly recommend that all customers running previous versions of XenForo Media Gallery 2.3 upgrade to this...
ตอบกลับ
0
จำนวนการดู
144
thxf.org 
  • บทความ บทความ
Security Fix Today we are advising all customers running XenForo that a potential security vulnerability has been identified. All affected customers should either upgrade to XenForo 2.1.15 or...
ตอบกลับ
1
จำนวนการดู
375
  • บทความ บทความ
XenForo 2.3.5 is now available for all licensed customers to download. We strongly recommend that all customers running previous versions of XenForo 2.3 upgrade to this release to benefit from...
ตอบกลับ
0
จำนวนการดู
268
thxf.org 

กรุณาปิด โปรแกรมบล๊อกโฆษณา เพราะเราอยู่ได้ด้วยโฆษณาที่ท่านเห็น
Please close the adblock program. Because we can live with the ads you see
กลับ
ยอดนิยม ด้านล่าง