กรุณาปิด โปรแกรมบล๊อกโฆษณา เพราะเราอยู่ได้ด้วยโฆษณาที่ท่านเห็น
Please close the adblock program. Because we can live with the ads you see


thxf.org

ข่าว XenForo Media Gallery Security Patch (1.0.1a)

  • ผู้เริ่มหัวข้อ ผู้เริ่มหัวข้อ thxf.org 
  • วันที่เริ่มต้น วันที่เริ่มต้น
We have recently become aware of a security issue relating to a third-party library included with XenForo Media Gallery and have released a patch to resolve this issue. The issue is a cross site scripting (XSS) flaw that could allow an attacker to steal cookies or force a user to take actions without their consent or knowledge (possibly including administrative actions). We recommend all XenForo Media Gallery customers use one of the methods described below to resolve this issue and improve their security.

If you have any questions regarding this patch, please post in the Media Gallery Support forum.

Method 1: Install the Patch

Download the patch zip file attached to the end of this message. It contains 3 files:
  • js/xengallery/media_share.js
  • js/xengallery/ZeroClipboard.swf
  • js/xengallery/min/media_share.js
These 3 files should be uploaded to your server, overwriting the existing files of the same names.

You can confirm that the patch has been applied properly by viewing a media item and looking at the "Share This Media" block. There should be no "copy" buttons next to the text-based sharing options. (Please note that you may have to hard refresh your browser to ensure that cached JS files are not used.)

Method 2: Download XFMG 1.0.1a and upload all files

The version of XenForo Media Gallery has been updated in the customer area to 1.0.1a to indicate that the patch has been applied to the original version of 1.0.1. (Please note that the version number listed in the XenForo control panel will not change. You can confirm that you have downloaded 1.0.1a by looking at the file name of the zip containing the XFMG files.)

The patch can be applied by downloading 1.0.1a from the customer area and acting as if you are upgrading XFMG as normal.

You can confirm that the patch has been applied properly by viewing a media item and looking at the "Share This Media" block. There should be no "copy" buttons next to the text-based sharing options. (Please note that you may have to hard refresh your browser to ensure that cached JS files are not used.)
 

กระทู้ที่คล้ายกัน

  • บทความ บทความ
XenForo Media Gallery 2.3.5 is now available for all licensed customers to download. We strongly recommend that all customers running previous versions of XenForo Media Gallery 2.3 upgrade to this...
ตอบกลับ
0
จำนวนการดู
254
thxf.org 
  • บทความ บทความ
XenForo Media Gallery 2.3.4 is now available for all licensed customers to download. We strongly recommend that all customers running previous versions of XenForo Media Gallery 2.3 upgrade to this...
ตอบกลับ
0
จำนวนการดู
144
thxf.org 
  • บทความ บทความ
Security Fix Today we are advising all customers running XenForo that a potential security vulnerability has been identified. All affected customers should either upgrade to XenForo 2.1.15 or...
ตอบกลับ
1
จำนวนการดู
375
  • บทความ บทความ
Today, we are releasing XenForo 2.2.17 to address a potential security vulnerability. We recommend that all customers running XenForo 2.2 upgrade to 2.2.17 or use the patch instructions below as...
ตอบกลับ
0
จำนวนการดู
470
thxf.org 
thxf.org เพิ่มไฟล์ใหม่: ภาษาไทย XenForo 2.3.0 Media Gallery - ภาษาไทย XenForo 2.3.0 Media Gallery ภาษาไทย XenForo 2.3.x Media Gallery : สวัสดีเพื่อน ๆ XenForo 2.3.x Media Gallery System...
ตอบกลับ
1
จำนวนการดู
257
thxf.org 

กรุณาปิด โปรแกรมบล๊อกโฆษณา เพราะเราอยู่ได้ด้วยโฆษณาที่ท่านเห็น
Please close the adblock program. Because we can live with the ads you see
กลับ
ยอดนิยม ด้านล่าง