PDA

توجه ! این یک نسخه آرشیو شده میباشد و در این حالت شما عکسی را مشاهده نمیکنید برای مشاهده کامل متن و عکسها بر روی لینک مقابل کلیک کنید : اصلاحیه امنیتی برای WHMCS 5.x



PersianDOT
October 4th, 2013, 00:23
WHMCS has released new patches for the 5.2 and 5.1 minor releases. These updates provide targeted changes to address security concerns with the WHMCS product. You are highly encouraged to update immediately.

WHMCS has rated these updates as having critical security impacts. Information on security ratings is available at Security Levels - WHMCS Documentation (http://docs.whmcs.com/Security_Levels).


Releases
The following patch release versions of WHMCS have been published to address a specific SQL Injection vulnerability:
v5.2.8
v5.1.10

Security Issue Information

The resolved security issue was publicly disclosed by "localhost" on October 3rd, 2013.
The vulnerability allows an attacker, who has valid login to the installed product, to craft a SQL Injection Attack via a specific URL query parameter against any product page that updates database information.


Mitigation

WHMCS Version 5.2

Download and apply the appropriate patch files to protect against these vulnerabilities.

Patch files for affected versions of the 5.2 series are located on the WHMCS site as itemized below.

v5.2.8 (full version) - Downloadable from the WHMCS Members Area
v5.2.8 (patch only; for 5.2.7) - http://go.whmcs.com/218/v528_Incremental

To apply a patch, download the files indicated above and replace the files within your installation.
No upgrade process is required.

WHMCS Version 5.1

Download and apply the appropriate patch files to protect against these vulnerabilities.

Patch files for affected versions of the 5.1 series are located on the WHMCS site as itemized below.

v5.1.10 (patch only; for 5.1.9) - http://go.whmcs.com/226/v5110_Incremental

To apply a patch, download the files indicated above and replace the files within your installation.
No upgrade process is required.

This Security Advisory is in the process of being emailed to all active license holders.

Updated: 10/3/2013 - 2:46PM CST
- Introduced 5.1 Mitigation

nimafire
October 4th, 2013, 12:15
پست ویرایش شد !!!!!

PersianDOT
October 6th, 2013, 15:47
این اصلاحیه خیلی مهم هست و روش هک کردنش عمومی شده بنابراین هرچه سریعتر این پچ را نصب کنید.

madanchi11
October 6th, 2013, 15:54
سلام

روی نال شدن بزنیم مشکلی پیش نمیاد؟

ممنونم

mil4ni
October 6th, 2013, 16:18
خوشبختانه پچ رو زود منتشر کردند ، طی چند روز گذشته داخل wht.com چند هاستینگ اعلام کردند که با این روش مورد حمله قرار گرفته اند

SniTomb
October 6th, 2013, 23:21
برای 5.2.6 ندادن ؟

mil4ni
October 6th, 2013, 23:29
برای 5.2.6 ندادن ؟

پچ برای هر دو سری 5.1 و 5.2 هست

shivahost
October 6th, 2013, 23:57
برای 5.2.6 ندادن ؟

....