Security issue in AdvancedForm and AdvancedNews Plugins

A place for security related announcements and discussions - please check this forum frequently!
Post Reply
Holger
Site Admin
Posts: 2813
Joined: Mon May 19, 2008 7:10 pm
Location: Hessen, Germany
Contact:

Security issue in AdvancedForm and AdvancedNews Plugins

Post by Holger » Wed Sep 08, 2010 8:47 pm

Security issue in AdvancedForm and AdvancedNews Plugins by jat-at-home.be

There's a potential security issue in the two popular plugins
Advanced Form and Advanced News.

The problem is in both, the freeware and the payware, versions of that plugins included.

Updating or deleting all installations is highly recommended!
If you not use the plugins anymore you must delete the files from the server!
It's not enough to delete the scripting-calls from the content or the template!

For the most used freeware versions we can provide a "quick fix":

Advanced News 1.0.4: download fix
Advanced Form 1.6.4: download fix

If you use a plugin with this version, you can fix the issue by overwriting the files on your server
with the files in the downloads above. But be sure to have the right version installed
(and a backup on your harddisk ;-) ).

Another way is updating to a newer version. JAT provides new free downloads at his homepage.
Please check http://jat-at-home.be/index.php?CMSimple_plugins for details.

Users of the payware-versions should receive updates from the author. Beside this the newest (former payware) versions
become available as free GPL - versions ASAP at http://www.cmsimplewiki.com.

At this point we want to thank Jan Kanters (JAT) for his help and cooperation and, last but not least,
for giving his plugins for free under the GPL to the community!


Holger

Tata
Posts: 2690
Joined: Tue May 20, 2008 5:34 am
Location: Slovakia
Contact:

Re: Security issue in AdvancedForm and AdvancedNews Plugins

Post by Tata » Wed Mar 06, 2013 5:07 am

Holger wrote:Advanced News 1.0.4: download fix
Advanced Form 1.6.4: download fix
Both links repor "404". The same on Wiki.
CMSimple.sk
It's no shame to ask for an answer if all efforts failed.
But it's awful to ask without any effort to find the answer yourself.

cmb
Posts: 12598
Joined: Tue Jun 21, 2011 11:04 am
Location: Mü-Sa, RLP, DE
Contact:

Re: Security issue in AdvancedForm and AdvancedNews Plugins

Post by cmb » Wed Mar 06, 2013 11:32 am

Seems Jan's website has been sold. I've uploaded both plugins (the versions that were offered on Jan's website most recently) to the wiki (http://cmsimplewiki.com/doku.php/plugins/advanced_news resp. http://cmsimplewiki.com/doku.php/plugin ... anced_form).
Christoph M. Becker –Plugins for CMSimple_XH, but not for CMSimple 4+

Post Reply