Hello Community,
probably all TemPlug templates suffer an arbitrary code execution vulnerability. I've checked that for tp_3cols_avantgardeXH, but other TemPlug templates are most likely affected as well.
I have PMed Gert 2 weeks ago, but he has not yet replied. I suggest you immediately contact him for a fix. I will not publicly reveal any details, let alone the exploit I've written to confirm this issue. You can contact me by mail or PM for further information.
Christoph
TemPlug Templates: Arbitrary Code Execution Vulnerability
TemPlug Templates: Arbitrary Code Execution Vulnerability
Christoph M. Becker – Plugins for CMSimple_XH
Re: TemPlug Templates: Arbitrary Code Execution Vulnerabilit
Download new and update the folder "templug/", but without the folder "templug/data/",
Gert
Gert
Re: TemPlug Templates: Arbitrary Code Execution Vulnerabilit
I don't find a link to the updated Templug.
Where is it?
(1.4 is from january 25th 2012)
Where is it?
(1.4 is from january 25th 2012)
Re: TemPlug Templates: Arbitrary Code Execution Vulnerabilit
http://www.ge-webdesign.de/cmsimpletemplates/?TemPlug
You have to update the templates, not the plugin,
Gert
You have to update the templates, not the plugin,
Gert
Re: TemPlug Templates: Arbitrary Code Execution Vulnerabilit
Ah, thank you. I am trying out tp_float_treesXH.zip - but it was not updated (it is from 27 march 2013).Gert wrote:http://www.ge-webdesign.de/cmsimpletemplates/?TemPlug
You have to update the templates, not the plugin,
Re: TemPlug Templates: Arbitrary Code Execution Vulnerabilit
It IS updated - I have updated all templates on 27 march 2013,MiHa wrote:but it was not updated (it is from 27 march 2013).
Gert
Re: TemPlug Templates: Arbitrary Code Execution Vulnerabilit
Great news!
I got started on the new CMSimple 4 on or right after march 27, then =)
I was on the old CMSimple a long time ago for a NGO ( www.hemundervisning.org ), and recently needed more - SO happy about the progress you are making!
I got started on the new CMSimple 4 on or right after march 27, then =)
I was on the old CMSimple a long time ago for a NGO ( www.hemundervisning.org ), and recently needed more - SO happy about the progress you are making!
Re: TemPlug Templates: Arbitrary Code Execution Vulnerabilit
"On" or "right after"?MiHa wrote:I got started on the new CMSimple 4 on or right after march 27, then =)
I have uploaded the new zip files 2 pm in the afternoon, but in case "right after march 27" you have the new template surely,
Gert