Skip to content
General Revolution Evolution Add-ons International
Login | Register | MODX.com
MODX Open Source Content Management System, Framework, Platform and More.
Find a Partner | Hosts + SaaS | Jobs | Donate
  • RegisterSign Up with the MODX Community
  • LoginUse Your MODX.com Account
  • MODX Community Forums
  • General
  • Security Notices
  •  
  • IMPORTANT: Two new vulnerabilities in 0.9.6.1#

  • 22303
    9,764
    - MODX Chief Architect

    Jason Coward | MODX Chief Architect

    jasoncoward.com | @drumshaman

    opengeek Reply #1, 4 years, 4 months ago

    Reply
    • Link to this post#1
    Please take notice that two security vulnerabilities have been reported and confirmed in 3rd-party scripts that are included in the MODx 0.9.6.1 distributions. Please see http://www.securityfocus.com/archive/1/485707/30/0/threaded for details.

    You need to take immediate action to protect your site( s ).

    For 0.9.6.1 Go to http://svn.modxcms.com/trac/tattoo/changeset/3281 and you can choose from three options for applying the changes to your existing installations: download the zip archive from the link at the bottom (http://svn.modxcms.com/trac/tattoo/changeset/3281?format=zip&new=3281 ) and overwrite your existing files, get the unified diff (http://svn.modxcms.com/trac/tattoo/changeset/3281?format=diff&new=3281 ) and apply as a patch, or apply the diffs detailed on the page manually.

    For 0.9.6 Same as above, though I recommend upgrading to 0.9.6.1 first to make sure you have the latest bug fixes.

    Alternative for 0.9.6 or before... Grab the latest trunk from SVN and upgrade your installation normally.


    Additional information, and an 0.9.6.2 official release with these patches included will be available shortly.


  • 22303
    9,764
    - MODX Chief Architect

    Jason Coward | MODX Chief Architect

    jasoncoward.com | @drumshaman

    opengeek Reply #2, 4 years, 4 months ago

    Reply
    • Link to this post#2
    FYI, trunk has been patched with solutions to both of these security fixes and I will be in the process of notifying all of the reporting services so they publish this information; see the original post for updated information.


  • 25663
    12,071


    Ryan Thrash

    MODX Co-Founder & Leader of Awesomeness




    MODX Revolution

    Your Content, Your Way.


    Issues | Documentation | Git the Source


    Need help? Help us help you.


    rthrash Reply #3, 4 years, 4 months ago

    Reply
    • Link to this post#3
    admin note: clarified for those with feed readers who don't see the entire thread in context

    The current download available at the MODx download site was replaced by a version containing the patches for 0961 in this thread. 0962 will also contain these patches as Jason mentioned. If you've not applied the security patch already (shame on you!), you can either grab it via the instructions listed above or just download the complete installer from the downloads page and install via the normal upgrade mode. If you're not running this latest patched version, now would be a very good time to upgrade.





Actions

Login to Post

Other Support Options

To file a bug or make a feature request visit our issue tracker, or you can also purchase commercial support.

Love MODX?

If you build sites for a living with MODX or just love using it, why not give back?

Information

Posted in this thread:
opengeek, rethrash

 
Back to Top

MODX Global HQ

1333 N Stemmons Fwy, Ste 110
Dallas, TX 75207
United States

+1 (469) 777-MODX (6639)

The MODX Company

  • Contact
  • Media Center
  • Careers at MODX
  • Wall of Fame
  • The MODX Blog

Sponsors

SoftLayer Firehost: Secure Cloud Hosting

Stay Connected

Read our previous email newsletters.

Twitter Facebook Google+ LinkedIn github Feeds

Privacy Policy | Terms of Service | Pixels by AKTA Web Studio© 2005-2012 MODX. All rights reserved. Trademark Policy