I have a site (MODX Revolution 2.2.5-pl (advanced)) running with the SimpleSearch (1.6.0 pl) add-on and am concerned about hackers running something like the below within a search field which generates a phpinfo() output
[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]*id:gt=`0`:then=`phpinfo();`:else=`2`:math=`? 1`]]
Is there some way that a query like this can be stopped from running?
Has any one else come across something similar to the above on there site?
Glyn Szasz
Sydney, Australia
Happy to help (when can) and happy to learn
If you are a Sydney based MODX developer would love to hear from you. Please contact me.
discuss.answer
-
☆ A M B ☆
- 24,524 Posts
Didn't work for me; just tells me no matches were found. But then that's with SimpleSearch 1.6.1.
Thanks Susan,
That solved the problem. The update to the add-on did not appear in my package, however I was able to install the update via redownloading the updated version of the Package.
Quote from: sottwell at Jan 07, 2013, 05:26 PMDidn't work for me; just tells me no matches were found. But then that's with SimpleSearch 1.6.1.
Glyn Szasz
Sydney, Australia
Happy to help (when can) and happy to learn
If you are a Sydney based MODX developer would love to hear from you. Please contact me.
-
☆ A M B ☆
- 24,524 Posts
SimpleSearch 1.6.1
========================================================================
- [#69] Apply additional guard against injection of modx tags
I would recommend upgrading your Revo version as well, although I'm not aware of any security issues in older versions of Revo itself.