Register | Forget Password | Login
Search :
SecurityReason

News

Search

SecurityAlert

About SecurityAlert

ExploitAlert

SecurityReason Research

WLB

WLB Database

Send to WLB

About WLB

RSS

News

SecurityAlert

World Laboratory of Bugtraq

ExploitAlert

Apache

PHP

Corporate

Contact

About us

Services

SecurePHP

Note

If you have found a vulnerability, please send to our SecurityAlert Database :
secalert()securityreason()com

Also if you have new ( 0-day ) exploit, please send to our ExploitAlert Archive :
exploit()securityreason()com

News from: Programs

» Topic:  PostNuke 0.760 released

» Added by:  cXIb8O3

» Date:  17.9.2005

  The PostNuke team are pleased to announce the availablity of PostNuke 0.7.6.0, a major milestone realized on the road to 1.0. This release features significant enhacements to the .7x range of releases in addition to containing a significant number of modules taken directory from the .8x codebase.

If performing an upgrade please review manual.txt carefully. Many of the core system modules (blocks, modules etc.) are upgraded in this release so the process needs to be followed carefully.

Links

* Download: http://news.postnuke.com/Downloads-req-viewdownload-cid-1.html
* Support: http://forums.postnuke.com

Summary of Main Changes
Further cleaning of HTML

* pn-normal custom class removed in favor of styling of block level element using CSS
* pn-pagetitle class replaced by use of h1 tag
* pn-title class replaced by use of h2 tag
* all fake lists created using middot's replaced with proper lists

Simplication of non API compliant links

op=modload & file=index are the defaults so these are removed from all links
New printer (Xanthia) theme - enables printable view of any page

A printable view of any page is available using the printer theme. Append the url theme=Printer to the url or build a 'print me' button into your theme.
Removal of NS- prefix on all modules

All modules that contained the NS- prefix in the directory name have had this removed. This prefix is a result of our origins in php-nuke.
Baseline security analyzer
This new feature adds a check for some of the more basic configuration settings that can enhance the security of a PostNuke installation.
New features in core

* Modules can now be referenced using an 'alias' via the module display name setting.
* Default start function type, function name & parameters to the function can be defined. Note: API compliant modules only.
* Standard database connection error moved to a 'template' in includes/templates.
* Ability to turn the site off for maintainence (access to provided via permissions setting).
* Smarty updated to v2.6.10.
* ADODB updated to v4.6.5.

Modules

Admin_Messages, Modules, Blocks, Permissions, Groups, legal, Censor, Messages, Ephemerids, Quotes, Autolinks, AvantGo, Credits, Members_List, Ratings & Admin have been updated for full API compliance and templated output.

New modules

* Sniffer; Detects browser and browser capabilities using phpSniff (by Roger Raymond).
* RSS; Replaces dated feed handling with an xml based parser (magpie rss).

Bug fixes

* Xanthia - many fixes since original release.
* Mailer (added support for additional headers, bcc's & cc's), fixed sending to multiple addresses.

New features in modules (in addition to API compliance and templated output)

Modules module

* filter by letter, state
* graphical indicatator of state
* detection of change of type, admin & user capability
* ability to recover from missing files state

Blocks

* graphical indicatator of state
* ability to define each block as collaspable (credit to Mark Heldstab)
* ability to define each blocks' default collapseable state (credit to Mark Heldstab)

Others

* Groups - ability to add multiple users to a group in one go
* legal - added template accessibility report (thanks to http://diveintoaccessibility.org)
* Censor - added transfrom hook for censor module (supercedes pnVarCensor API - maintained for backwards compatability)
* Admin - added ability to split modules into categories, the categories view are skinable via a single stylesheet
* Credits



Alert

*BSD libc (strfmon) Multiple vulnerabilities

high- 2008-03-25

Maksymilian Arciemowicz discovered a Integer Overflow vulnerability in the libc library "strfmon()" function.A vulnerability could allow an attacker who successfully exploits this vulnerability to take control of the affected *BSD systems.

Apache rss

» Apache Tomcat <=
   6.0.18 UTF8 Directory
   Traversal Vulnerability

» Apache Tomcat information
   disclosure vulnerability

» Apache Tomcat XSS
   vulnerability

» Apache-SSL memory
   disclosure

PHP rss

» PHP 5.2.6 chdir(),ftok()
   (standard ext) safe_mode
   bypass

» PHP 5.2.6 posix_access()
   (posix ext) safe_mode
   bypass

» PHP 5.2.5 and prior :
   *printf() functions
   Integer Overflow

» PHP 5.2.5 cURL safe_mode
   bypass

Copyright © SecurityReason. All Rights Reserved.