3002 Hits
Security Alert - please read! Print E-mail
Written by Mambo Foundation Inc.   
Jan 11, 2008 at 02:52 PM

 Urgent 
   Earlier today, Team Mambo was alerted to a security vulnerability in the search component and module that generates a large number of queries if certain strings are input. This creates a major impact on the server's available resources and can lead to the site going down. While we intend to have two new releases out within this next week, the search vulnerability is of enough concern that we have just released a patch.

This vulnerability affects all versions of Mambo. It may also affect other CMS that are based on the Mambo code.

If you are using Mambo 4.5.5, please go here and download the patch file: http://mambo-code.org/gf/download/fr...earchPatch.zip

For all versions of Mambo 4.6, please download this file: http://mambo-code.org/gf/download/frsrelease/298/544/20080110-Mambo46x-SearchPatch.zip

This is not an upgrade. The files contained in the release will overwrite and replace existing files. To install, either unzip locally and upload via ftp, or upload the patch and unzip on your server through your server control panel, such as cPanel.

We urge all Mambo users to apply this patch as soon as possible.

สำหรับท่านที่ใช้แมมโบ้ลายไทย  สามารถใช้ Patch นี้ได้ และรีบทำการอับเดด Patch นี้โดยด่วน!

Last Updated ( Jan 15, 2008 at 06:43 PM )