Kepada rakan-rakan blogger dan pemilik portal, sila ambil prhatian maklumat keselematan ini bagi mengelak blog (self hosting) dan portal anda menjadi mangsa serangan penggodam.
Pastikan anda sentiasa menukar kata laluan kepada akses hostingĀ sekurang-kurangnya setiap 90 hari.
Sila kemaskini atau patch sistem keselamatan laman web anda dan ambil perhatian kepada plugin/widget yang berisiko seperti dibawah:
June 30th, 2012
Application: WordPress
Affected Version: version 3.0.1 and other versions.
Vendorās URL: Google Maps Via Store Locator Plus Plugin
Bug Type: SQL Injection & Path Disclosure
Risk Level: Critical
Solution:
Restrict access to the wp-content/plugins/store-locator-le/core/load_wp_config.php file (e.g. via .htaccess). Edit the source code to ensure that input is properly sanitised.
WordPress HTML5 AV Manager Plugin Arbitrary File Upload
June 30th, 2012
Application: WordPress
Affected Version: version 0.2.7 and other versions.
Vendorās URL: HTML5 AV Manager Plugin
Bug Type: File Upload
Risk Level: Critical
Solution:
Restrict access to the wp-content/plugins/html5avmanager/lib/uploadify/custom.php file (e.g. via .htaccess).
June 30th, 2012
Application: WordPress
Affected Version: version 0.2 and other versions.
Vendorās URL: Asset Manager Plugin
Bug Type: File Upload
Risk Level: Critical
Restrict access to the wp-content/plugins/asset-manager/upload.php file (e.g. via .htaccess).
June 30th, 2012
Application: WordPress
Affected Version: version 0.4.2.1 and other versions.
Vendorās URL: FoxyPress Plugin
Bug Type: File Upload
Risk Level: Critical
Update to version 0.4.2.2.
Affected Version: version 1.1.3 and other versions.
Vendorās URL: Thinkun Remind Plugin
Bug Type: File Inclusion
Risk Level: CriticalSolution:
Edit the source code to ensure that input is properly verified.
Affected Version: version 1.0 and other versions.
Vendorās URL: Simple Download Button Shortcode Plugin
Bug Type: File Disclosure
Risk Level: CriticalSolution:
Edit the source code to ensure that input is properly verified.
Affected Version: version 2.1 and other versions.
Vendorās URL: RBX Gallery Plugin
Bug Type: File Upload
Risk Level: CriticalSolution:
Restrict access to the wp-content/plugins/rbxgallery/uploader.php file (e.g. via .htaccess).
Affected Version: version 2.1.0 and prior versions.
Vendorās URL: Top Quark Architecture Plugin
Bug Type: File Upload
Risk Level: CriticalSolution:
Update to version 2.1.1.
Affected Version: version 1.1.0 and other versions.
Vendorās URL: Easy Contact Forms Export Plugin
Bug Type: File Disclosure
Risk Level: CriticalSolution:
Edit the source code to ensure that input is properly verified.
Affected Version: version 2.5.29 and prior versions.
Vendorās URL: wpStoreCart Plugin
Bug Type: File Upload
Risk Level: CriticalSolution:
Update to version 2.5.30.
Affected Version: version 1.3 and other versions.
Vendorās URL: Nmedia Member Conversation Plugin
Bug Type: File Upload
Risk Level: CriticalSolution:
Restrict access to the /wp-content/plugins/wordpress-member-private-conversation/doupload.php script (e.g. via .htaccess).
Affected Version: version 1.2.4 and other versions.
Vendorās URL: Font Uploader Plugin
Bug Type: File Upload
Risk Level: CriticalSolution:
Edit the source code to ensure that input is properly verified.
Affected Version: versions prior to 6.4.0.
Vendorās URL: SugarCRM
Bug Type: Code Execution
Risk Level:Solution:
Update to version 6.4.0 or later.
Affected Version: version 1.11 and prior versions.
Vendorās URL: SS Quiz Plugin
Bug Type: Cross Site Scripting and Security Bypass
Risk Level: CriticalSolution:
Update to version 1.12.
Affected Version: version 1.4 and other versions.
Vendorās URL: Hupsi Fancybox Plugin
Bug Type: File Upload
Risk Level: CriticalSolution:
Restrict access to the e107_plugins/hupsi_fancybox/uploader/uploadify.php script (e.g. via .htaccess).
June 30th, 2012
Application: e107
Vendorās URL: Radio Plan Plugin
Bug Type: File Upload
Risk Level: CriticalSolution:
Restrict access to the e107_plugins/radio_plan/admin/upload.php script (e.g. via .htaccess).
Affected Version: version 1.1 and other versions.
Vendorās URL: Hupsi Share Plugin
Bug Type: File Upload
Risk Level: CriticalSolution:
Restrict access to the e107_plugins/hupsi_share/inc/uploader/uploadify.php script (e.g. via .htaccess).
Affected Version: version 2.0 and prior versions.
Vendorās URL: Easy Flash Uploader Module
Bug Type: File Upload
Risk Level: CriticalSolution:
Update to version 2.1.
Affected Version: version 1.3.2 and other versions.
Vendorās URL: FirstLastNames Plugin
Bug Type: Cross Site Scripting
Risk Level: CriticalSolution:
Edit the source code to ensure that input is properly sanitised.
Affected Version: version 1.1 and other versions.
Vendorās URL: LatestComment Plugin
Bug Type: Cross Site Scripting
Risk Level: CriticalSolution:
Edit the source code to ensure that input is properly sanitised.
++++++

