2012-07-16, 12:25:13
(This post was last modified: 2012-07-16, 12:34:44 by kuba.sanitrak.)
Sorry if it's already been linked to but it seems this plugin hasn't been patched for this vulnerability yet:
GetSimple Items Manager Arbitrary File Upload Vulnerability
Edit: Maybe just a Deny from All .htaccess in the server folder will be enough, otherwise the old <?php if(!defined('IN_GS')){ die('You cannot load this page directly.'); } ?> at the top might be the go too. Hard to say without looking at it closer.
GetSimple Items Manager Arbitrary File Upload Vulnerability
Edit: Maybe just a Deny from All .htaccess in the server folder will be enough, otherwise the old <?php if(!defined('IN_GS')){ die('You cannot load this page directly.'); } ?> at the top might be the go too. Hard to say without looking at it closer.