Thread Rating:
  • 0 Vote(s) - 0 Average
  • 1
  • 2
  • 3
  • 4
  • 5
Is your GetSimple installation hackable?
#5
Well, yes.

GetSimple has a bug in all versions prior to and including 1.7 that allows anyone to get files on your server. Version 1.71 fixes this, but breaks uploading functionality all together.

Another (still undocumented) bug I found yesterday gives people the ability to cripple your site. I’m not going to say too much about this ’til we got it patched though. But to be completely clear, this should be patched soon.

The hack I wrote just checks whether you are running a secure version of GetSimple. If you’re not, it tells me the site is hackable.
“Don’t forget the important ˚ (not °) on the a,” says the Unicode lover.
Help us test a key change for the core! ¶ Problems with GetSimple? Be sure to enable debug mode!
Reply


Messages In This Thread
Is your GetSimple installation hackable? - by Zegnåt - 2009-12-31, 22:04:35



Users browsing this thread: 2 Guest(s)