This security update for SiteStudio 1.6 Final and 1.6 Patch 1
fixes XSS vulnerability in SiteStudio Guestbook.
IMPORTANT:
Do not update from SiteStudio 1.6RC3 or earlier versions, only from SiteStudio 1.6 Final or 1.6 Patch 1.
To apply the security update:
Standalone SiteStudio on Linux/BSD:
Note: You must perform these actions under the account your SiteStudio is run under.
- Enter the SiteStudio directory:
cd /home/SiteStudio
- Run the script:
sh ./patch-gb-ss1.6.sh
- Restart SiteStudio.
SiteStudio integrated with H-Sphere
Note: You must perform these actions under the cpanel account.
- Enter the SiteStudio directory:
cd /hsphere/shared/SiteStudio
- Run the script:
sh ./patch-gb-ss1.6.sh
- Restart H-Sphere under root.
- Restart imaker.sh:
/hsphere/shared/SiteStudio/imaker.sh restart
For SiteStudio on Windows®:
- Change into the directory studio/WEB-INF/classes in the SiteStudio directory.
- Create the directory psoft/guestbook.
- Restart SiteStudio.
Special thanks to Donnie Werner of exploitlabs.com
for finding this vulnerability and notifying us!
|