[<prev] [next>] [day] [month] [year] [list]
Message-ID: <20090604215359.13939.qmail@securityfocus.com>
Date: 4 Jun 2009 21:53:59 -0000
From: peter@...er.com
To: bugtraq@...urityfocus.com
Subject: Re: Re: [InterN0T] Geeklog 1.5 - Pre-Installation Vulnerabilities
Hi Dirk,
"
>-:: Solution ::-
>I didn't bother to find one, sorry.
A simple solution is to follow the installation instructions, which
strongly recommend removing the install script after a successful
install. There are also further checks and reminders about this built
into Geeklog.
"
You cant expect your users to do so, then the best way would be to force the webmaster to remove the install scripts before he can use the CMS.
Regards
Powered by blists - more mailing lists