Topics

User Functions

Events

There are no upcoming events

What's New

Stories

1 new Stories in the last 2 weeks

Comments last 2 weeks

No new comments

Trackbacks last 2 weeks

No new trackback comments

Links last 2 weeks

No recent new links

NEW FILES last 14 days

No new files

Welcome to Geeklog Friday, May 24 2013 @ 10:59 AM EDT

> >

FCKeditor input sanitization errors

Security
  • Sunday, July 05 2009 @ 07:20 AM EDT
  • Contributed by:
  • Views:
    6,498

An advisory has been published, warning about "input sanitization errors" in all current versions of FCKeditor. Unfortunately, the advisory is a bit light on details and so it's not clear whether FCKeditor as packaged with Geeklog is affected or not. A patch for these issues is supposed to be released this coming Monday (July 6).

Here's what we know:

  • The advisory mentions that "several" of the FCKeditor connector modules are affected and suggests removing all unused connectors. Geeklog only ships with one connector (for PHP), but it's not clear whether this connector is affected or not.
  • There's a second issue regarding XSS in the FCKeditor samples. Geeklog does not include the samples, so we're not affected by this issue at least.

The advisory recommends disabling the file browser for now. To do this in Geeklog, open the file

fckeditor/editor/filemanager/connectors/php/config.php

(from your public_html directory) and find the line that reads

$Config['Enabled'] = true ;

Change that to = false; and save the change. You will still see the "Browse" buttons in FCKeditor, but they won't let you browse your server's directories any more.

If you don't use FCKeditor, you can simply remove the entire fckeditor directory (again, in public_html).

It's very frustrating for us not to be able to provide you with more information. The above is a summary of the situation as we understand it, to the best of our knowledge. Once the update for FCKeditor is out, things will (hopefully) become clearer and we can provide you with more and better advice on how to secure your site.

We're also delaying Geeklog 1.6.0rc2 until the FCKeditor update is available.

Trackback

Trackback URL for this entry:
http://www.geeklog.net/trackback.php/fckeditor-input-sanitization

[...] should also be the last stop before the release of the final 1.6.0. This releases includes fixes for the FCKeditor security issue, some more fixes for the migration option of the install script, a fix for searches by date, and some more [...] [read more]

[...] (7)Monday 27-Jul PostgreSQL beta support! (4)Sunday 19-Jul Geeklog 1.6.0 (1) Geeklog 1.6.0rc2 (3) FCKeditor input sanitization errors (3) Welcome to GeeklogSunday, August 30 2009 @ 01:06 PM EDT Geeklog 1.6.0sr2 Sunday, August 30 2009 @ 01:05 [...] [read more]

The following comments are owned by whomever posted them. This site is not responsible for what they say.

  • FCKeditor input sanitization errors
  • Authored by:xardoz on Monday, July 06 2009 @ 08:12 AM EDT
I was using the FCKeditor on a test of the release candidate and while it accepted the [image] tag, it ignored the alignment specification in [image_right]. Picture showed, but didn't align right. Didn't have a chance to test further, and I was using an old, highly modded theme, but it's never failed me before.
  • FCKeditor input sanitization errors
  • Authored by:xardoz on Monday, July 06 2009 @ 09:21 AM EDT
Looks like it was my theme - works fine under Professional.
  • FCKeditor 2.6.4.1 drop-in replacement available
  • Authored by:Dirk on Sunday, July 12 2009 @ 10:31 AM EDT

A drop-in replacement for earlier FCKeditor versions, as shipped with all Geeklog versions prior to 1.6.0rc2, is now available for download.

This is FCKeditor 2.6.4.1 bundled to work with Geeklog and should work with Geeklog 1.5.x (as well as Geeklog 1.6.0 prior to rc2). It also seems to work with Geeklog 1.4.1. Other versions have not been tested.

Installation instructions are included. Summary: Replace your fckeditor directory with the one from this tarball.

Post a Comment

Your Name
Create Account
Allowed HTML Tags:
 

Security code
This question is for testing whether you are a human visitor and to prevent automated spam submissions.

What code is in the image?
Enter the bolded text, case sensitive!
Important Stuff
  • Please try to keep posts on topic.
  • Try to reply to other people comments instead of starting new threads.
  • Read other people's messages before posting your own to avoid simply duplicating what has already been said.
  • Use a clear subject that describes what your message is about.
  • Your email address will NOT be made public.