Get XOOPS XOOPS FAQ Forums News Themes Modules
News World of XOOPS Developers Hacks Modules Themes Archive Submit News

XOOPS vs. Herko Coomans

Make a donation

Please select an amount to donate


Do you want your username revealed with your donation?
Yes - List me as a Generous Donor
No - List my donation as from an Anonymous Donor


Search

Local Support Sites

Cumulus Tag Cloud

admin Arabic banner block Christmas comments cumulus DayDawn dhsoft e-Commerce E-Learning Google GUI hacks instant-zero jQuery module news Nordic Olédrion oxygen PageRank security SEO simple-XOOPS sport tag Theme wiki xoops

New Users

Registering user

# 96574

audriusr

Welcome to XOOPS!

Archives

XOOPS Code hosted on SourceForge

vulnerability in SPAW editor

Posted by phppp on 2007/6/13 0:05:22 (8356 reads) | Posted on Security
Vulnerability was reported in some version of the SPAW editor, which is used by some of XOOPS third-party modules.

Module "tinycontent" is one of the modules using SPAW. Although we are not sure which version(s) is vulnerable, we suggest disable SPAW in tinycontent and remove the "modules/tinycontent/admin/spaw/" folder from your server.


Printer Friendly Page Send this Story to a Friend Create a PDF from the article


Bookmark this article at these sites

                   

The comments are owned by the poster. We aren't responsible for their content.

I can confirm this. Remove the Spaw directory.
Posted: 2007/6/13 2:01 • Updated: 2007/6/13 2:01
Could these kind of news articles be posted on the frontpage of Xoops.org. Specially because alot of people use this module on their site. Just a thought;)
Posted: 2007/6/13 2:06 • Updated: 2007/6/13 2:06
It would be usefull to have such lerts on xoops.org. If a site is working fine, admin may not login very often.
But you are rigt - it will be nice to have it there (in admin) too...

In short is this related? http://xoops.peak.ne.jp/modules/news/ ... e=article&storyid=398

And here is another one: command injection of phpmailer in XOOPS:
http://xoops.peak.ne.jp/md/news/index ... e=article&storyid=431

And what abot FCK http://xoops.peak.ne.jp/modules/news/ ... e=article&storyid=396

Last What about security team that will investigate reports, help with fixes for core/modules, write good practice papers(for XOOPS, modules, web servers ...) and try to hack core/modules and fix them in order to make xoops more secure
Posted: 2007/6/13 10:02 • Updated: 2007/6/13 10:02
Hi all

I also can confirm this.
I had 2 sites atacked.
They could use your server to send TONS of spam´s.
Posted: 2007/6/13 11:47 • Updated: 2007/6/13 11:47
got hacked by this too
Posted: 2007/6/13 16:49 • Updated: 2007/6/13 16:49
the problem is the spaw_control.class.php

DELETE IT!!!!
Posted: 2007/6/18 9:51 • Updated: 2007/6/18 9:51
Details her:
http://www.securityfocus.com/bid/24302
Posted: 2007/6/18 10:58 • Updated: 2007/6/18 10:58
Quote:
A more useful thing - and this is a practical suggestion for the core team ... is to send a security update every time they log into their admin area. People don't have to return to this site when they're set up - but people would have to read that...

This would be bad news for site designers IMHO. I already disabled version notification in Zen Cart because I had a raft of demands to upgrade as soon as the new version came out. Upgrades should be the webmaster's decision. They shouldn't be pressurised into it because a client has been panicked by a version 'warning' or a security scare. As long as xoops.org continue to highlight issues like this promptly, webmasters can keep up to speed on security issues. Users can subscribe to the security news category and receive email notifications of new articles. If they don't bother, that's their problem.
Posted: 2007/6/18 11:42 • Updated: 2007/6/18 11:42
My site just got hit for this

Tinycontent 1.5
hosting provider
mentioned spaw_control.class.php
Posted: 2007/6/18 11:53 • Updated: 2007/6/18 11:53
Quote:
Users can subscribe to the security news category and receive email notifications of new articles.

Sorry, actually they can't at present. But it would be good if they could.
Posted: 2007/6/18 12:25 • Updated: 2007/6/18 12:25
According to the National Vulnerability Database, Xoops modules affected by the spaw_control.class.php vulnerability include:

Tiny Content
XT-Contuedo
CJay Content


This is beacause they include the old Spaw version 1.0.

According to Secunia, the issue is resolved by upgrading Spaw to version > 1.0.4.

http://secunia.com/advisories/10451/

Solmetra (the makers of Spaw) recommend upgrading to 1.2.4.

See this advisory

The current version of Spaw is 2.0.4.1.
Posted: 2007/6/18 18:01 • Updated: 2007/6/18 18:01
As well as the modules listed above, Spaw 1.0 is also present in:

Wordpress ME
Xoopseditor Framework 1.2


If you use this editor, it may be straightforward to upgrade simply by replacing the Spaw folder?.
Posted: 2007/6/20 12:29 • Updated: 2007/6/20 12:30