Using Amember? Then You're Going to Be Upset Today...

4 replies
If you haven't heard, they've discovered a security exploit, called a XSS or cross site script attack, in Amember (the membership program).

The patch is here:

SecurityNote06

And if you need more details, I blog a little about it here:

Amember Security Issue

If you use it, you've likely gotten the email.

However, I just want to encourage people to FIX IT ASAP.

It's a bad one, and the result is your site could be wide open if you don't fix it.

The fix takes less than 1/2 hour, and I frankly encourage you to drop everything and do it right away - I did when I read about it (I use Amember for my ActiveBlogging site).
#amember #today #upset
  • Profile picture of the author Allen Graves
    Applying patch now!!!!

    Your site could be wide open for what? Do you mean the html pages and your files themselves could be edited or just that someone can get in without being a member?

    AL
    Signature
    Every day I check the obituaries. If I don't see my name there, then I know it's going to be a good day!
    {{ DiscussionBoard.errors[824431].message }}
  • Profile picture of the author footpod
    Done - It takes about 5 minutes. When you log in, you get a red WARNING to remind you to do it - even if you have...
    {{ DiscussionBoard.errors[824524].message }}
  • Profile picture of the author MichaelHiles
    reason # 543,124 why interpreted script-based applications are teh suxxor
    {{ DiscussionBoard.errors[824768].message }}
  • Profile picture of the author anth.elias
    Originally Posted by David Pankhurst View Post

    If you haven't heard, they've discovered a security exploit, called a XSS or cross site script attack, in Amember (the membership program).

    The patch is here:

    SecurityNote06

    And if you need more details, I blog a little about it here:

    Amember Security Issue

    If you use it, you've likely gotten the email.

    However, I just want to encourage people to FIX IT ASAP.

    It's a bad one, and the result is your site could be wide open if you don't fix it.

    The fix takes less than 1/2 hour, and I frankly encourage you to drop everything and do it right away - I did when I read about it (I use Amember for my ActiveBlogging site).
    Piece of cake took me 2 minutes to fix. no biggy, just glad CGI let us no about it.
    {{ DiscussionBoard.errors[825005].message }}

Trending Topics