Serious XSS vulnerability (in v.0.94)

Helpdesk for my helpdesk software

Moderator: mkoch227

Post Reply
Avram
Posts: 7
Joined: Thu Oct 25, 2007 11:11 am

Serious XSS vulnerability (in v.0.94)

Post by Avram »

(REMOVED BY KLEMEN)

Nemanja, thanks for bringing this to my attention. I removed your post from here to avoid any misuse. This indeed seems to be an issue if the server is not configured to force mime headers properly, will have a look at it ASAP and post the results.

Regards,
Klemen
Klemen
Site Admin
Posts: 10142
Joined: Fri Feb 11, 2005 4:04 pm

Post by Klemen »

This issue has been fixed. I strongly recommend anyone using Hesk 0.94 to update to 0.94.1. You can get it from here:
http://www.phpjunkyard.com/free-helpdesk-software.php

Update is quick and easy and you won't loose any current settings/tickets.
Klemen, creator of HESK and PHPJunkyardWas this helpful? You can buy me a drink here Image

Image You should follow me on Twitter here

Help desk software | Cloud help desk | Guestbook | Link manager | Click counter | more PHP Scripts ...

Also browse for php hosting companies, read php books, find php resources and use webmaster tools
Avram
Posts: 7
Joined: Thu Oct 25, 2007 11:11 am

Post by Avram »

Thanks for quick reaction, will update ASAP :)
Triblade
Posts: 4
Joined: Thu Oct 25, 2007 12:55 pm

Post by Triblade »

But I do lose my custom header.txt for example. :)
Be carefull what you overwrite. (Luckely I saw it before overwriting)
Klemen
Site Admin
Posts: 10142
Joined: Fri Feb 11, 2005 4:04 pm

Post by Klemen »

if you are upgrading from 0.94 you shouldn't lose the header.txt if you follow readme instructions :P
Klemen, creator of HESK and PHPJunkyardWas this helpful? You can buy me a drink here Image

Image You should follow me on Twitter here

Help desk software | Cloud help desk | Guestbook | Link manager | Click counter | more PHP Scripts ...

Also browse for php hosting companies, read php books, find php resources and use webmaster tools
DigiMon
Posts: 29
Joined: Sat Aug 12, 2006 12:01 am

Post by DigiMon »

Thank you for the patch Klemen! The upgrade instructions in the readme file made it simple for me to upgrade without losing my customized Hesk. It literally took less than 5 minutes... awesome~!
DigiMon
Posts: 29
Joined: Sat Aug 12, 2006 12:01 am

Post by DigiMon »

Just FYI, I discovered a couple things that the upgrade did "break", but they were customizations to fields contained tickets that we talked about in the following posts (where you gave me the instructions):

viewtopic.php?p=5914&highlight=#5896

viewtopic.php?p=5914&highlight=#5909

Going to try to re-apply them shortly and see if they work again.

EDIT - applied the instructions again, works fine, you rock! :)
Last edited by DigiMon on Mon Oct 29, 2007 11:55 pm, edited 1 time in total.
Klemen
Site Admin
Posts: 10142
Joined: Fri Feb 11, 2005 4:04 pm

Post by Klemen »

Yeah, didn't include any other edits or anything with this release, just the patch. Fixes should still work, just line numbers can be different.

I will probably release a bigger update with new functionality in the next few months.
Klemen, creator of HESK and PHPJunkyardWas this helpful? You can buy me a drink here Image

Image You should follow me on Twitter here

Help desk software | Cloud help desk | Guestbook | Link manager | Click counter | more PHP Scripts ...

Also browse for php hosting companies, read php books, find php resources and use webmaster tools
Post Reply