MangoBery is a simple and user-friendly way for small groups and organizations to have a dynamic and easy to update web site. It uses PHP and MySQL to provide a great deal of flexibility in the way a web site looks and behaves.
Be the first to post a text review of MangoBery Content Management System. Rate and review a project by clicking thumbs up or thumbs down in the right column.
Today it was reported on Secunia (http://secunia.com/advisories/24686/) that MangoBery has a bug: some supporting files in the project were not properly hardened against malicious users. I've looked into it and corrected the bug in the SVN tree; I have taken the precaution of removing the "release" on the release page, since it's so horribly outdated that I wouldn't trust it anyway. Here is a list of the affected files, which have been patched in the SVN repository: /conf.default.php /footer.php /functions.php /header.php /boxes/main_menu.php /boxes/quotes.php /includes/column_left.php /includes/column_right.php /templates/benign/footer.sample.php /templates/benign/header.sample.php /templates/mangobery/footer.sample.php /templates/mangobery/header.sample.php /templates/plain-jayne/footer.sample.php /templates/plain-jayne/header.sample.php Also, it is recommended that you disable Image Uploads and make sure that the "/Images" folder is not world-writable. I apologize for the inconvenience :(
Be the first person to add a text review.
Copyright © 2010 Geeknet, Inc. All rights reserved. Terms of Use
Thanks for your rating!
Would you also like to write a review?
Thanks for your review!
Get credit for your review by logging in via OpenID. Click your account provider: