Contentteller

Contentteller Support Forums
Home Forums > Announcements > Announcements >

Security: SQL Injection Vulnerability in Storyteller CMS

Discussion in 'Announcements' started by Philipp, Mar 4, 2011.

  1. Philipp Administrator

    Storyteller CMS is the predecessor of Contentteller, which will be still used by some websites.

    Shamus from the http://antijasakom.net/forum forum discovered a weakness in Storyteller CMS where an attacker may execute arbitrary SQL statements on the vulnerable system. I was able to pinpoint the vulnerability and have released the patch below.

    Unzip the patch and upload the new core.php to your Storyteller main directory. This vulnerability exists only in Storyteller, Contentteller is using a completely different code base.

    Attached Files:

    • st182_fix.zip
      st182_fix.zip
      File size:
      8.5 KB
      Views:
      76
    Philipp, Mar 4, 2011
    #1
  2. Richard B Customer

    Philipp said: ↑
    Storyteller CMS is the predecessor of Contentteller, which will be still used by some websites.

    Shamus from the http://antijasakom.net/forum forum discovered a weakness in Storyteller CMS where an attacker may execute arbitrary SQL statements on the vulnerable system. I was able to pinpoint the vulnerability and have released the patch below.

    Unzip the patch and upload the new core.php to your Storyteller main directory. This vulnerability exists only in Storyteller, Contentteller is using a completely different code base.
    Just wondered what the base64_encode is for in this?
    Richard B, Apr 20, 2011
    #2
  3. Philipp Administrator

    Richard B said: ↑
    Just wondered what the base64_encode is for in this?
    In line 751? To make the username file system safe, so special characters will not break the filename.
    Philipp, Apr 20, 2011
    #3
Tweet
Facebook:
Forgot your password?
Contentteller Support Forums
Home Forums > Announcements > Announcements >
  • Home
  • Forums

    Forums

    Quick Links
    • Search Forums
    • What's New?
  • Members

    Members

    Quick Links
    • Registered Members
    • Current Visitors
    • Recent Activity
  • Help

    Help

    Quick Links
    • Smilies
    • BB Codes
    • Trophies

Separate names with a comma.

Advanced search...
    Forum software by XenForo™ ©2011 XenForo Ltd.