Version 1 of the Beta
Printed From: Web Wiz Forums
Category: Web Wiz Web App Support Forums
Forum Name: Web Wiz Forums
Forum Description: Support forum for Web Wiz Forums application.
URL: https://forums.webwiz.net/forum_posts.asp?TID=29333
Printed Date: 01 April 2026 at 10:40am Software Version: Web Wiz Forums 12.08 - https://www.webwizforums.com
Topic: Version 1 of the Beta
Posted By: 123Simples
Subject: Version 1 of the Beta
Date Posted: 16 May 2011 at 1:26pm
Hi Bruce - Just to check, on another forum category you say:
Web Wiz Rich text Editor version 4.08 which fixes this vulnerability has been released and is available from the download page:-
http://www.webwiz.net/web-wiz-rich-text-editor/downloads.htm" rel="nofollow - Web Wiz RTE Download
This
new version strips semicolons from uploaded file names to prevent
hackers from exploiting this vulnerability in IIS 6 and below. |
Does this mean that the beta release has been updated to cover this exploit, or does it merely affect Web Wiz RTE?
|
Replies:
Posted By: WebWiz-Bruce
Date Posted: 16 May 2011 at 1:47pm
This vulnerability is only in IIS 6 and below so does not affect Windows 2008 IIS 7 or above.
The Version 10 beta version will have protection against this in beta 2.
------------- https://www.webwiz.net/web-wiz-forums/forum-hosting.htm" rel="nofollow - Web Wiz Forums Hosting https://www.webwiz.net/web-hosting/windows-web-hosting.htm" rel="nofollow - ASP.NET Web Hosting
|
Posted By: 123Simples
Date Posted: 16 May 2011 at 6:03pm
Thanks for clarifying that point Bruce
Well I jumped in with the update running the beta test version 1 on one of our forums. Pleasantly the actual upgrade all went smoothly  A few minor hiccups (but more to do with Firefox 4 I'm sure). By that I mean at first the images seemed displaced on the window, but IE9 seemed to render fine! Then refreshed the window and the images and CSS all came back in normally - thought I would mention this for other "numpties" like me 
Apart from that not so bad. I'm pretty certain it will be a firm favourite for current users to look at when the final release comes out
------------- http://www.123simples.com/" rel="nofollow - Visit 123 Simples Web Design
|
|