Products

Solutions

Resources

Partners

Community

Blog

About

QA

Ideas Test

New Community Website

Ordinarily, you'd be at the right spot, but we've recently launched a brand new community website... For the community, by the community.

Yay... Take Me to the Community!

Welcome to the DNN Community Forums, your preferred source of online community support for all things related to DNN.
In order to participate you must be a registered DNNizen

HomeHomeUsing DNN Platf...Using DNN Platf...Administration ...Administration ...Major Security problem reported AGES ago, still in 5.6.2Major Security problem reported AGES ago, still in 5.6.2
Previous
 
Next
New Post
4/11/2011 6:38 PM
 
I agree this bug is not good. I also hope there is a 5.6.3 release but I did see that Joe Brinkman has said that there will be no more 5.x releases (see http://www.dotnetnuke.com/Resources/F...).

Also, I don't know if this bug is the cause or not but can anyone else confirm that on 5.6.2 if you are on the user profile page and logout you get a too many redirects error (this happens on all web browsers for me)???
 
New Post
4/18/2011 4:49 PM
 
I am trying to understand if this is the same thing I am seeing after upgrade from 5.6.0. I did this updated to get it to work inside of 5.6.0 http://www.dotnetnuke.com/Resources/Forums/tabid/795/forumid/200/threadid/397993/scope/posts/threadpage/3/Default.aspx. Then double checked this fix seems to be in source just not in the upgrade of DNN.dll file maybe? I am going to compile 5.6.2 to see if that will help fix the admin features showing for basic editors.

Chris
 
New Post
5/4/2011 6:23 AM
 
FYI, I just reported this issue to the security team as I believe it is a serious security issue. I made the request that a 5.6.3 release is created to fix it. If the last release in the 5.x family (which people will naturally assume is the stablest DNN version to use, even when 6.0 has been out for some time), contains a major security flaw, this will catch a lot of people out and not give them a good impression of DNN or DNN Corp.
 
New Post
5/8/2011 3:12 AM
 
I've just posted another comment on the partner forum to try and get some movement happening. Hopefully someone at DNN corps will realise how serious this issue is!
 
New Post
5/12/2011 10:42 AM
 
I could not figure anything out so sticking with 5.6 until I hear this has been fixed. Plus I am having other issues with some custom modules in 5.6 that I need to fix because debugging DNN code.
 
Previous
 
Next
HomeHomeUsing DNN Platf...Using DNN Platf...Administration ...Administration ...Major Security problem reported AGES ago, still in 5.6.2Major Security problem reported AGES ago, still in 5.6.2


These Forums are dedicated to discussion of DNN Platform and Evoq Solutions.

For the benefit of the community and to protect the integrity of the ecosystem, please observe the following posting guidelines:

  1. No Advertising. This includes promotion of commercial and non-commercial products or services which are not directly related to DNN.
  2. No vendor trolling / poaching. If someone posts about a vendor issue, allow the vendor or other customers to respond. Any post that looks like trolling / poaching will be removed.
  3. Discussion or promotion of DNN Platform product releases under a different brand name are strictly prohibited.
  4. No Flaming or Trolling.
  5. No Profanity, Racism, or Prejudice.
  6. Site Moderators have the final word on approving / removing a thread or post or comment.
  7. English language posting only, please.
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out