Page 1 of 1

Massive Security Hole with File Downloads

PostPosted: August 11th, 2011, 3:54 pm
by bluedot
----

Re: Massive Security Hole with File Downloads

PostPosted: August 11th, 2011, 7:01 pm
by Bruce C
I get a 404 error when I try something like that.

Have you encrypted your website? I'll run some more tests and see if I can replicate the situation.

Re: Massive Security Hole with File Downloads

PostPosted: August 11th, 2011, 8:38 pm
by Ciderhelm
Ace, I sent you a PM. I can confirm what Bluedot has posted.

Re: Massive Security Hole with File Downloads

PostPosted: August 11th, 2011, 9:37 pm
by Cristián Lávaque
Thank you guys. I emailed Jason.

Re: Massive Security Hole with File Downloads

PostPosted: August 11th, 2011, 10:47 pm
by Jason Caldwell
Thanks for reporting this important security issue.
~ We're investigating this now.

Re: Massive Security Hole with File Downloads

PostPosted: August 11th, 2011, 10:49 pm
by Cristián Lávaque
Awesome! Thanks Jason.

Re: Massive Security Hole with File Downloads

PostPosted: August 12th, 2011, 12:27 am
by Jason Caldwell
Thanks for the heads up on this thread Cristián.

This major security issue has been resolved in the release of s2Member v110812.
Please see this update for details: viewtopic.php?f=46&t=14419

s2Member® v110812 Security Release ( now available! )
http://wordpress.org/extend/plugins/s2member/

IMPORTANT: This release addresses an important security vulnerability in previous releases of the s2Member Framework ( i.e. the free version of s2Member ). Sites with Download Options configured for s2Member should be advised to update to s2Member v110812+ as soon as possible to avoid possible exploits. Changelog is located here: http://wordpress.org/extend/plugins/s2member/changelog/

Re: Massive Security Hole with File Downloads

PostPosted: August 12th, 2011, 12:41 am
by bluedot
Just installed, appears to have fixed it!

Big thanks for the quick turn around on this!

Re: Massive Security Hole with File Downloads

PostPosted: August 12th, 2011, 12:43 am
by Jason Caldwell
Thanks for the follow-up.
bluedot wrote:Just installed, appears to have fixed it!

Big thanks for the quick turn around on this!

Very welcome. Thank you VERY much for reporting this!