PROBLEM:CMS400 Security Update
Applies To:
CMS400.NET
Summary:
Ektron has an update for a security issue found in CMS400 for version 7.0X and 7.50, 7.51, and 7.52. This is not an issue in version 7.53 or above.
We have remedied the issue and have a resolution for the versions affected.
Symptoms:
-
A page in the workarea folder was susceptible to attack by dishonest companies that attempt to maliciously execute this page. There have been no reported cases of this happening that Ektron is aware of and there are ways to prevent this type of attack through best practices of setting up an Ektron CMS site.
Changing the name of your workarea folder during the installation is one way to prevent attacks of this nature.
Solutions: