Category: Security info

b2evolution 2.4.5 now available in Fantastico

Permalink December 15, 2008 @ 03:33, by Francois Planque • Category: Security info
If you still haven't upgraded to b2evolution 2.4.5, you can now do it with even less clicks than before if you have installed b2evolution with Fantastico Deluxe. Fantastico now ships b2evolution 2.4.5 as part of their installer. Thank you to the sh… more »

b2evo 1.8.6 AND 1.9.1 released!

Permalink December 2, 2006 @ 19:42, by Francois Planque • Category: New releases, Security info
Only December the 2nd and we already have 2 new releases this month! It may seem as we can't get enough releases out the door. But these ones are for your security, so... It is extremely strongly advised you upgrade! Download here! These release… more »

Security Alert: import-mt.php

Permalink November 30, 2006 @ 14:27, by Francois Planque • Category: Security info
Well, it's been a long time since the last security alert, but every now and then someone finds a security hole and it gets exploited... This one doesn't affect b2evolution in itself but the Movable Type Importer as shipped with b2evolution since vers… more »

b2evolution passing the Scanmus test

Permalink November 13, 2005 @ 23:54, by Francois Planque • Category: Security info
Last week, at PHP Forum Paris 2005, Rasmus Lerdorf (the father of PHP if you don't know) showcased "Scanmus", a tool he's been developping internally at Yahoo in order to detect any severe security holes in PHP applications. Of course, I took the oppo… more »

Fix for XML-RPC vulnerability (again!)

Permalink August 31, 2005 @ 19:53, by Francois Planque • Category: Security info
Yope, that's right, they did it again! :| The previous XML-RPC fix may not be secure enough, so... It is highly recommended you fix you installation by downloading this NEW patch file and unzipping it into you /blogs/b2evocore/ folder. This should… more »

Fix for XML-RPC vulnerability

Permalink July 5, 2005 @ 15:37, by Francois Planque • Category: Security info
A critical security issue has been discovered in the XML-RPC for PHP that most applications use, including b2evolution. It is highly recommended you fix you installation by downloading this patch file and unzipping it into you /blogs/b2evocore/ folder… more »

Security issue

Permalink January 7, 2005 @ 12:13, by Francois Planque • Category: Security info
A moderately critical security advisory has been posted here: http://secunia.com/advisories/13718/ Methods to fix this issue are described here: http://forums.b2evolution.net/viewtopic.php?t=2695 We are encouraging all b2evo users to update their… more »

b2evolution 0.8.2.2 maintainance release

Permalink September 2, 2003 @ 19:19, by Francois Planque • Category: New releases, Security info
At b2evolution's, one of our main concerns is security. While we constantly keep securing the legacy b2 codebase while developing new versions, we felt it was appropriate to release a security upgrade for our latest stable release (0.8.2). We are plea… more »