aMember Pro 3.1.8 (security fix) released

Discussion in 'Troubleshooting' started by pahcsor, Jul 1, 2009.

  1. pahcsor

    pahcsor New Member

    Joined:
    Aug 28, 2006
    Messages:
    9
    Personally, I feel it is entirely wrong to charge for issues with your application. In this case, if you don't want your amember hacked with HTML injection, you need to pay $40 bucks for the upgrade.

    It seems pretty rotten that you would not just provide security updates for free considering they are issues you left there when you built the application (that we paid for in the understanding that it was in working order).

    If you agree (or disagree), please add your comments to this thread so we can make our concerns known.
  2. thehpmc

    thehpmc Member

    Joined:
    Aug 24, 2006
    Messages:
    901
    Totally disagree with you.

    Alex provided totally FREE OF CHARGE details of the necessary changes.
  3. alexander

    alexander Administrator Staff Member

    Joined:
    Jan 8, 2003
    Messages:
    6,279
    We don't charge for this.
    1. If you have active "upgrade" subscription we will upgrade your installation for free.
    or
    2. We can implement just security fix on your current aMember PRO version, again free of charge.
  4. pahcsor

    pahcsor New Member

    Joined:
    Aug 28, 2006
    Messages:
    9
    I apologize - I read the security update info., but somehow must have missed this. Please excuse my ignorance.

    Thank you for your responses.
  5. asmar

    asmar New Member

    Joined:
    Nov 22, 2004
    Messages:
    3
    Is there a way to remove the following message from been displayed:

    # WARNING: XSS Security problem found in your version of aMember Pro. Please visit aMember Website for details right now BEFORE YOU CLICK ANY OTHER LINKS YOUR AMEMBER CP.
    If you have already followed instructions, please just ignore this message - we cannot detect if your site is protected, so this message is displayed to all customers
    # New version of aMember Pro is available (latest is 3.1.8, you have 3.1.6 installed). More Details...

    I've already patched the files but don't have an active subscription.

    Thanks
  6. skippybosco

    skippybosco CGI-Central Partner Staff Member

    Joined:
    Aug 22, 2006
    Messages:
    2,526
    There are a couple of ways to get around this:

    1) In Admin-CP -> Setup/Configuration -> Advanced -> Don't check for aMember updates (check the box to not check for updates)

    2) edit amember\common.inc.php and change $config['version'] (line 31 I think) to be a newer version (3.1.8 in your case)

Share This Page