PhotoPost Community

PhotoPost Community (http://www.photopost.com/forum/)
-   Classifieds Installation & Upgrades (http://www.photopost.com/forum/classifieds-installation-upgrades/)
-   -   Classifieds 2.02: Security Fix (http://www.photopost.com/forum/classifieds-installation-upgrades/111279-classifieds-2-02-security-fix.html)

Michael P January 2nd, 2005 10:14 AM

Classifieds 2.02: Security Fix
 
=======================
PHOTOPOST CLASSIFIEDS 2.02
=======================

Minor update to address possible security vunerability.

Files changes since 2.01:

showcat.php
header-inc.php
uploadproduct.php

templates/searchbox.tmpl

Version numbers were updated with the files and should be uploaded:

pp-inc.php
adm-editcfg.php

You only need to upload these two files to bring your release up-to-date. There is no upgrade script to run and no database changes.

Security Fix Info
============

I've updated the current build which modifys a single line in uploadproduct.php which prevents unauthorized file types from being uploaded.

In uploadproduct.php at line 230 is the line:

if ( $realname != "none" && $realname != "" && is_image($realname) ) {

the modification has been made in bold. You can either modify the line yourself and update your script or download the current build and upload the file uploadproduct.php

The other files contain a minor fix to prevent html code from being passed as part of a URL string.


All times are GMT -5. The time now is 08:10 PM.

Powered by vBulletin® Version 3.8.1
Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Search Engine Friendly URLs by vBSEO 3.2.0


1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97