PhotoPost Photo Gallery Sales PhotoPost Sales Toll Free Phone Number
Mon-Fri 9am-4pm EST
  PhotoPost Photo Sharing Photo Gallery    Visualize community tm
| | | | | | | | |

Go Back   PhotoPost Community > General Forums > General Discussion

General Discussion General use discussion forum for PhotoPost products.

Reply
 
LinkBack Thread Tools Rating: Thread Rating: 2 votes, 5.00 average. Display Modes
Old April 6th, 2010, 08:42 AM   #1 (permalink)
WB
Member
Verified Customer
 
Join Date: Jan 2002
Posts: 265
Potential SQL Injection

FYI, to the developers:

PhotoPost vBGallery Two SQL Injection Vulnerabilities - Advisories - Community
WB is offline   Reply With Quote
Old April 6th, 2010, 11:42 AM   #2 (permalink)
Photopost Developer
Verified Customer
 
Chuck S's Avatar
 
Join Date: Jun 2002
Location: Abingdon,MD
Posts: 71,654
Thanks will pass this along
__________________
Photopost Developer and Support Engineer

Please do not PM me for support or sales questions. Thank you for your understanding.
Chuck S is offline   Reply With Quote
Old April 6th, 2010, 01:02 PM   #3 (permalink)
PhotoPost Developer
Verified Customer
 
Join Date: Jan 2002
Posts: 11,834
I'm not sure this is valid; at least from what we can see.

Honestly, I've had dozens of reports on there that were simply not true.
__________________
Please do not PM me for support or sales questions. Thank you for your understanding.
Michael P is offline   Reply With Quote
Old April 7th, 2010, 02:04 AM   #4 (permalink)
Member
 
Join Date: Jun 2004
Posts: 164
It is true.

Here is the original exploit:
SecurityFocus

Everyone can just test it out.
Kirby is offline   Reply With Quote
Old April 7th, 2010, 07:25 PM   #5 (permalink)
PhotoPost Developer
Verified Customer
 
Join Date: Jan 2002
Posts: 11,834
Fix

Attached is a new profile_start.php script for versions 2.0-2.4.X.

Download, rename the file to profile_start.php and replace your file:

forums / includes / vbgallery / profile_start.php

I will also update the build with an updated file.

For version 2.5, you will need to go to Plugin & Products -> Plug-in Manager -> UserCP -> profile_start and replace with the content from profile_start_plugin.txt
Attached Files
File Type: txt profile_start_plugin.txt (6.3 KB, 0 views)
File Type: txt profile_start.php.txt (7.3 KB, 0 views)
__________________
Please do not PM me for support or sales questions. Thank you for your understanding.

Last edited by Michael P; May 4th, 2010 at 04:49 PM.
Michael P is offline   Reply With Quote
Old April 15th, 2010, 02:07 AM   #6 (permalink)
Junior Member
 
Join Date: Jan 2005
Posts: 5
I've got an active license and I can't even download it...
Ian Cunningham is offline   Reply With Quote
Old April 23rd, 2010, 12:59 PM   #7 (permalink)
Junior Member
Verified Customer
 
Join Date: Jan 2008
Posts: 22
Unfortunately I got attacked by this anyways I moved hosts servers because I really didn't understand what was going on...
I won't get into the fine details what I would like to do if I caught the individual that did that to me.

But anyways I had my webpage migrated over to another host company and bought a renewal license of photo post I just installed it and now when I go to ...gallery/search.php?do=getdaily it's a blank page and I believe I'm setting the permissions correctly..

Last edited by Chuck S; April 23rd, 2010 at 01:06 PM.
Rideharder is offline   Reply With Quote
Old April 23rd, 2010, 01:06 PM   #8 (permalink)
Photopost Developer
Verified Customer
 
Chuck S's Avatar
 
Join Date: Jun 2002
Location: Abingdon,MD
Posts: 71,654
Is this a real post or a spam post sorry have to ask as your post is xxx link but I see your a verified customer.
__________________
Photopost Developer and Support Engineer

Please do not PM me for support or sales questions. Thank you for your understanding.
Chuck S is offline   Reply With Quote
Old April 23rd, 2010, 01:54 PM   #9 (permalink)
Junior Member
Verified Customer
 
Join Date: Jan 2008
Posts: 22
Yes I'm a paying customer, Would you like to correct URL?

And yes I was one of the ones that was hacked due to SQL injection..
Calling on Vbulletin community need help

I should of received a coupon code for the renewal license..lol
Rideharder is offline   Reply With Quote
Old April 23rd, 2010, 02:31 PM   #10 (permalink)
Junior Member
Verified Customer
 
Join Date: Jan 2008
Posts: 22
I got it working..

what do I put for misc.php?do=buddylist&focus=1
for Global PhotoPost vBGallery Settings...
Rideharder is offline   Reply With Quote
Old April 23rd, 2010, 03:36 PM   #11 (permalink)
Photopost Developer
Verified Customer
 
Chuck S's Avatar
 
Join Date: Jun 2002
Location: Abingdon,MD
Posts: 71,654
Okay well you used a url that went to a porn site which is why I had to ask.

You might not want to place dummy urls called xxx.net
__________________
Photopost Developer and Support Engineer

Please do not PM me for support or sales questions. Thank you for your understanding.
Chuck S is offline   Reply With Quote
Old April 23rd, 2010, 03:50 PM   #12 (permalink)
Member
Verified Customer
 
Join Date: Nov 2005
Location: Southern Germany
Posts: 213
Thanks for the quick fix.
Ramses is offline   Reply With Quote
Old April 23rd, 2010, 06:05 PM   #13 (permalink)
Photopost Developer
Verified Customer
 
Chuck S's Avatar
 
Join Date: Jun 2002
Location: Abingdon,MD
Posts: 71,654
let us know if you need anything else
__________________
Photopost Developer and Support Engineer

Please do not PM me for support or sales questions. Thank you for your understanding.
Chuck S is offline   Reply With Quote
Old April 26th, 2010, 01:27 AM   #14 (permalink)
Junior Member
Verified Customer
 
Join Date: Jan 2008
Posts: 22
what do I put for misc.php?do=buddylist&focus=1
for Global PhotoPost vBGallery Settings...

It still is popping up blank..............
Rideharder is offline   Reply With Quote
Old April 26th, 2010, 01:27 AM   #15 (permalink)
Junior Member
Verified Customer
 
Join Date: Jan 2008
Posts: 22
Quote:
Originally Posted by Chuck S View Post
Okay well you used a url that went to a porn site which is why I had to ask.

You might not want to place dummy urls called xxx.net

My bad..
Rideharder is offline   Reply With Quote
Old April 26th, 2010, 01:28 AM   #16 (permalink)
Junior Member
Verified Customer
 
Join Date: Jan 2008
Posts: 22
Quote:
Originally Posted by Ramses View Post
Thanks for the quick fix.

Thanks for the quick fix
Rideharder is offline   Reply With Quote
Old April 26th, 2010, 01:30 AM   #17 (permalink)
Junior Member
Verified Customer
 
Join Date: Jan 2008
Posts: 22
And I have a question for the bulk upload... how do I highlight all the pictures at once or am I misunderstanding how to do it...

I hardly used Photopost in the past but now since I have unlimited bandwidth, I figured I would use it now to its fullest.


Hopefully this time you can stay off the xxx site and answer my question..lol

Last edited by Rideharder; April 26th, 2010 at 01:38 AM.
Rideharder is offline   Reply With Quote
Old April 26th, 2010, 05:37 AM   #18 (permalink)
Photopost Developer
Verified Customer
 
Chuck S's Avatar
 
Join Date: Jun 2002
Location: Abingdon,MD
Posts: 71,654
I beleive version 2.5 has the flash uploader included you want to use that version and turn on the flash upload so you can highlight multiple photos to upload.
__________________
Photopost Developer and Support Engineer

Please do not PM me for support or sales questions. Thank you for your understanding.
Chuck S is offline   Reply With Quote
Old April 29th, 2010, 06:42 PM   #19 (permalink)
Junior Member
Verified Customer
 
Join Date: Jan 2008
Posts: 22
Quote:
Originally Posted by Chuck S View Post
I beleive version 2.5 has the flash uploader included you want to use that version and turn on the flash upload so you can highlight multiple photos to upload.
Worked. Thanks..
Rideharder is offline   Reply With Quote
Old April 30th, 2010, 05:34 AM   #20 (permalink)
Photopost Developer
Verified Customer
 
Chuck S's Avatar
 
Join Date: Jun 2002
Location: Abingdon,MD
Posts: 71,654
No problem.
__________________
Photopost Developer and Support Engineer

Please do not PM me for support or sales questions. Thank you for your understanding.
Chuck S is offline   Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
Potential Security Issue WB ReviewPost Bug Reports 7 August 19th, 2009 02:37 PM
PP5.5 - sql injection attempts ! flat Photopost Pro Bug Reports 6 November 4th, 2006 06:17 AM
Potential Issue WB ReviewPost Bug Reports 6 September 18th, 2006 02:44 PM
potential double post jp182 Before You Buy 1 May 31st, 2006 01:53 PM
sql injection attacks stmpspaz General Discussion 1 July 3rd, 2004 09:55 AM


All times are GMT -5. The time now is 05:18 AM.

Powered by vBulletin® Version 3.8.1
Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Search Engine Friendly URLs by vBSEO 3.2.0