PhotoPost Photo Gallery Sales PhotoPost Sales Toll Free Phone Number
Mon-Fri 9am-4pm EST
  PhotoPost Photo Sharing Photo Gallery    Visualize community tm
| | | | | | | | |

Go Back   PhotoPost Community > PhotoPost Support > PhotoPost Pro Support Forums > Photopost Pro Bug Reports

Photopost Pro Bug Reports Post post installation PhotoPost Pro problems here.

Reply
 
LinkBack Thread Tools Rate Thread Display Modes
Old October 4th, 2012, 01:40 PM   #1 (permalink)
Member
Verified Customer
 
Whity's Avatar
 
Join Date: Aug 2006
Location: Russia
Posts: 85
SWFUpload !!!

In all libraries SWFUpload (2.2.0.1, probably earlier versions + version Beta), Plupload of the version is lower 1.5.4(?) is found by XSS (in SWFUpload) and CSRF (in Plupload) vulnerability!


Hash sum vulnerable file swfupload.swf
CRC32: 5d875b2f
MD5: 3a1c6cc728dddc258091a601f28a9c12
SHA-1: 17c372678aafb3bc1a7b37320b5cc1d8af433527


Hash sum file bugfixed swfupload.swf:
CRC32: 1a2edc65
MD5: c0e5c70af799aeb906b1bef3b11e9a8d
SHA-1: 7156a56ffa8a90589951637c8c2833e84f3e8d4b

https://nealpoole.com/blog/2012/05/x...load-plupload/

Last edited by Whity; October 4th, 2012 at 02:16 PM.
Whity is offline   Reply With Quote
Old October 4th, 2012, 02:25 PM   #2 (permalink)
Photopost Developer
Verified Customer
 
Chuck S's Avatar
 
Join Date: Jun 2002
Location: Abingdon,MD
Posts: 71,691
You can report any specific issues with SWFUpload to there site as we do not work with or code there application. the issue was reported months ago

Issue 376 - swfupload - XSS via ExternalInterface.call - JavaScript & Flash Upload Library - Google Project Hosting

If you are really worried about it all I can tell you to do is turn off the flash uploader.
__________________
Photopost Developer and Support Engineer

Please do not PM me for support or sales questions. Thank you for your understanding.
Chuck S is offline   Reply With Quote
Old October 6th, 2012, 05:56 AM   #3 (permalink)
Photopost Developer
Verified Customer
 
Chuck S's Avatar
 
Join Date: Jun 2002
Location: Abingdon,MD
Posts: 71,691
what kills me is I search for externalinterface as that function from reading on the net is buggy and say this issue they respond to yet the one posted above months ago they do not.

Issue 257 - swfupload - Internet Explorer silently fails to initialize ExternalInterface callbacks when swfupload.swf is cached - JavaScript & Flash Upload Library - Google Project Hosting
__________________
Photopost Developer and Support Engineer

Please do not PM me for support or sales questions. Thank you for your understanding.
Chuck S is offline   Reply With Quote
Old October 15th, 2012, 04:00 PM   #4 (permalink)
Photopost Developer
Verified Customer
 
Chuck S's Avatar
 
Join Date: Jun 2002
Location: Abingdon,MD
Posts: 71,691
More research but it appears to me your not going to see a fix for SWFUpload anytime soon. That flash uploader is a free source project and the last gold release was over 3 years ago.
__________________
Photopost Developer and Support Engineer

Please do not PM me for support or sales questions. Thank you for your understanding.
Chuck S is offline   Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
SWFUpload v2.2.0 Released Michael P General Discussion 0 April 7th, 2009 06:13 PM


All times are GMT -5. The time now is 09:50 AM.

Powered by vBulletin® Version 3.8.1
Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Search Engine Friendly URLs by vBSEO 3.2.0