PhotoPost Photo Gallery Sales PhotoPost Sales Toll Free Phone Number
Mon-Fri 9am-4pm EST
  PhotoPost Photo Sharing Photo Gallery    Visualize community tm
| | | | | | | | |

Go Back   PhotoPost Community > PhotoPost Support > ReviewPost Pro Support Forums > ReviewPost Bug Reports

ReviewPost Bug Reports Let us know about any post installation problems you are having with ReviewPost.

Reply
 
LinkBack Thread Tools Rate Thread Display Modes
Old September 18th, 2006, 01:13 PM   #1 (permalink)
WB
Member
Verified Customer
 
Join Date: Jan 2002
Posts: 265
Potential Issue

Chuck:

Could you comment on:

http://secunia.com/advisories/21971/

the original advisory section listed there.

It mentions 2.5 but notes that other versions could still be vulnerable.

Could you check that out to see if that is still an issue with 3.3 and above?

Thanks!
WB is offline   Reply With Quote
Old September 18th, 2006, 01:24 PM   #2 (permalink)
Photopost Developer
Verified Customer
 
Chuck S's Avatar
 
Join Date: Jun 2002
Location: Abingdon,MD
Posts: 71,683
Doesnt seem to be an issue that I see

http://www.reeftalk.com/reviews/inde...k.com/test.php
__________________
Photopost Developer and Support Engineer

Please do not PM me for support or sales questions. Thank you for your understanding.
Chuck S is offline   Reply With Quote
Old September 18th, 2006, 01:32 PM   #3 (permalink)
PhotoPost Developer
Verified Customer
 
Join Date: Jan 2002
Posts: 11,834
I believe that all the security code added to all our products came out in RP3.0 which was still over a year ago.

RP 2.5 was released back in 1/2004.
__________________
Please do not PM me for support or sales questions. Thank you for your understanding.
Michael P is offline   Reply With Quote
Old September 18th, 2006, 01:33 PM   #4 (permalink)
WB
Member
Verified Customer
 
Join Date: Jan 2002
Posts: 265
Chuck:

Thanks.

The URL looks like it has RR_PATH versus RP_PATH in it. I assume that was a typo and that the test was with RP_PATH.

On a more general note, so 3.3x versions properly verify input pass to variables like 'RP_PATH' such that similar types of remote includes, etc. aren't an issue?

Thanks for the quick response!
WB is offline   Reply With Quote
Old September 18th, 2006, 01:36 PM   #5 (permalink)
WB
Member
Verified Customer
 
Join Date: Jan 2002
Posts: 265
Quote:
Originally Posted by Michael P View Post
I believe that all the security code added to all our products came out in RP3.0 which was still over a year ago.

RP 2.5 was released back in 1/2004.
Michael:

Thanks, just saw your message after posting my reply to Chuck.

So I take it then that generally speaking the security code added properly verifies input pass to variables like 'RP_PATH' such that similar types of remote includes, etc. aren't an issue?
WB is offline   Reply With Quote
Old September 18th, 2006, 01:43 PM   #6 (permalink)
Photopost Developer
Verified Customer
 
Chuck S's Avatar
 
Join Date: Jun 2002
Location: Abingdon,MD
Posts: 71,683
We only define variables in our typecast function.

$RP_PATH is only set in config file

The issue with earlier versions is that we got all variables through a standard $_GET from the url but now we typecast only certain variables and define them either as INT and STRING
__________________
Photopost Developer and Support Engineer

Please do not PM me for support or sales questions. Thank you for your understanding.
Chuck S is offline   Reply With Quote
Old September 18th, 2006, 02:44 PM   #7 (permalink)
WB
Member
Verified Customer
 
Join Date: Jan 2002
Posts: 265
I see, thanks for the explanation.
WB is offline   Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
PP v5.31 issue Zigw Photopost Pro Installation & Upgrades 4 July 11th, 2006 08:28 AM
Potential bug? Report Photo issue ludachris Installs and Upgrade - vBulletin 3.5.X 1 June 21st, 2006 02:52 PM
potential double post jp182 Before You Buy 1 May 31st, 2006 01:53 PM
Another What's New Issue Xil Ze Installs and Upgrade - vBulletin 3.0.X 3 July 10th, 2005 09:37 PM
Register Issue Alteczen Photopost Pro Installation & Upgrades 2 July 16th, 2004 03:23 PM


All times are GMT -5. The time now is 02:15 AM.

Powered by vBulletin® Version 3.8.1
Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Search Engine Friendly URLs by vBSEO 3.2.0