PhotoPost Photo Gallery Sales PhotoPost Sales Toll Free Phone Number
Mon-Fri 9am-4pm EST
  PhotoPost Photo Sharing Photo Gallery    Visualize community tm
| | | | | | | | |

Go Back   PhotoPost Community > PhotoPost Support > ReviewPost Pro Support Forums > ReviewPost Bug Reports

ReviewPost Bug Reports Let us know about any post installation problems you are having with ReviewPost.

Reply
 
LinkBack Thread Tools Rate Thread Display Modes
Old August 19th, 2009, 11:09 AM   #1 (permalink)
WB
Member
Verified Customer
 
Join Date: Jan 2002
Posts: 265
Potential Security Issue

Chuck:

Can you comment on:

Secunia RP Advisory

Does that impact standalone installs as well? Versions 3.x as well as 4.x?

Thank you.
WB is offline   Reply With Quote
Old August 19th, 2009, 11:57 AM   #2 (permalink)
Photopost Developer
Verified Customer
 
Chuck S's Avatar
 
Join Date: Jun 2002
Location: Abingdon,MD
Posts: 71,704
Not really sure there is no information on what they say the issue is

I am not sure why they classify the date field as a cross site security issue. This is not a field users in anyway input data too. It is only used internally by the program to enter the date a product or review is uploaded. It can only be an integer and is defined totally in the program by this line

Cross-site scripting - Wikipedia, the free encyclopedia

I would like to see examples of what they mean here. The date field is filled in by a line in the software not an external field

Code:
Content visible to verified customers only.
__________________
Photopost Developer and Support Engineer

Please do not PM me for support or sales questions. Thank you for your understanding.
Chuck S is offline   Reply With Quote
Old August 19th, 2009, 12:03 PM   #3 (permalink)
Photopost Developer
Verified Customer
 
Chuck S's Avatar
 
Join Date: Jun 2002
Location: Abingdon,MD
Posts: 71,704
I am further reading on this they say date passed is not sanatized on showproduct

You can surely add date to the code in showproduct.php

Code:
Content visible to verified customers only.
__________________
Photopost Developer and Support Engineer

Please do not PM me for support or sales questions. Thank you for your understanding.
Chuck S is offline   Reply With Quote
Old August 19th, 2009, 02:03 PM   #4 (permalink)
WB
Member
Verified Customer
 
Join Date: Jan 2002
Posts: 265
Quote:
Originally Posted by Chuck S View Post
Not really sure there is no information on what they say the issue is

I am not sure why they classify the date field as a cross site security issue. This is not a field users in anyway input data too.
On page two of the secunia advisory, there's a link to the original advisory. That has some samples of using date to show the document cookie, hence the XSS designation.

One of their examples is:

http://www.techimo.com/reviews/showproduct.php?product=473&cat=24&date="><script>alert(document.cookie);</script>

which shows the cookie.
WB is offline   Reply With Quote
Old August 19th, 2009, 02:09 PM   #5 (permalink)
Photopost Developer
Verified Customer
 
Chuck S's Avatar
 
Join Date: Jun 2002
Location: Abingdon,MD
Posts: 71,704
Just do what is posted in my last post should take care of that
__________________
Photopost Developer and Support Engineer

Please do not PM me for support or sales questions. Thank you for your understanding.
Chuck S is offline   Reply With Quote
Old August 19th, 2009, 02:13 PM   #6 (permalink)
Photopost Developer
Verified Customer
 
Chuck S's Avatar
 
Join Date: Jun 2002
Location: Abingdon,MD
Posts: 71,704
There example code does not seem to do anything or allow anything on my site but no worries adding the date to the typecase function makes sure it has to be an integer.
__________________
Photopost Developer and Support Engineer

Please do not PM me for support or sales questions. Thank you for your understanding.
Chuck S is offline   Reply With Quote
Old August 19th, 2009, 02:14 PM   #7 (permalink)
WB
Member
Verified Customer
 
Join Date: Jan 2002
Posts: 265
Thanks.

We'll make that change.
WB is offline   Reply With Quote
Old August 19th, 2009, 02:37 PM   #8 (permalink)
Photopost Developer
Verified Customer
 
Chuck S's Avatar
 
Join Date: Jun 2002
Location: Abingdon,MD
Posts: 71,704
Not a problem at all enjoy your day.
__________________
Photopost Developer and Support Engineer

Please do not PM me for support or sales questions. Thank you for your understanding.
Chuck S is offline   Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
RP 3.33 & phpBB3 Potential Issue [Forum Database Prefix] Swanny ReviewPost Installation & Upgrades 5 May 14th, 2008 09:29 AM
Security Issue?? mkdevo Photopost Pro How Do I...? 2 September 26th, 2006 10:15 PM
Potential Issue WB ReviewPost Bug Reports 6 September 18th, 2006 02:44 PM
Potential bug? Report Photo issue ludachris Installs and Upgrade - vBulletin 3.5.X 1 June 21st, 2006 02:52 PM
Security issue? d3nnis Photopost Pro Installation & Upgrades 2 January 17th, 2006 08:08 PM


All times are GMT -5. The time now is 08:13 PM.

Powered by vBulletin® Version 3.8.1
Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Search Engine Friendly URLs by vBSEO 3.2.0