Members: 16,996
Threads: 38,846
Posts: 159,391
Online: 26

Newest Member: Kl_broka@rediffmail.com


Odoo.tv - Outdoor Television


Sedo - Domains kaufen und verkaufen das Projekt mambers.com steht zum Verkauf Besucherstatistiken von mambers.com etracker® Web-Controlling statt Logfile-Analyse

Go Back   Mambers.com > Mambo 4.5.1 > Mambo 4.5.1 Bugs

Reply
 
LinkBack Thread Tools Display Modes
Old 06.06.2005, 13:07   #1 (permalink)
Baby Mamber
 
Join Date: Apr 2004
Posts: 21
Bernard is on a distinguished road
Angry Bug with special chars after last security patch

hi !

i applied the last secrity patch and have the following issue. mambo does not convert any special charachters to html-codes anymore.

before i was able to paste content from a croatian site and had all the croatian characters in my iso-8859-1 site coded as html chars. that does not work anymore when applying the patch or using mambo 4.5.2.2.


Example Text taken from www.iskon.hr (to see the special characters that i mean):


"Studija je pokazala da većini pušača treba nekoliko pokušaja odvikavanja od te navike prije nego što potpuno prestanu pušiti, tvrdi Walter Farke iz Njemačkog centra za ovisnosti . "


Should be in html (it was like this in mambo before the security patch):

"Studija je pokazala da većini pušača treba nekoliko
pokušaja odvikavanja od te navike prije nego što potpuno prestanu pušiti,
tvrdi Walter Farke iz Njemačkog centra za ovisnosti . "


Anyone can help ?

Thanx in forward
Bernard is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Sponsored Links
Old 10.06.2005, 00:18   #2 (permalink)
Junior Mamber
 
indy68's Avatar
 
Join Date: Nov 2004
Location: Belgium
Posts: 30
indy68 is on a distinguished road
Default Re: Bug with special chars after last security patch

I've done the same patch and noticed when new content is added, html-code is deleted from the content.
example : <a href="...">{mosimage}</a> is just {mosimage} after saving.
I guess this is the same problem
indy68 is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 14.06.2005, 17:30   #3 (permalink)
Junior Mamber
 
indy68's Avatar
 
Join Date: Nov 2004
Location: Belgium
Posts: 30
indy68 is on a distinguished road
Default Re: Bug with special chars after last security patch

I've been looking into this a little further. It seems to be an php-input-filter-class that has been inplemented with this patch that is causing a lot of mischief.

This class is intended to make mambo more secure by preventing users to input "malicious" code into the content.

Although I can understand this COULD be a security issue for website with a large number of contributing users, my current implementation of mambo is for sites with between 1 and 20 users.

The bottom line is that "richer" content (like the use of javascript) is no longer possible in Mambo 4.5.2.2 and existing content will be stripped (=defaced) when it's saved after installation of the patch.

Yet this richer content is neccesary for my websites as it adds functionality to it that Mambo can not. I understand that mambots, components or modules would be the better (safe) solution to this problem. Unfortunately these bots, modules or components are available yet.

As there is no way to disable this filter or to define a set of trusted users (like the backend users), I've decided to wait with this 4.5.2.2 patch and stick with the older versions, until I find a way to install it without the input-filter.

You can test the effects of the php-input-filter that was used here : http://cyberai.com/inputfilter/index.php

If you use this string : <a href="javascript:openIT(test.jpg')"><img src="test.jpg" width="72" height="54" hspace="6" alt="click for bigger photo" title="click for bigger photo" border="0" /></a>,
you will see not a lot is left after the execution ...
indy68 is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 15.06.2005, 12:41   #4 (permalink)
Junior Mamber
 
indy68's Avatar
 
Join Date: Nov 2004
Location: Belgium
Posts: 30
indy68 is on a distinguished road
Default Re: Bug with special chars after last security patch

Security patch 4.5.2.3 should correct this problem.

Last edited by indy68; 16.06.2005 at 11:42.
indy68 is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
Warning - latest security patch is malicious conficio Mambo 4.5.1 Installation and Upgrades 2 07.06.2005 01:35
Important security Patch! eyezberg Community Announcements 2 05.06.2005 02:02
Security Patch for Community Builder 1 beta 4 MamboJoe Mambo 4.5 Security 0 14.03.2005 08:30
Ako Comment Security Patch Bug Baal Mambo 4.5.1 Installation and Upgrades 1 05.03.2005 15:23
username-restriction (no special chars) ricardo.cristof Mambo 4.5.1 Bugs 4 18.09.2004 22:38


All times are GMT +2. The time now is 08:40.

Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.1.0
A vBSkinworks Design
© Copyright 2004-2008 by Arthur Konze Webdesign.