Members: 16,996
Threads: 38,846
Posts: 159,391
Online: 21

Newest Member: Kl_broka@rediffmail.com


Odoo.tv - Outdoor Television


Sedo - Domains kaufen und verkaufen das Projekt mambers.com steht zum Verkauf Besucherstatistiken von mambers.com etracker® Web-Controlling statt Logfile-Analyse

Go Back   Mambers.com > Archive > Mambo 4.5 > Mambo 4.5 Security

 
 
LinkBack Thread Tools Display Modes
Old 28.02.2005, 06:59   #1 (permalink)
Baby Mamber
 
Join Date: Jan 2005
Posts: 12
ivytony is on a distinguished road
Default Mamblog 1.0 RC2 security concern:

Hi, everybody:

I downloaded and installed Mamblog 1.0 RC2 from mamboportal.com

after installation, I found that when common users tried to make blog entries, the WYSIWYG editor allows the user to delete pictures from media folder (which is normally used in the backend of mambo media manager). In this way, some malignant users may delete all the pictures that are used in the mambo system.

any ideas as to how to fix this problem? thanks

Quote:
Mamblog 1.0 RC 2 (Downloads)
A user blog system that allows for users to sign up to write their own blogs.
__________________
Be the Best! Successful PhD
ivytony is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Sponsored Links
Old 28.02.2005, 08:35   #2 (permalink)
Baby Mamber
 
Join Date: Nov 2004
Posts: 9
MrSleep is on a distinguished road
Default Re: Mamblog 1.0 RC2 security concern:

Whats the version of WYSIWYG? Insert this code in file query image:

Code:
if (! $my->id) {
	require( "path_to_admin/administrator/includes/auth.php" );
}
MrSleep is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
 

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
PartyStaff 1.0 RC2 released! mightyb Development Announcements 68 12.09.2005 16:50
Mambo und Forensystem SMF 1.0 RC2 nexius Installation 0 10.11.2004 20:14
Traduzione Mamblog 1.0 RC2 Pippolo Componenti 2 13.09.2004 13:15
PartyStaff 1.0 RC2 in italiano Waterloo Annunci 5 04.08.2004 09:08


All times are GMT +2. The time now is 02:26.

Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.1.0
A vBSkinworks Design
© Copyright 2004-2008 by Arthur Konze Webdesign.