Search found 7 matches

by Schmoe
Wed Jul 28, 2004 9:13 pm
Forum: General discussions
Topic: Serious Security Issue In PHPMyFAQ 1.4
Replies: 32
Views: 47030

Safemode off here too, but still having the problem.

Chad: If you keep clicking on the Image Manager, it eventually comes up? Even if I click over and over, I never get anything but a blank box...
by Schmoe
Wed Jul 28, 2004 1:40 pm
Forum: General discussions
Topic: Serious Security Issue In PHPMyFAQ 1.4
Replies: 32
Views: 47030

Hi,
I made the replacements in both files, but unfortunately it didn't fix the problem.
by Schmoe
Wed Jul 28, 2004 10:35 am
Forum: General discussions
Topic: Serious Security Issue In PHPMyFAQ 1.4
Replies: 32
Views: 47030

I do get one error if the session has expired:
Notice: Undefined variable: auth in /admin/editor/plugins/ImageManager/manager.php on line 49
You are not authorized.

...but maybe this is how the authentication is supposed to work?
by Schmoe
Wed Jul 28, 2004 9:17 am
Forum: General discussions
Topic: Serious Security Issue In PHPMyFAQ 1.4
Replies: 32
Views: 47030

Hi,
is your FAQ online? Can I test it there?

Unfortunately, the faq I am testing on is local :(

I turned on error reporting as instructed, but I am not getting any error results. :?: :?: :?:

I tried both error_reporting(E_ALL); and ini_set('error_reporting', E_ALL); , but neither produced any ...
by Schmoe
Tue Jul 27, 2004 10:26 am
Forum: General discussions
Topic: Serious Security Issue In PHPMyFAQ 1.4
Replies: 32
Views: 47030

Thanks again. :)

I'm still having the issue with a blank page/box instead of the image manager. I even cleared the browser cache just to make sure that I'm not getting the old version of image-manager.js, but the problem persists in both IE and Mozilla.
by Schmoe
Tue Jul 27, 2004 8:28 am
Forum: General discussions
Topic: Serious Security Issue In PHPMyFAQ 1.4
Replies: 32
Views: 47030

Thorsten,
I'm just getting a blank page with the new manager.php. Also, there's another very serious security issue that I sent you info on via email.

Thanks for all your great work!
by Schmoe
Tue Jul 27, 2004 4:36 am
Forum: General discussions
Topic: Serious Security Issue In PHPMyFAQ 1.4
Replies: 32
Views: 47030

Serious Security Issue In PHPMyFAQ 1.4

Hi,
I've been using phpmyfaq through the last 4 versions and it's great. But, I've found a serious security issue in the wysiwyg image manager in the latest release. The image manager can be accessed by anyone on the web without logging in :(

All someone has to do to access the image manager is ...