![]() |
XSS Vulnerability Patched!
All running Beta 1 prior to 11/19/05 are strongly encouraged to apply this patch or download the updated file then overwrite. To patch this security risk find the following in journal.php(Find and Replace All Instaces): PHP Code:
PHP Code:
PHP Code:
PHP Code:
|
upgraded from 1.0.1 to current beta and i'm getting
Invalid SQL: SELECT journals.journal_id, journals.journalname, journals.journaldesc, journals.journalist, journals.journalist_id, entrycount, commentcount, usertextfield.jbuddylist, ipaddress, journals.lastentry, journals.lastentry_date, journals.private, journals.lastentry_id, journals.lastentry_misc, journals.status, journals.journalviews, journals.journal_totalrating AS totalrating, journals.journal_totalvotes AS totalvotes FROM journals AS journals LEFT JOIN usertextfield AS usertextfield ON (journals.journalist_id=usertextfield.userid) WHERE journal_id IN(1,2,3,4,5,6,8,9) ORDER BY LIMIT 0,10 on journal.php although everything seems ok if i access the journals directly via user name... really confused need some help ehre. |
Quote:
|
yeah i just went in and saved the current settings and its all working now...
sorry dumbass moment there... jesus im special, sorry |
Quote:
|
yeah thing is so far i've managed quite a few decades of idiocy......;) by the way great work on the hack! The upgrade was simplicity after my own mistake! keep it up!
|
Quote:
|
nice one..i know on another forum blog software has been asked for but with a few more additions on here and this is it to be honest! It'd be nice to have a collapsable comments block so you could expand the comments under a journal entry..or some kind of alternative thread views and obviously a now listening too and all the like.
Anyway you'll have a better idea of what you want to do with it than me. I'm just happy its still supported seeing as everyone else is going 3.5 and im staying 3.0.x :D |
Quote:
also 1.5 will be the last version of vB Journal on 3.0.x, future versions past 1.5 will be designed for 3.5.x. I felt as though I owed it the users to include a more stable and featured version before I migrate to 3.5. |
just the intergration if possible of the the linear , hybrid and threaded display modes.
so when you clicked on comments you'd be taken to comments that are pretty much styled like showthread.php with the ability to change the display type. It would be nice to see the comments like showthread.php making the journal entry and comments a thread unto themselves, then you could support more display views, the postbit templates, use the quick reply box as the add new comment and other bits and bats.You could potentially do stuff for journal attachments as well but that would mean changes to newattachments.php and attachment.php. However thats a big change and would mean much more intergration work. It would however be nice to have the comments similar to postbit and postbit_legacy so you can see user avatars etc. |
Quote:
|
I tried to upgrade but the old templates still look the same... (your signage on the bottom) and I get a database error even if I update the journals in admincp
Quote:
|
entire editor is gone through out the site.
An obvious error in changing the hacked code. any idea what file would do that? As in what file would handle the wysiwyg editor? or template? It seems to have disapeared thru out the site. Thanks. |
For some reason editor_toolbar_wysiwyg has replaced editor_clientscript template...
newpost_usernamecode posticons these templates are not in the 3.0.x setup. How do I adjust things back to call proper templates? Please and thank you. How would that happen? Please advise. |
what version are you running and can you please state your errors more conscisely.
|
Quote:
It happens whenever I try to goto journal.php and adjusting the admincp does nothing.... unless you need a specific edit this was on 3.0.3 board and updating to your latest version here. your other port for 3.5 works like a charm I just have a 3.0.x site that needs updating... |
it should have updated the old templates...you did not get any errors while upgrading?
|
Quote:
thank you. |
Quote:
|
Quote:
|
Quote:
I will manually add the templates but the SQL error what would that be from? |
if you did not receive errors you can rebuild the styles through admincp and hopefully the templates will update.
i think it may be caused by the space between ON and '('. im currently tinkering with beta 2 so once im done adding the features to beta 2 ill go and see if removing the spaces does anything. |
could it be because your 3.0.7 and this was on 3.0.3?
Ok for this site how do I go about reverting? I want them to at least have thier old journals back. |
Quote:
|
Quote:
|
Quote:
|
Can users have several journals for travel etc?
|
Quote:
|
thanks for the info. Shame it doesnt work for me.
|
dont have time to look into this in great detail myself but i need to be able to stop administrators being able to read peoples or just other administrators private journals / entries . One admin read another admins journals private entries...caused mass havoc...:s would be nice to be able to set it so admins can't read things set private to other admins.
:surprised: |
i made a quick change in function verify_viewer($id, $type) which works but i've had to hard code it i'd like a nicer solution for it but it'll do for a temp solution.
|
remove all clauses of
PHP Code:
|
that kind of been my approach but i've set it so that one administrators account can't be viewed by any other admin account but he can see every other administrators journal and entries.
Any chances of getting some kind of permissions settings for this in the next version? i've had to make other changes in journal.php to make sure no one who knows or tries to guess an entry link can view it via printentry or editentry..even delete entry if someone just wants to try and mangle a journal.... |
probably not the next beta but the one after it definately:) my current version i am working on overhauls the front end message system.
|
Quote:
is it now possible to sort the journals by categories and to change the autor? |
Quote:
|
Quote:
|
Quote:
|
any luck on that error I was getting? Any update I can beta test?
|
Quote:
|
All times are GMT. The time now is 03:36 AM. |
Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.
X vBulletin 3.8.12 by vBS Debug Information | |
---|---|
|
|
![]() |
|
Template Usage:
Phrase Groups Available:
|
Included Files:
Hooks Called:
|