vb.org Archive

vb.org Archive (https://vborg.vbsupport.ru/index.php)
-   Modification Graveyard (https://vborg.vbsupport.ru/forumdisplay.php?f=224)
-   -   Major Additions - microAUCTIONS (Auction Classifieds) (https://vborg.vbsupport.ru/showthread.php?t=231577)

MaryTheG(r)eek 12-31-2009 04:34 PM

For those who're interesting for Classifieds rather than Auctions, I'll release microCLASSIFIEDS on Sunday or max on Monday as I need a day to finish microAUCTIONS first of all.

Maria

bigtime 12-31-2009 05:21 PM

Excellent! Thanks.

Crazyfruitbat 01-01-2010 01:13 AM

I'm afraid I had the same uninstall issues too

MaryTheG(r)eek 01-01-2010 05:00 PM

*** ATTENTION ***

All prior posts are reffering to Alpha version.
From here and then are for the stable Beta 4.1.0

Maria

micheal332001 01-01-2010 05:45 PM

Quote:

Originally Posted by BBR-APBT (Post 1941761)
Very Nice I would rather have the Classifieds with out the auctions. Still very nice.

Rated and nominated even though I have no use for it.


Quote:

Originally Posted by zelnik (Post 1942279)
Hi Maria,

Great mod and any idea when the Pro version will be available?

Since vbclassifieds looks like it will not be updated for vb4 I believe there is a big market place for a classifieds that isn't expensive like photopost classifieds

Quote:

Originally Posted by ndahiya (Post 1942911)
Microhellas, great mod, but again, too heavy for my intended use. i am looking for a basic classifieds addon (no need for auctions, payments etc). the pro version is a good idea, but it would be a bit like using a hammer to kill a fly. wonder if you plan to release a classifieds only lite version. i do not mind making a (financial) contribution if that is the bottleneck...

ndahiya

Maria's old classifieds script will be updated to vb4.0 soon as this is being done now.

As for the members that have said that maria's code is heavy and horrable is out of line as she works hard to give everyone some great add-ons to there sites.
When a coder heres things like this for there hard work puts them down and makes them think twice about making mods for release here.

People here or on any other site should be thinking how much work goes into making these scripts and thanking the coders that make these for you.

Most of the members that put add-ons down dont even know how to code,
they cannot code even in html not alone php or java.

So say thankyou to members that make these scripts for your use as they have put in alot of time to make these for you.

micheal332001 01-01-2010 05:46 PM

By the way Maria great script i will be using this for my site.

kf4eok 01-02-2010 03:02 AM

Just what I have been looking for, I just wish the Pro verson was out.
Thanks

kf4eok 01-02-2010 03:04 AM

I have a question. When I go to post a auction, then chose a category there is nothing there. How do I make the category list?

MaryTheG(r)eek 01-02-2010 06:54 AM

Quote:

Originally Posted by kf4eok (Post 1944610)
I have a question. When I go to post a auction, then chose a category there is nothing there. How do I make the category list?

From your admincp:D You can add unlimited level categories.

Maria

MaryTheG(r)eek 01-02-2010 08:14 AM

I'm so happy to say, that someone from IP: 77.54.237.148 is wasting his time to crash my microAUCTIONS in my demo installatin. Below you'll find some of his attempts:
Code:

SELECT * FROM vb4_microauctions_items WHERE active=1 AND sold=0 AND categoryid IN (5, 6, 7, 8, 9, 10, 11, 12, 13) AND (keywords LIKE '';$r = select * from vb4_user;$rr=mysql_fetch_array($r);print_r($rr);%' OR keywords LIKE '%';$r = select * from vb4_user;$rr=mysql_fetch_array($r);print_r($rr);%' OR keywords LIKE '%';$r = select * from vb4_user;$rr=mysql_fetch_array($r);print_r($rr);') ORDER BY ends ASC;
Code:

SELECT * FROM vb4_microauctions_items WHERE active=1 AND sold=0 AND categoryid IN (5, 6, 7, 8, 9, 10, 11, 12, 13) AND (keywords LIKE '';select * from vb4_user;mysql_fetch_array%' OR keywords LIKE '%';select * from vb4_user;mysql_fetch_array%' OR keywords LIKE '%';select * from vb4_user;mysql_fetch_array') ORDER BY ends ASC;
Code:

SELECT * FROM vb4_microauctions_items WHERE active=1 AND sold=0 AND categoryid IN (5, 6, 7, 8, 9, 10, 11, 12, 13) AND (keywords LIKE ';';select * from vb4_user;%' OR keywords LIKE '%;';select * from vb4_user;%' OR keywords LIKE '%;';select * from vb4_user;') ORDER BY ends ASC;
Code:

SELECT * FROM vb4_microauctions_items WHERE active=1 AND sold=0 AND categoryid IN (5, 6, 7, 8, 9, 10, 11, 12, 13) AND (keywords LIKE '';select * from vb4_user;%' OR keywords LIKE '%';select * from vb4_user;%' OR keywords LIKE '%';select * from vb4_user;') ORDER BY ends ASC;
Code:

SELECT * FROM vb4_microauctions_items WHERE active=1 AND sold=0 AND categoryid IN (1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14, 15, 16, 17, 18, 19, 20, 21, 22, 23, 24, 25, 26, 27, 28, 29, 30, 31, 32, 34, 35, 36, 37, 38, 39, 40, 41, 42, 43, 44, 45, 46, 47, 48, 49, 51, 52, 53, 54, 55, 56, 57, 58, 59, 60, 61, 62, 63, 64, 65, 66, 67, 68, 69, 70, 71, 72, 73, 74, 75, 76, 77, 78, 79, 80, 81, 82, 83, 84, 85, 86, 87, 88, 89, 90, 91, 92, 93, 94, 95, 96, 97, 98, 99, 100, 101, 102, 103, 104, 105, 106, 107, 108, 109, 110, 111, 112, 113, 114, 115, 116, 117, 118, 119, 120, 121, 122, 123, 124, 125, 126, 127, 128, 129, 130, 131, 132, 133, 134, 135, 136, 137, 138, 139, 140, 141, 142, 143, 144, 145, 146, 147, 148, 149, 150, 151, 152, 153, 154, 155, 156, 157, 158, 159, 160, 161, 162, 163, 164, 165, 166, 167, 168, 169, 170, 171, 172, 173, 174, 175, 176, 177, 178, 179, 180, 181, 182, 183, 184, 185, 186, 187, 188, 189, 190, 191, 192, 193, 194, 195, 196, 197, 198, 199, 200, 201, 202, 203, 204, 205, 206, 207, 208, 209, 210, 211) AND (location LIKE '<script>alert('Hello World!')</script>%' OR location LIKE '%<script>alert('Hello World!')</script>%' OR location LIKE '%<script>alert('Hello World!')</script>') ORDER BY ends ASC;
Code:

SELECT * FROM vb4_microauctions_items WHERE active=1 AND sold=0 AND categoryid IN (5, 6, 7, 8, 9, 10, 11, 12, 13) AND (keywords LIKE '';select * from vb4_user%' OR keywords LIKE '%';select * from vb4_user%' OR keywords LIKE '%';select * from vb4_user') ORDER BY ends ASC;
Code:

SELECT * FROM vb4_microauctions_items WHERE active=1 AND sold=0 AND categoryid IN (5, 6, 7, 8, 9, 10, 11, 12, 13) AND (keywords LIKE '';drop table vb4_microauctions_items%' OR keywords LIKE '%';drop table vb4_microauctions_items%' OR keywords LIKE '%';drop table vb4_microauctions_items') ORDER BY ends ASC;
...and many others. Of course my demo is still active, but right now I'll get any legal action against him. If someone wants to try security, lets do it on his site.

Maria


All times are GMT. The time now is 03:04 PM.

Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.

X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.03061 seconds
  • Memory Usage 1,751KB
  • Queries Executed 10 (?)
More Information
Template Usage:
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (7)bbcode_code_printable
  • (4)bbcode_quote_printable
  • (1)footer
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (6)option
  • (1)pagenav
  • (1)pagenav_curpage
  • (4)pagenav_pagelink
  • (1)post_thanks_navbar_search
  • (1)printthread
  • (10)printthreadbit
  • (1)spacer_close
  • (1)spacer_open 

Phrase Groups Available:
  • global
  • postbit
  • showthread
Included Files:
  • ./printthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/class_bbcode_alt.php
  • ./includes/class_bbcode.php
  • ./includes/functions_bigthree.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • printthread_start
  • pagenav_page
  • pagenav_complete
  • bbcode_fetch_tags
  • bbcode_create
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • printthread_post
  • printthread_complete