![]() |
stristr error
I'm getting a very similar error as was mentioned in this thread
I upgraded to ibProArcade v2.7.2+ yesterday and I'm getting this error at the top of the index page of the arcade. Quote:
|
Just updated and also have this error.
|
<a href="https://vborg.vbsupport.ru/showpost.php?p=2304863&postcount=13" target="_blank">https://vborg.vbsupport.ru/showp...3&postcount=13</a>
|
@Hippy
I tried those changes and it did not effect this error. The error points to line 5550... I've looked at the arcade.php file and line 5550 comes up as.... PHP Code:
PHP Code:
Any help would be appreciated. |
compare v2.7.1 and 2.7.2 and remove or comment out that code and the link above
stangger5 posted what will work in replace of till Mrz figures out the issue it fixes the security issue I updated 20+ arcade and 1/4 of them don't like this code.. it's a server issue I am guessing |
I have used stangger5 fix but was getting the reported issue with stristr on a customer forum.
I did the below edit, code will do the same and is simpler. In arcade.php search for the ibp_cleansql function, search for PHP Code:
PHP Code:
PHP Code:
PHP Code:
PHP Code:
Though I must admit that Mrz fixed the 2.7.1 security issue rather uglily... That bit of code could remove actual correct content ... |
I didnt upgrade to 2.7.2 for just two edits..
My one edit to the arcade.php file and the mod_arcade.php.. So my arcade doesnt have any of the: PHP Code:
Thanks for the code update VBDev !! :up: |
1 Attachment(s)
Quote:
Code:
function ibp_cleansql($value) I am just wondering at this moment.. thanks |
Yep.
Dunno why but I didn't had that error on my install but a customer had the issue. Anyways I don't know the root cause of this function but honestly that shouldn't be done like that... It removes potential words from comments for example... That sucks :p --------------- Added [DATE]1331204033[/DATE] at [TIME]1331204033[/TIME] --------------- Quote:
|
The security issue was s_id,, which allowed it to be a string when it was supposed to be a int,, that is what allowed the exploit.
Comments should be ok because of the way strings are put in the database.. |
Quote:
|
Quote:
IMO, IBProArcade really needs a cleanup of the code one day... Quote:
|
|
Quote:
|
why you confused sir
|
Quote:
Quote:
Quote:
PHP Code:
|
Quote:
Fatal error: Call to undefined function: str_ireplace() in /home/ls2com/public_html/forums/arcade.php on line 5601 2.7.2 does it now required PHP5? my code in arcade.php Code:
// remove any SQL-commands |
Hey
Quote:
Greetings Jo |
Quote:
|
Quote:
|
Hey guys -
Is it possible for stangger5 and Hippy to get "joint custody" of this script since Mr Z is too busy? Having to sift through multiple threads with lengthy discussions about which code to use, what edits are best and why 2.7.1 is the version to use and not 2.72 (???!!!???) gets pretty confusing for us non-coders. For a long time now, this script is has been officially dormant with new versions few and far between, while fixes (or not) abound in the forums. I understand the original author has expanded his family and his outside comimtments, and I'm not trying to criticize him in the least. Without him, this wouldn't be here in the first place. That said, stangger5 and Hippy have been doing most of the heaving lifting on this script for some time now, and it seems it would be to everyone's benefit to give them equal access to the official releases along with Mr. Z to make this an equal partnership. The code could get back on track to be the awesome script it could be, instead of limping along and propped up with forum post file edits. They both have demonstrated a commitment to the script, and on their own sites have expanded its capabilities. Let's give 'em a chance to take this script to new heights instead of limiting their talents to covering it with bandaids. Do I hear an "amen?" |
in my sig youll find a link to the post I made with everything youll needl I did the reading and sifting for you all..
If anyone stangger5 is the man.. when it come to this arcade.. but i will be here helping all the same to keep this arcade alive |
Quote:
|
Quote:
In case anyone cares, the new version of Arcade DOES require PHP5, str_ireplace is not available in PHP4. |
Quote:
https://vborg.vbsupport.ru/attachmen...6&d=1335142146 |
Quote:
do we all use the arcade.php you linked to here or do we do the edits that the rest of the thread talks about as the 2 are completely different |
I did the eidtes in the attached file to make it easy for everyone
|
Hi,
in the forum it works fine. But in the VB admin section (main settings) these errors displayed : Code:
Deprecated: Assigning the return value of new by reference is deprecated in /usr/www/xxxx/arcade.php on line 897 --------------- Added [DATE]1378141057[/DATE] at [TIME]1378141057[/TIME] --------------- Solved. modify of arcade.php in admincp folder. |
<a href="https://vborg.vbsupport.ru/showthread.php?p=2328579" target="_blank">https://vborg.vbsupport.ru/showthread.php?p=2328579</a>
I also have one posted here with the edits |
All times are GMT. The time now is 05:51 PM. |
Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.
X vBulletin 3.8.12 by vBS Debug Information | |
---|---|
|
|
![]() |
|
Template Usage:
Phrase Groups Available:
|
Included Files:
Hooks Called:
|