Topics

User Functions

Events

There are no upcoming events

What's New

Stories

No new stories

Comments last 2 weeks

No new comments

Trackbacks last 2 weeks

No new trackback comments

Links last 2 weeks

No recent new links

NEW FILES last 14 days

No new files

Welcome to Geeklog Saturday, May 18 2013 @ 04:47 PM EDT

> >

Geeklog 1.3.9sr2 and 1.3.8-1sr6

Security
  • Friday, October 08 2004 @ 02:00 PM EDT
  • Contributed by:
  • Views:
    6,830
Geeklog 1.3.9sr2 and 1.3.8-1sr6 fix the following security issues:
  1. A cross site scripting issue, due to the use of the (unfiltered) variable $topic in most of the language files (thanks to the anonymous submitter of bug #293).
  2. It was possible to post comments to stories and polls for which comments had been disabled. The comments were never displayed, though, but did show up in the What's New block.

The upgrade to 1.3.9sr2 also includes a lib-plugins.php that fixes problems with plugins on PHP 5. The complete 1.3.9sr2 tarball also includes updated PEAR packages that should resolve email problems that some users had (see this story for details).

For those who made changes in the language files, it may be easier to apply the following fix manually: The 3rd text string in the $LANG05 array should read ' for topic %s' (instead of using $topic). This only fixes the XSS vulnerability but not the comment posting bug, for which comment.php has to be replaced.

Users still running on earlier versions may also want to apply the above fix manually. I'd like to point out again, though, that there is no offical support for versions older than 1.3.8 any more and that you should at the very least be running Geeklog 1.3.7sr5 plus the comment posting fix linked from this story.

The following comments are owned by whomever posted them. This site is not responsible for what they say.

  • Geeklog 1.3.9sr2 and 1.3.8-1sr6
  • Authored by:geeklog-fan on Saturday, October 09 2004 @ 07:30 AM EDT
thank you for the update! can't wait till 1.3.10 is released :)

Post a Comment

Your Name
Create Account
Allowed HTML Tags:
 

Security code
This question is for testing whether you are a human visitor and to prevent automated spam submissions.

What code is in the image?
Enter the bolded text, case sensitive!
Important Stuff
  • Please try to keep posts on topic.
  • Try to reply to other people comments instead of starting new threads.
  • Read other people's messages before posting your own to avoid simply duplicating what has already been said.
  • Use a clear subject that describes what your message is about.
  • Your email address will NOT be made public.