Canon Digital Photography Forums  

P.O.T.N. SUPPORT SHOP IS OPEN, check it out now!

Go Back   Canon Digital Photography Forums > Exhibit Engine > Version 1.0-1.5 discussion
Register Rules FAQ Members List Search Today's Posts Mark Forums Read



Reply
 
Thread Tools Display Modes
Old 1st of June 2005 (Wed)   #1
Pekka
El General Moderator
 
Pekka's Avatar
 
Join Date: Mar 2001
Location: Hellsinki, Finland
Posts: 11,698
Default EE security notice, read this.

In all current EE installations, due to a possibility of "mysql injection" attack, please change line 8 in file slashwork.php

print mysql_error();

with

//print mysql_error();

This will void possible textual result of injection attack. EE 1.22 users are adviced to upgrade to EE 1.5RC4 and apply above fix. In next EE version all database errors are logged in editor only.

Thanks for Bernhard Mueller from http://www.sec-consult.com for reporting me this security advisory.

I have attached the fixed slashwork.php file for EE 1.5RC4:
Attached Files
File Type: zip slashwork.zip (780 Bytes, 94 views)
__________________
1D Mark III, 5D Mark II, lenses, 5-string bass
PHOTOS: Selected Snaps | Orchestra Photos | Brass Week 2009
2009 POTN BOOK AVAILABLE NOW -- click here

----------------------------

Last edited by Pekka : 1st of June 2005 (Wed) at 18:04.
Pekka is offline   Reply With Quote
This ad block will go away when you log in as member
Old 1st of June 2005 (Wed)   #2
neil_r
Cream of the Proverbial Crop
Landscape and Cityscape Photographer 2006
 
neil_r's Avatar
 
Join Date: Jan 2003
Location: Mumbai, Pune or Bengaluru
Posts: 12,782
Default Re: EE security notice, read this.

many thanks

N
__________________
Neil - © NHR Photography
There are no rules for good photographs, there are only good photographs. ~ Ansel Adams
neil_r is offline   Reply With Quote
Old 20th of July 2005 (Wed)   #3
Adrian
Member
 
Adrian's Avatar
 
Join Date: Sep 2003
Location: East Sussex, UK.
Posts: 368
Default Re: EE security notice, read this.

Much obliged,

Thanks
__________________
All the best,

Adrian...

Do not deprive me of solitude without providing me with company. (Alexander Pope 1711)

Equipment list
Adrian is offline   Reply With Quote
This ad block will go away when you log in as member
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
At first I didn't notice the people sam casey Nature & Landscapes 3 10th of July 2007 (Tue) 14:37
Be still and no one will notice athomefun Birds 3 28th of January 2007 (Sun) 16:27
I have read all I can read on lighting... kpiela Small Flash and Studio Lighting 13 17th of September 2006 (Sun) 11:22
ever notice...... saturnin General Photography Talk 9 21st of April 2006 (Fri) 10:41


All times are GMT -5. The time now is 12:09.


Powered by vBulletin® Version 3.6.12
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.
This forum is not affiliated with Canon in any way and is run as a free user helpsite by Pekka Saarinen, Helsinki Finland. You will need to register in order to be able to post messages. Cookies are required for registering and posting. HTML in messages is not allowed, plain website addresses are automatically made active by the board.