Modify

Opened 10 years ago

Closed 10 years ago

Last modified 8 years ago

#782 closed Bug/Fehler (fixed)

FCKEditor: Filemanager-Sicherheit

Reported by: noRiddle Owned by: somebody
Priority: hoch Milestone: modified-shop-1.06-SP4
Component: Admin Version: 1.06
Keywords: Cc:
Blocked By: Blocking:

Description (last modified by Torsten Riemer)

Die Absicherung des FCK-Editor-Filemanagers (Filebrowser) ist mittels des flag admin in der Tabelle sessions lediglich für db-basiertes Session-Handling gemacht worden, nicht jedoch für file-basiertes.

Entweder müsste man dann file-basiertes Session-Handling ausschließen oder es fixen, zumal es auch niemand weiß und der Filemanager bei file-basiertem Session-Handling keine Funktion hat.

Bitte dazu auch diesen Thread beachten, wo ich einen Lösungsvorschlag gemacht habe: FCKEditor: Filemanager-Sicherheit

Gruß,
noRiddle

Attachments (0)

Change History (8)

comment:1 by Torsten Riemer, 10 years ago

Milestone: modified-shop-2.00modified-shop-1.06-SP4
Version: 2.01.06

comment:2 by Torsten Riemer, 10 years ago

Description: modified (diff)

comment:3 by Ronald Parcinski, 10 years ago

comment:4 by Torsten Riemer, 10 years ago

Resolution: fixed
Status: newclosed

In 9448:

Fix #782 - update security for FCKeditor in /branches/modified-shop-1.06-SP4

comment:5 by Torsten Riemer, 10 years ago

Resolution: fixed
Status: closedreopened

Bitte nochmal prüfen, ob in Datei "/admin/includes/modules/fckeditor/editor/filemanager/connectors/php/config.php":

require('../../../../../../configure.php');

geändert werden sollte in:

require_once('../../../../../../configure.php');

Siehe dazu: FCKEditor: Filemanager-Sicherheit

comment:6 by Torsten Riemer, 10 years ago

Priority: normalhoch

comment:7 by Gerhard Waldemair, 10 years ago

Resolution: fixed
Status: reopenedclosed

In 9670:

fix #782

comment:8 by Torsten Riemer, 8 years ago

Reporter: changed from anonymous to noRiddle

Modify Ticket

Action
as closed The owner will remain somebody.
The resolution will be deleted. Next status will be 'reopened'.

Add Comment


E-mail address and name can be saved in the Preferences .
 
Note: See TracTickets for help on using tickets.