Textpattern CMS support forum
You are not logged in. Register | Login | Help
- Topics: Active | Unanswered
Re: [plugin] [ORPHAN] TXPhorum 0.3 / A simple forum solution for Textpattern
If that thing above, posted by elwins, is from the plugin’s source code, I would not recommend using it. Seriously, you shouldn’t be using that in any situation. That code has some very serious security vulnerabilities.
Offline
#50 2011-12-17 05:32:36
- elwins
- Member
- From: Latvia
- Registered: 2011-08-29
- Posts: 80
Re: [plugin] [ORPHAN] TXPhorum 0.3 / A simple forum solution for Textpattern
Its default code, only place what has changed is:
$lang = array( 'section' => 'forums', 'reply_section' => 'forums_replies', 'category' => 'category name is here..', 'parent_custom_field' => 'custom1', );
But I think, that some part of that code propobly is lost, because there was problems with posting it.
Offline
Offline
Re: [plugin] [ORPHAN] TXPhorum 0.3 / A simple forum solution for Textpattern
elwins
I’ve already donethe category thing, and more besides, in my (unreleased) modded version. I can’t remember how many of the security loopholes I closed offhand. Maybe some, maybe none — it was a loooong time ago I last looked at it. I’m due to revisit this over the next few weeks if you can wait a bit.
Gocom
In case you’re at a loose end over the holidays, could you please jot down some of the security issues and let me have them by e-mail. I can see a bunch of them in the code above (unescaped things, lack of doSlash(), etc) which I’ve probably caught already, but in case I missed any I’d appreciate your expertise on this. Thanks, man.
Last edited by Bloke (2011-12-17 08:23:00)
The smd plugin menagerie — for when you need one more gribble of power from Textpattern. Bleeding-edge code available on GitHub.
Txp Builders – finely-crafted code, design and Txp
Online
#53 2011-12-17 14:34:26
- elwins
- Member
- From: Latvia
- Registered: 2011-08-29
- Posts: 80
Re: [plugin] [ORPHAN] TXPhorum 0.3 / A simple forum solution for Textpattern
Bloke wrote:
I’ve already donethe category thing, and more besides, in my (unreleased) modded version. I can’t remember how many of the security loopholes I closed offhand. Maybe some, maybe none — it was a loooong time ago I last looked at it. I’m due to revisit this over the next few weeks if you can wait a bit.
maybe you can give me now that category thing? I Just need to get visual side done, and then later, security side.
Last edited by elwins (2011-12-17 14:34:55)
Offline
Re: [plugin] [ORPHAN] TXPhorum 0.3 / A simple forum solution for Textpattern
elwins wrote:
maybe you can give me now that category thing? I Just need to get visual side done, and then later, security side.
Not right now. I’m travelling and it’s at home. maybe when I get back.
The smd plugin menagerie — for when you need one more gribble of power from Textpattern. Bleeding-edge code available on GitHub.
Txp Builders – finely-crafted code, design and Txp
Online
#55 2011-12-18 19:00:06
- elwins
- Member
- From: Latvia
- Registered: 2011-08-29
- Posts: 80
Re: [plugin] [ORPHAN] TXPhorum 0.3 / A simple forum solution for Textpattern
ok, when will you be back at home? :)
Offline
#56 2012-01-12 16:08:56
- elwins
- Member
- From: Latvia
- Registered: 2011-08-29
- Posts: 80
Re: [plugin] [ORPHAN] TXPhorum 0.3 / A simple forum solution for Textpattern
Someone then can help me?
Offline