Security Problem with Comments - Need Fix Asap
Issue description
Files
| Comments.zip 10,668 bytes, 46 downloads Edited by Dobliu on June 22 Zoom |
Comments
AnsteyER![]() 301 posts | I have commented out the code on search.php that searches the comments until this is resolved. If you want me to uncomment and show you my results, let me know.
The concern is that we often use the comments for sensitive private data. |
| Bernard from nearby-an-airport Associate, 6696 posts | Ok, I will do the same, and comment out the released code until a solution is find. |
| Dobliu from L'Île de Pâques (en espagnol Isla de Pascua, en rapanui Rapa Nui) 203 posts | Hello anteyER, it's a major bug in YACS. Several months ago, i have posted a solution on French forum, due i think, a missing of time it was not reused in news releases. Code below in function search file comments.php; it is running with mysql version = or > v4.1, YACS 7.12 or 8.1,
|
| Bernard from nearby-an-airport Associate, 6696 posts |
Dobliu: What is the minimum version of MySQL that supports combined SELECT statements such as the one you propose ? |
| Dobliu from L'Île de Pâques (en espagnol Isla de Pascua, en rapanui Rapa Nui) 203 posts | Bernard:
|
| Dobliu from L'Île de Pâques (en espagnol Isla de Pascua, en rapanui Rapa Nui) 203 posts | hello all where is the search comment patch ? Bernard, do you have a feeback on the suggested fix ? is it in version 8.2 ? bye ...
|
AnsteyER![]() 301 posts | I am using mysql MySQL 5.0.24 are there any particular settings that might be wrong in my version? |
AnsteyER![]() 301 posts |
So i should find comment.php and replace the function there with this code? |
| Dobliu from L'Île de Pâques (en espagnol Isla de Pascua, en rapanui Rapa Nui) 203 posts | hello ansteyER : do you have opened the folder in above comment : "Hello anteyER, it's a major bug in YACS. Several months ago, i have posted a solution on French forum, due i think, a missing of time it was not reused in news releases. Code below in function search file comments.php; it is running with mysql version = or > v4.1, YACS 7.12 or 8.1,
" |
| Bernard from nearby-an-airport Associate, 6696 posts | Dobliu, at the moment the core code of yacs does not allow for search requests in comments, nor in links, to preserve confidentiality. If you wish, please provide an updated version of search.php and of related scripts, that could be integrated in July release.
|
| Dobliu from L'Île de Pâques (en espagnol Isla de Pascua, en rapanui Rapa Nui) 203 posts | Dear YACSER'S, Find attached this latest update of comments.php file release 8.1. Don't forget to activate the search in comments (search.php) i am very busy during last days, and for the 8.5 release, i have not make a revision. Bye ...
comments.zip |
Rate this page
Posted by AnsteyER on Feb. 4, commented by Dobliu on June 22, (popular)
