Get XOOPS XOOPSXOOPS FAQFAQ ForumsForums NewsNews ThemesThemes ModulesModules
New Posts New Topics All Posts All Forums Index General Modules Themes Development International XOOPS.org

Search

Donat-O-Meter

Make donations with PayPal!
Stats
Goal: $100.00
Due Date: May 31
Gross Amount: $65.00
Net Balance: $61.80
Left to go: $38.20

Donations
studioC  ($25)May-17
Anonymous ($15)May-16
Anonymous ($25)May-4

Learn XOOPS Core

Local Support

Advertisement

XOOPS Code hosted on SourceForge

Cumulus Tag Cloud

2 2.5 2.5.5 2.6 3.0 90 2013 Abuse alimento AntiHarvesting AntiMalUser AntiSpam API ASP Beats billige black Blocks blue Bytes Captcha cell Christmas chronolabs Client content Conversion demo docek download Dresses editor Elastic ELB evden eve Evening facebook floor free games herre Honeypot Human IP jQuery kantor Karaoke lamps log logger mobile module modules Monster MyAlbum-p nakliyat newbb news online oxygen PageRank Payment Permissions pink Plugin portal Prevention profile project Protector publisher Rights rmcommon Room sale security Server site Smarty Spam SQL stem StopForumSpam Studio support tag tags tdmcreate Theme themes Twitter Umfrage User userlog website Whitepaper xoops Xortify ZendFramework

New Users

Registering user

# 136029

Relentless

Welcome to XOOPS!




Bottom   Previous Topic   Next Topic  Register To Post



#1 Posted on: 2004/2/15 3:00 Agenda-X 1.2.4 released
CHANGELOG

2004-02-15
version 1.2.4 wjue
fixed minical display on feb 2004 when week starts from monday
fixed remainning potential security problems when your PHP has register_globals on AND "remote include" is also permitted.

http://sourceforge.net/project/showfiles.php?group_id=83736

As beta test for v2.0 goes very smoothly, I will release Agenda-X v2.0RC in a few days.


wjue

Top

wjue
Not too shy to talk
Not too shy to talk
Joined:
2002/8/3 2:36
Group:
Registered Users
Posts: 185
(Show More) (Show Less)


#2 Posted on: 2004/2/15 3:36 Re: Agenda-X 1.2.4 released
By "remote include", do you mean allow_url_fopen?

Top

Dave_L
XOOPS is my life!
XOOPS is my life!
Joined:
2003/11/7 15:34
From Virginia, USA
Group:
Registered Users
Posts: 2267
(Show More) (Show Less)


#3 Posted on: 2004/2/15 5:10 Re: Agenda-X 1.2.4 released
From what I understand I think he means that yes. He means that it now safe to have that function enabled, no hackers can anymore include anyfile...

So people, this is a SAFE VERSION. I repeat, SAFE VERSION!

Top

Jan304
Official Support Member
Official Support Member
Joined:
2002/3/31 7:13
From Belgium/België/Belgique
Group:
Registered Users
Posts: 422
(Show More) (Show Less)


#4 Posted on: 2004/2/15 5:55 Re: Agenda-X 1.2.4 released
Quote:
So people, this is a SAFE VERSION. I repeat, SAFE VERSION!

Perhaps double-check a bit before being so absolute?

Top

Mithrandir
XOOPS is my life!
XOOPS is my life!
Joined:
2003/6/21 11:37
From Copenhagen, Denmark
Group:
Registered Users
Posts: 6094
(Show More) (Show Less)


#5 Posted on: 2004/2/15 8:03 Re: Agenda-X 1.2.4 released
I think the correct statement should be "It is a MORE SAFE VERSION"

I applied the change that removes the possibility of remote inclusion instead of workarrounds.

wjue

Top

wjue
Not too shy to talk
Not too shy to talk
Joined:
2002/8/3 2:36
Group:
Registered Users
Posts: 185
(Show More) (Show Less)







You can view topic.
You cannot start a new topic.
You cannot reply to posts.
You cannot edit your posts.
You cannot delete your posts.
You cannot add new polls.
You can vote in polls.
You cannot attach files to posts.
You cannot post without approval.
You cannot use topic type.
You cannot use HTML syntax.
You cannot use signature.

[Advanced Search]