Advanced search  

News:

cpg1.5.48 Security release - upgrade mandatory!
The Coppermine development team is releasing a security update for Coppermine in order to counter a recently discovered vulnerability. It is important that all users who run version cpg1.5.46 or older update to this latest version as soon as possible.
[more]

Pages: [1]   Go Down

Author Topic: Batch Add  (Read 3533 times)

0 Members and 1 Guest are viewing this topic.

rtenny

  • Coppermine newbie
  • Offline Offline
  • Gender: Male
  • Posts: 2
Batch Add
« on: May 30, 2005, 06:26:17 pm »

Why can only admin use the batch add feature?? The manual just states "for securitz reason". I have my own dedicated server and only familiy members can use ist. I don't want to make them all "administrators". Is there another way?
« Last Edit: June 03, 2005, 06:59:33 am by GauGau »
Logged

Tranz

  • Dev Team member
  • Coppermine addict
  • ****
  • Country: 00
  • Offline Offline
  • Gender: Female
  • Posts: 6149
Re: Batch Add
« Reply #1 on: May 30, 2005, 06:28:56 pm »

mmm... if you don't understand the security implications, maybe you should not be maintaining your own server...
Logged

rtenny

  • Coppermine newbie
  • Offline Offline
  • Gender: Male
  • Posts: 2
Re: Batch Add
« Reply #2 on: June 03, 2005, 01:11:49 am »

mmm... if you don't understand the security implications, maybe you should not be maintaining your own server...

this really help, thanks. >:(

already reprogrammed the code so no need to answer.
Logged

Tranz

  • Dev Team member
  • Coppermine addict
  • ****
  • Country: 00
  • Offline Offline
  • Gender: Female
  • Posts: 6149
Re: Batch Add
« Reply #3 on: June 03, 2005, 05:56:29 am »

??? I thought I was helping. Maybe it wasn't very obvious... but it's like when someone says they have trouble seeing, and I'd suggest maybe they shouldn't drive... It's not something they want to hear but it's for their own good.
Logged

Joachim Müller

  • Dev Team member
  • Coppermine addict
  • ****
  • Offline Offline
  • Gender: Male
  • Posts: 47843
  • aka "GauGau"
    • gaugau.de
Re: Batch Add
« Reply #4 on: June 03, 2005, 07:02:26 am »

chaning the coppermine code to allow everyone to batch-add is easy, but means that you have to allow users to ftp-upload, which is a huge security risk. Given just the url of your pgae any script kiddie can easily take over or break your site in one minute. This is why you shouldn't do that. It should be obvious that non-admins don't have ftp access. This is the reason why Thu suggested not to do what you're doing.
Logged
Pages: [1]   Go Up
 

Page created in 0.018 seconds with 15 queries.