Advanced search  

News:

cpg1.5.48 Security release - upgrade mandatory!
The Coppermine development team is releasing a security update for Coppermine in order to counter a recently discovered vulnerability. It is important that all users who run version cpg1.5.46 or older update to this latest version as soon as possible.
[more]

Pages: [1]   Go Down

Author Topic: [README IMPORTANT] Security bug in CPG 1.1D !!!!!!!!!!!!!!!!  (Read 8806 times)

0 Members and 1 Guest are viewing this topic.

DJMaze

  • VIP
  • Coppermine addict
  • ***
  • Offline Offline
  • Posts: 831
    • Dragonfly CMS
[README IMPORTANT] Security bug in CPG 1.1D !!!!!!!!!!!!!!!!
« on: November 06, 2003, 12:21:40 am »

We discovered a security bug in Coppermine 1.1D for any phpNuke.

When the Userinfo block of www.gnaunited.com (SPLATT) is installed it's exposed, but it's affected on every install even if you don't use above block !!!!

Some of you already fixed it partially after finding it, but did not completely fix it, so please also download this fix !!!

This is a "High risk" security bug and we suggest you download the proper fix for your installation at the Coppermine for phpNuke Dev Team website download section: Patches for 1.1d

Or if you use phpNuke 5.5 or up you can upgrade to our latest Coppermine release 1.2.0-nukeRC3 which doesn't have the security bug here.
Logged
There are 2 kinds of users in this world: satisfied and complainers.
Why do we never hear something from the satisfied users?
http://coppermine-gallery.net/forum/index.php?topic=24315.0

skully

  • Coppermine newbie
  • Offline Offline
  • Posts: 2
    • http://www.aibo-friends.com
Use of undefined constant pwd
« Reply #1 on: November 06, 2003, 11:03:36 am »

After applying the patch i get this error:
 
Notice: Use of undefined constant pwd - assumed 'pwd' in /home/www/aibo-vrienden/mainfile.php on line 203

I use Nuke 6.5 and coppermine 1.1D
Error happens when i am logged in as admin, user and anonymous.
I am using the watermark MOD in my gallery.

Could this cause this ?
Can the changes in the init.inc.php be published so we can apply them manually ?

I left the error in my gallery so you can see for yourself:

http://www.aibo-vrienden.nl

CHeers
Robert
Logged

DJMaze

  • VIP
  • Coppermine addict
  • ***
  • Offline Offline
  • Posts: 831
    • Dragonfly CMS
[README IMPORTANT] Security bug in CPG 1.1D !!!!!!!!!!!!!!!!
« Reply #2 on: November 06, 2003, 11:37:33 am »

it's not a error it's an notice so don't worry.

open your phpNuke mainfile.php and change [pwd] into ['pwd']
Logged
There are 2 kinds of users in this world: satisfied and complainers.
Why do we never hear something from the satisfied users?
http://coppermine-gallery.net/forum/index.php?topic=24315.0

icebox

  • Translator
  • Coppermine novice
  • **
  • Offline Offline
  • Gender: Male
  • Posts: 21
    • Open Photography
[README IMPORTANT] Security bug in CPG 1.1D !!!!!!!!!!!!!!!!
« Reply #3 on: November 06, 2003, 11:57:57 am »

Thank-you, that fixed it  :mrgreen:  :!:
Logged
Cool photos, reviews, forums at:
http://www.openphoto.tk/
[size=10]Note: Contains  artistic nudity...[/size]

skully

  • Coppermine newbie
  • Offline Offline
  • Posts: 2
    • http://www.aibo-friends.com
[README IMPORTANT] Security bug in CPG 1.1D !!!!!!!!!!!!!!!!
« Reply #4 on: November 06, 2003, 12:48:12 pm »

Yep solves mine too.

thx

Robert
aibo-friends.com / aibo-vrienden.nl
Logged

rico

  • Coppermine newbie
  • Offline Offline
  • Posts: 6
[README IMPORTANT] Security bug in CPG 1.1D !!!!!!!!!!!!!!!!
« Reply #5 on: November 20, 2003, 09:42:20 am »

Me when i apply this patch i've got this error :


Notice: Undefined variable: debug in /home/aretmeti/www/html/db/mysql.php on line 104

Notice: Use of undefined constant pwd - assumed 'pwd' in /home/aretmeti/www/html/mainfile.php on line 287

i change the [pwd] to ['pwd'] but that change nothing.

Can you help me pleaze :)
Logged
Pages: [1]   Go Up
 

Page created in 0.017 seconds with 14 queries.