Advanced search  

News:

cpg1.5.48 Security release - upgrade mandatory!
The Coppermine development team is releasing a security update for Coppermine in order to counter a recently discovered vulnerability. It is important that all users who run version cpg1.5.46 or older update to this latest version as soon as possible.
[more]

Pages: [1]   Go Down

Author Topic: security issue - special filenames in root of domain not allowed  (Read 6045 times)

0 Members and 1 Guest are viewing this topic.

photoexposer

  • Coppermine novice
  • *
  • Offline Offline
  • Gender: Male
  • Posts: 26
    • start your virtual journey ...

Hello Dev-Team,

1st thanks for the 1.3.. great :)

for security reasons some hoster do NOT allow special filenames like config.*, system-bin.* or spicons.*
in the root directory of the domain. (Inst. in subdirectory works)

Therefore I am not able to install CPG in the root directory.

now my wish...

is it possible, that you rename all these filenamens in the package like config.php, etc..? that installing into root would be possible ?
Thanks

cu Thomas

Logged

Tarique Sani

  • VIP
  • Coppermine addict
  • ***
  • Offline Offline
  • Gender: Male
  • Posts: 2712
    • http://tariquesani.net
Re: security issue - special filenames in root of domain not allowed
« Reply #1 on: June 18, 2004, 06:51:46 am »

This is being considered....
Logged
SANIsoft PHP applications for E Biz

Joachim Müller

  • Dev Team member
  • Coppermine addict
  • ****
  • Offline Offline
  • Gender: Male
  • Posts: 47843
  • aka "GauGau"
    • gaugau.de
Re: security issue - special filenames in root of domain not allowed
« Reply #2 on: June 18, 2004, 01:44:43 pm »

meanwhile (as a workaround), rename config.php to somename.php and change the link pointing to it in themes/yourtheme/theme.php

GauGau
Logged

photoexposer

  • Coppermine novice
  • *
  • Offline Offline
  • Gender: Male
  • Posts: 26
    • start your virtual journey ...
Re: security issue - special filenames in root of domain not allowed
« Reply #3 on: June 18, 2004, 05:07:12 pm »

Hello

changed files, change locations, tested.. works.
thank you GauGau

cu
Thomas

Logged

photoexposer

  • Coppermine novice
  • *
  • Offline Offline
  • Gender: Male
  • Posts: 26
    • start your virtual journey ...
Re: security issue - special filenames in root of domain not allowed
« Reply #4 on: June 18, 2004, 06:34:03 pm »

Hello again,

after changing the installation path to root.. anything else to refurnish ?
if I batch-upload images now..

1) the image is not shown up before uploading
2) after uploading the result-sign is not available
3) after revisiting the album the images are there

 did I forget something to change ??
I allready did a database update (admin tools)

thanks
cu Thomas
Logged

Joachim Müller

  • Dev Team member
  • Coppermine addict
  • ****
  • Offline Offline
  • Gender: Male
  • Posts: 47843
  • aka "GauGau"
    • gaugau.de
Re: security issue - special filenames in root of domain not allowed
« Reply #5 on: June 19, 2004, 10:42:54 am »

Do not hijack a thread - not even the ones you started yourself. We have a one question per thread policy on this board. As far as I can see this is a new issue...

GauGau
Logged

photoexposer

  • Coppermine novice
  • *
  • Offline Offline
  • Gender: Male
  • Posts: 26
    • start your virtual journey ...
Re: security issue - special filenames in root of domain not allowed
« Reply #6 on: June 19, 2004, 02:22:53 pm »

anyway ;;)
I followed you advice -> http://forum.coppermine-gallery.net/index.php?topic=7115.0

cu
Thomas
Logged
Pages: [1]   Go Up
 

Page created in 0.031 seconds with 19 queries.