|
|
Joined: Aug 2000
Posts: 3,590
Moderator
|
Moderator
Joined: Aug 2000
Posts: 3,590 |
5.1.2 perl has an "allowfiles" config option which seems to be missing from the php version.
This allows users to upload .php files and if you have php enabled site wide this attachment can be run on the server with the associated obvious secuirty problems.
As a work around you can disable php in your "files" directory on apache by creating a .htaccess file containing:
php_flag engine off
Regards
Paul
|
|
|
|
Joined: May 1999
Posts: 3,039
Guru
|
Guru
Joined: May 1999
Posts: 3,039 |
This is one thing that hasn't been added yet, but I will be getting it in. This is the main reason I haven't released the third beta. I'll try and get this in today.
Thanks for the report though.
UBB.threads Developer
|
|
|
Donate to UBBDev today to help aid in Operational, Server and Script Maintenance, and Development costs.
Please also see our parent organization VNC Web Services if you're in the need of a new UBB.threads Install or Upgrade, Site/Server Migrations, or Security and Coding Services.
|
|
Posts: 1,157
Joined: July 2001
|
|
Forums63
Topics37,573
Posts293,925
Members13,849
|
Most Online5,166 Sep 15th, 2019
|
|
Currently Online
Topics Created
Posts Made
Users Online
Birthdays
|
|
|
|
|