PunBB 1.3 hibák

Nézd égig a listát a hibákról, és ha találnál még akkor add hozzá. Sajnos a program nem tökéletes de mint egy ingyenes bárki által fejlesztető alkalmazásról van szó nem is várhatjuk el, hogy hibátlan legyen.

PunBB 1.3 hibák

  • Moderátori hibák:
    • Incorrect hidden field value on actions with multiple topics (fixed in [898], hotfix in process).
    • XSS vulnerability, reported by PHPLizardo (fixed in [909], hotfix hotfix_13_moderate_xss released).
    • Replies and Views are exchanged in moderate.php, reported by coordinator (fixed in [932]).
    • There is no link to the reports page in the admin menu for moderators, reported by 8k84 (fixed in [940]).
  • Markup and language file issues (no hotfixes will be released if the bug results no errors):
    • Incorrect markup of the „download latest version” link (fixed).
    • Missing language file entries for install.php, reported by coolhd (fixed in [891]).
    • Markup issues in the guest post form in post.php, reported by Adelf (fixed in [900]).
    • Markup issues in install.php (fixed in [901]).
    • Incorrect heading set in profile, reported by fantasma (fixed in [902]).
    • Underline is working as italics (post by Garciat, fixed in [922]).
    • Incorrect message you must copy/upload the file .htaccess from the extras directory in forum settings (topic by esupergood, fixed in [923]).
    • Make „new hotfixes” message more informative, see Forums topic by colak for details (fixed in [923]).
    • Breadcrumbs: Lack of link on topic subject ⇒ no topic permalink at all! (fixed in [924])
    • Wrong appearing of 'sticky' word in search results, reported by teva and Garciat (fixed in [910] and [928]).

PunBB 1.3.1 hibák

PunBB 1.3.2 hibák

  • User count in user search results is displayed incorrect (reported by 8k84, fixed in [1065]).
  • Messages in feeds are shown as they are stored in DB, without parsing (reported by alpha2zee, fixed in [1070]).
  • Incorrect layout in viewforum.php when „Topic views” is disabled (reported by burina, fix by AracornRed in [1073]).
  • Incorrect hooks positions (reported by Cereal, YonasH, Strofanto; fixed in [1068], [1079]).
  • Markup issues and hooks location in moderate.php, search.php, viewforum.php ([1073], [1089] and [1092]).
  • IE6 CSS issues (reported by Ishimaru Chiaki, 8k84, fixed in [1106] and [1113]).
  • The usage of language pack at the final stage of installing process (reported by Dan_y2k, fixed in [1108]).
  • Incorrect HTTP response code (503 instead 404) for non-existent pages when SEF is enabled (reported by commanche, fixed in [1118]).

PunBB 1.3.3 bugs

PunBB 1.3.4 hibák

  • One can't post in a forum if there is only post permission (reported by Cereal).
  • FIXME Just after installing the 'online' table takes a lot of diskspace on some systems (for example, 1.6 Mb on PHP: 4.4.9, Accelerator: eAccelerator, DB: MySQL Standard 4.1.22; see also a topic on forums).
  • FIXME Seems like checking of csrf tokens does not involve correspondent timeout in a right way.
  • FIXME Updating script (admin/db_update.php) issues?

Possible XSS in moderate

A topic title was not converted to HTML in forum moderation. A user could steal moderator's & administrator's session by injecting JavaScript in the topic title.

Possible XSS in login

Password field value (set directly from POST-request) was not properly escaped, so that one could use it to execute JavaScript. CSRF confirm message would be displayed.

Potential SQL-injections at admin/users.php page

The values of $_POST['order_by'] and $_POST['direction'] were escaped, but not logically checked before using in SQL query at the AdministrationUsers page. One could execute any SQL query via making administrator to send a POST-request (e.g. giving him a link to the specially formed page). CSRF confirm message would be displayed.

Potential SQL-injections in admin/settings.php via configuration values

The values of configuration options were not checked before using in SQL query at AdministrationSettings page. One could execute any SQL query via making administrator to send a POST-request (e.g. giving him a link to the specially formed page). CSRF confirm message would be displayed.

Továbbá

Linkek

punbb13/hibak.txt · Utolsó módosítás: 2009/08/18 17:12 szerkesztette: admin
Vissza a tetejére
CC Attribution-Noncommercial-Share Alike 3.0 Unported chimeric.de = chi`s home Valid CSS Driven by DokuWiki do yourself a favour and use a real browser - get firefox!! Recent changes RSS feed Valid XHTML 1.0