[Xerte-dev] Re: SECURITY PATCH for upload.php

Pat @ Pgogy xerte at pgogywebstuff.com
Thu Mar 7 14:53:31 GMT 2013


Hello,

I hobble the Wordpress version deliberately to only allow a few file types but that isn't the list that full XOT needs (there is in fact, no list, hence the problem).

My reg exp is a bit flaky as well, if you copied that over.

There is a sort of whitelist in the sitedetails table as the media upload properties panel page uses this - but not sure this is the XOT list.

Pgogy Webstuff - http://www.pgogywebstuff.com
Makers of web things of a fair to middling quality

On 7 Mar 2013, at 13:01, "Smith, John" <J.J.Smith at gcu.ac.uk> wrote:

> Hi,
>  
> I’ve just committed a change to upload.php (revision 714) to stop users exploiting a system by uploading php code. I’ve added a whitelist and stuck in the same allowed file extensions that Pat uses in the Wordpress plugins.
>  
> Can someone test this and advise if there are any other media types that we want/need to allow?
>  
> There was also a session check but exit(); was commented out therefore in an unpatched system ANYONE can post data to upload.php and get some code onto the server. I’ve uncommented this now but does anyone know why it was commented out in the first place?
>  
> Regards,
>  
> John Smith
> Learning Technologist
> School of Health & Life Sciences
> Glasgow Caledonian University
>  
> 
> Glasgow Caledonian University is a registered Scottish charity, number SC021474
> 
> Winner: Times Higher Education’s Widening Participation Initiative of the Year 2009 and Herald Society’s Education Initiative of the Year 2009.
> http://www.gcu.ac.uk/newsevents/news/bycategory/theuniversity/1/name,6219,en.html
> 
> Winner: Times Higher Education’s Outstanding Support for Early Career Researchers of the Year 2010, GCU as a lead with Universities Scotland partners.
> http://www.gcu.ac.uk/newsevents/news/bycategory/theuniversity/1/name,15691,en.html
> 
> 
> 
> _______________________________________________
> Xerte-dev mailing list
> Xerte-dev at lists.nottingham.ac.uk
> http://lists.nottingham.ac.uk/mailman/listinfo/xerte-dev
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.nottingham.ac.uk/pipermail/xerte-dev/attachments/20130307/121363c4/attachment.html>


More information about the Xerte-dev mailing list