Kunena 7.0.5 & Kunena 6.4.11 – Security Updates Released

The Kunena team has announce the arrival of Kunena 7.0.5 [K 7.0.5] in stable which is now available for download as a native Joomla extension for J! 5.4.x/6.0.x. This version addresses most of the issues that were discovered in K 6.2 / K 6.3 / K 6.4 and issues discovered during the last development stages of K 7.0.

The Kunena team is also pleased to announce the eleventh version of Kunena 6.4, a native Joomla extension for Joomla! 5.0, 5.1, 5.2, 5.3, 5.4 and 6.0.

Topics that are moved into this category are generally considered to be closed. Users may want to add additional information but these topics should not be resurrected in order to discuss new problems or unrelated matters.

Question Unable to attach php files

More
15 years 9 months ago #53854 by kiwi3685
If any of my users attaches a php file to a forum post the attachment file name displays OK, but clicking on it opens a blank page.

Is there any way to be able to attach php file other than 'zipping' it first?

(By the way, I do have php included in the list of allowed file uploads: "pdf,zip,txt,doc,gz,tgz,php")

(Kunena 1.5.9)

Please Log in or Create an account to join the conversation.

More
15 years 9 months ago - 15 years 9 months ago #53860 by xillibit
Replied by xillibit on topic Unable to attach php files
Hello,

I think it will be working if you change the extension of php file in .txt

I don't provide support by PM, because this can be useful for someone else.
Last edit: 15 years 9 months ago by xillibit.

Please Log in or Create an account to join the conversation.

More
15 years 9 months ago #53885 by sozzled
Replied by sozzled on topic Unable to attach php files
Interesting situation. I wonder if this was an issue only for K 1.5.9 and maybe it was fixed in K 1.5.12? Does upgrading to K 1.5.12 overcome the problem? :dry:

Please Log in or Create an account to join the conversation.

More
15 years 7 months ago #65443 by kiwi3685
Replied by kiwi3685 on topic Unable to attach php files
Just a late follow up. The same problem exists in K1.6, so no, upgrading to 1.5.12 was not likely to have helped (although I admit I never tried).

However, thinking about it, clicking on a link to a php file is presumably always going to try and run the file, not download it? So it has to be necessary to either change the suffix (as suggested) or zip the file (which is what we now require of users).

I would be interested in alternative solutions though, as php files are the most common type of upload we have.

Please Log in or Create an account to join the conversation.

More
15 years 7 months ago - 15 years 7 months ago #65445 by fxstein
Replied by fxstein on topic Unable to attach php files
No you cannot upload php files, nor would Joomla or Kunena ever allow this. This would represent a HUGE security hole. Think of this - I can upload any php file (good or bad) and just by pointing to it, the server will execute it. You can take over the entire server with a single php file upload.

You cannot have public php file uploads or your server would be open to all hackers - and I mean open.

We love stars on the Joomla Extension Directory . :-)
Last edit: 15 years 7 months ago by fxstein.

Please Log in or Create an account to join the conversation.

More
15 years 7 months ago #65615 by kiwi3685
Replied by kiwi3685 on topic Unable to attach php files
That's pretty much what I though. Thanks.

Please Log in or Create an account to join the conversation.

Time to create page: 0.241 seconds