Kunena 6.3.0 released

The Kunena team has announce the arrival of Kunena 6.3.0 [K 6.3.0] in stable which is now available for download as a native Joomla extension for J! 4.4.x/5.0.x/5.1.x. This version addresses most of the issues that were discovered in K 6.2 and issues discovered during the last development stages of K 6.3

Question Full path disclosure downloading attachments

More
8 years 9 months ago #1 by Texpaok
Hi there,

After installing 4.0.3 version, when I download an attached file I get the full path in the filename. I don't upload an screenshot for security reasons, but instead filename.pdf I get home_xxxx_media_kunena_attachments_filename.pdf

I have tried enabling and disabling Protect attachments option under Configuration --> Uploads, but nothing happens...

Regards,
Jose

Please Log in or Create an account to join the conversation.

More
8 years 9 months ago #2 by sozzled
This same issue is also discussed in the topic [K4.0.1] Attachment displaying full URL location .

This problem has not been solved.
The following user(s) said Thank You: Texpaok

Please Log in or Create an account to join the conversation.

More
8 years 9 months ago #3 by Texpaok
Thanks sozzled.

To avoid it I have manually changed attachment filenames in database. This workaround avoid the full path disclosure while the issue is not corrected.

Regards,
Jose

Please Log in or Create an account to join the conversation.

More
8 years 9 months ago #4 by xillibit
Hello,

Can-you post here please your Kunena report configuration ?

I don't provide support by PM, because this can be useful for someone else.

Please Log in or Create an account to join the conversation.

More
8 years 9 months ago #5 by Texpaok
Here you have (omited confidential info):

Kunena menu details:
Warning: Spoiler!
[/quote]

Joomla default template details : gk_startup | author: GavickPro | version: 3.9 | creationdate: Unknown

Kunena default template details : Blue Eagle | author: Kunena Team | version: 4.0.3 | creationdate: 2015-06-29

Kunena version detailed: Kunena 4.0.3 | 2015-06-29 [ Possagno ]
| Kunena detailed configuration:

Warning: Spoiler!
| Kunena integration settings:
Warning: Spoiler!
| Joomla! detailed language files installed:
Warning: Spoiler!

Third-party components: None

Third-party SEF components: None

Plugins: None

Modules: None

Please Log in or Create an account to join the conversation.

More
8 years 9 months ago #6 by webuniverse
I have a similar problem :dry:

Since i have updated from 3.0.6 to 4.0.3, some Attachments have a wrong Path like this:

http://media/kunena/attachments/Dienstleistungskatalog_eines_Versicherungsbrokers.pdf/Dienstleistungskatalog_eines_Versicherungsbrokers.pdf

No correkt URL and double documentname :S

Is there a solution to fix this?

Thanks from Switzerland
Corinne


This message contains confidential information

Database collation check: The collation of your table fields are correct

Joomla! SEF: Enabled | Joomla! SEF rewrite: Disabled | FTP layer: Disabled |

This message contains confidential information
htaccess: Missing | PHP environment: Max execution time: 30 seconds | Max execution memory: 64M | Max file upload: 32M

Kunena menu details:

Warning: Spoiler!

Joomla default template details : Standard_1_optimalis | author: Beatrice Brupbacher | version: 1.0 | creationdate: Unknown

Kunena default template details : Blue Eagle | author: Kunena Team | version: 4.0.3 | creationdate: 2015-06-29

Kunena version detailed: Kunena 4.0.3 | 2015-06-29 [ Possagno ]
| Kunena detailed configuration:

Warning: Spoiler!
| Kunena integration settings:
Warning: Spoiler!
| Joomla! detailed language files installed:
Warning: Spoiler!

Third-party components: None

Third-party SEF components: None

Plugins: Search - Kunena Search 3.1.0

Modules: Kunena Search 3.1.0

Please Log in or Create an account to join the conversation.

More
8 years 9 months ago #7 by Texpaok
Hi Corinne,

It seems this only happens when you edit forum entries.

This is my workaround; it's a bit technical:

1. Make a backup. We have to modify some database fields, so the entire site could break.
2. Using phpmyadmin (or similar) go to kunena_attachments table.
3. Search something relevant of your path (for example, media) in the filename_real field:



4. Results are the attachments with full path. Just edit each one deleting the full path and keeping the file name.
For example, in your case you should have an entry with media/kunena/attachments/Dienstleistungskatalog_eines_Versicherungsbrokers.pdf/Dienstleistungskatalog_eines_Versicherungsbrokers.pdf and after editing you should have only Dienstleistungskatalog_eines_Versicherungsbrokers.pdf

Obviously, you have to do this every time you edit a forum entry while a patch is provided.

If you don't know how to do it, I can give you a hand. Just use the contact form of my website and I will help you.

Regards,
Jose
Attachments:

Please Log in or Create an account to join the conversation.

More
8 years 9 months ago - 8 years 9 months ago #8 by webuniverse
Hello Jose

Thanks for your solution, but is not exactly like this.

I made to printscreens from a wrong and a correct entry.

The "folder" entry is not correct...

OLD: /media/kunena/attachments/documentname.pdf




Correct: media/kunena/attachments




Maybe i can make a database replace from all entries with ".pdf" to /media/kunena/attachments :unsure:

i will try this :silly:

Thank you for your help
Corinne
Attachments:
Last edit: 8 years 9 months ago by webuniverse.

Please Log in or Create an account to join the conversation.

More
8 years 9 months ago #9 by Texpaok
You're welcome Corinne!

In my case, the full path disclosure is located only in the filename_real field...

To be fully sure there is no path disclosure we should replace all downloadable file types, not only .pdf. More work to do! :silly:

Regards,
Jose

Please Log in or Create an account to join the conversation.

More
8 years 9 months ago #10 by webuniverse
I have some path there are correct... so i need only the .pdf's

If somebody else have the same problem here my Script

UPDATE `xxx_kunena_attachments` SET `folder` = "media/kunena/attachments" WHERE `folder` LIKE "%.pdf"

Now everything works okay :)

Have a nice Day B)
Corinne

Please Log in or Create an account to join the conversation.

Time to create page: 0.578 seconds