Kunena 7.0.5 & Kunena 6.4.11 – Security Updates Released

The Kunena team has announce the arrival of Kunena 7.0.5 [K 7.0.5] in stable which is now available for download as a native Joomla extension for J! 5.4.x/6.0.x. This version addresses most of the issues that were discovered in K 6.2 / K 6.3 / K 6.4 and issues discovered during the last development stages of K 7.0.

The Kunena team is also pleased to announce the eleventh version of Kunena 6.4, a native Joomla extension for Joomla! 5.0, 5.1, 5.2, 5.3, 5.4 and 6.0.

Question Full path disclosure downloading attachments

More
10 years 10 months ago #166794 by Texpaok
Hi there,

After installing 4.0.3 version, when I download an attached file I get the full path in the filename. I don't upload an screenshot for security reasons, but instead filename.pdf I get home_xxxx_media_kunena_attachments_filename.pdf

I have tried enabling and disabling Protect attachments option under Configuration --> Uploads, but nothing happens...

Regards,
Jose

Please Log in or Create an account to join the conversation.

More
10 years 10 months ago #166795 by sozzled
This same issue is also discussed in the topic [K4.0.1] Attachment displaying full URL location .

This problem has not been solved.
The following user(s) said Thank You: Texpaok

Please Log in or Create an account to join the conversation.

More
10 years 10 months ago #166798 by Texpaok
Thanks sozzled.

To avoid it I have manually changed attachment filenames in database. This workaround avoid the full path disclosure while the issue is not corrected.

Regards,
Jose

Please Log in or Create an account to join the conversation.

More
10 years 10 months ago #166883 by xillibit
Hello,

Can-you post here please your Kunena report configuration ?

I don't provide support by PM, because this can be useful for someone else.

Please Log in or Create an account to join the conversation.

More
10 years 10 months ago #166888 by Texpaok
Here you have (omited confidential info):

Kunena menu details:
Warning: Spoiler!
[/quote]

Joomla default template details : gk_startup | author: GavickPro | version: 3.9 | creationdate: Unknown

Kunena default template details : Blue Eagle | author: Kunena Team | version: 4.0.3 | creationdate: 2015-06-29

Kunena version detailed: Kunena 4.0.3 | 2015-06-29 [ Possagno ]
| Kunena detailed configuration:

Warning: Spoiler!
| Kunena integration settings:
Warning: Spoiler!
| Joomla! detailed language files installed:
Warning: Spoiler!

Third-party components: None

Third-party SEF components: None

Plugins: None

Modules: None

Please Log in or Create an account to join the conversation.

More
10 years 10 months ago #166914 by webuniverse
I have a similar problem :dry:

Since i have updated from 3.0.6 to 4.0.3, some Attachments have a wrong Path like this:

http://media/kunena/attachments/Dienstleistungskatalog_eines_Versicherungsbrokers.pdf/Dienstleistungskatalog_eines_Versicherungsbrokers.pdf

No correkt URL and double documentname :S

Is there a solution to fix this?

Thanks from Switzerland
Corinne


This message contains confidential information

Database collation check: The collation of your table fields are correct

Joomla! SEF: Enabled | Joomla! SEF rewrite: Disabled | FTP layer: Disabled |

This message contains confidential information
htaccess: Missing | PHP environment: Max execution time: 30 seconds | Max execution memory: 64M | Max file upload: 32M

Kunena menu details:

Warning: Spoiler!

Joomla default template details : Standard_1_optimalis | author: Beatrice Brupbacher | version: 1.0 | creationdate: Unknown

Kunena default template details : Blue Eagle | author: Kunena Team | version: 4.0.3 | creationdate: 2015-06-29

Kunena version detailed: Kunena 4.0.3 | 2015-06-29 [ Possagno ]
| Kunena detailed configuration:

Warning: Spoiler!
| Kunena integration settings:
Warning: Spoiler!
| Joomla! detailed language files installed:
Warning: Spoiler!

Third-party components: None

Third-party SEF components: None

Plugins: Search - Kunena Search 3.1.0

Modules: Kunena Search 3.1.0

Please Log in or Create an account to join the conversation.

Time to create page: 0.306 seconds