Kunena 6.3.0 released

The Kunena team has announce the arrival of Kunena 6.3.0 [K 6.3.0] in stable which is now available for download as a native Joomla extension for J! 4.4.x/5.0.x/5.1.x. This version addresses most of the issues that were discovered in K 6.2 and issues discovered during the last development stages of K 6.3

Important txt attachement revealed my absolute folder path

More
8 years 3 days ago - 8 years 3 days ago #1 by baijianpeng
My server runs on CentOS. You know that it is a security consideration to NOT let public know the ABSOLUTE Path of your Joomla folders.

Well, today I noticed that just a simple TXT format attachement will reveal the absolute path on my server.

Someone on my forum uploaded a txt file named "rterror2.txt", but after submission, the filename was converted to :
Code:
-home-u1234-web-uhiker.com-public_html-media-kunena-attachments-41969-rterror2.txt

If you replace those dash characters with slash, you will get the absolute path:
Code:
/home/u1234/web/uhiker.com/public_html/media/kunena/attachments/41969/rterror2.txt

The worse is, you don't have to download this attachement to see its filename then know the path, it is just showing there in the post with full file name which is indicating the absolute path of the website!

Don't you think this is horrible?

I think this is a bug of Kunena 4.0.10.

Hope you will fix it in Kunena 5.

Thank you.

www.joomlagate.com/

Chinese Joomla Users' Portal
Last edit: 8 years 3 days ago by baijianpeng.

Please Log in or Create an account to join the conversation.

More
8 years 3 days ago #2 by 810
looks like a wrong .htaccess file.

When I add a txt, I can see only the normal url, like www.website.com/media/kunena/attachments/48/test.txt

Please Log in or Create an account to join the conversation.

More
8 years 3 days ago #3 by baijianpeng
Maybe because yur are using Kunena 5 but I was using Kunena 4.0.10?

I attached my .htaccess file here, could you please help to check this file and find the possible cause in it?


File Attachment:

File Name: htaccess.zip
File Size:4 KB



Thank you.

www.joomlagate.com/

Chinese Joomla Users' Portal
Attachments:

Please Log in or Create an account to join the conversation.

More
8 years 3 days ago #4 by 810
yes, its your htaccess, I get now errors:

Rendering Error in layout BBCode/Image: Property "url" is not defined in /home/****/domains/***/public_html/components/com_kunena/template/crypsis/layouts/bbcode/image/unauthorised.php on line 15
Layout was rendered in /home/****/domains/****/public_html/components/com_kunena/template/crypsis/layouts/message/item/default.php on line 83

Please Log in or Create an account to join the conversation.

More
8 years 3 days ago #5 by 810
ok that is a new bug what I get on the errors, will check your htaccess again

Please Log in or Create an account to join the conversation.

More
8 years 3 days ago #6 by 810
ok I use now k4, I have no issues, I see the normal path.

Please Log in or Create an account to join the conversation.

More
8 years 3 days ago #7 by baijianpeng
Could you please point out which line(s) of code in my .htaccess file is the cause of this issue on my Kunena 4? And how to fix it?

Thank you.

www.joomlagate.com/

Chinese Joomla Users' Portal

Please Log in or Create an account to join the conversation.

More
8 years 3 days ago #8 by 810
your htaccess seems to be ok now, it was a new bug. So the only thing left is maybe a wrong server setting. Because I have no issues with k4.0 and your htaccess file.

Please Log in or Create an account to join the conversation.

More
8 years 3 days ago #9 by baijianpeng
OMG, I don't know how to find out the cause of this issue.

I found "configuraiton report tool" in Kunena, following is my configuration report:

This message contains confidential information

Database collation check: The collation of your table fields are correct

Joomla! SEF: Disabled | Joomla! SEF rewrite: Enabled | FTP layer: Disabled |

This message contains confidential information
htaccess: Exists | PHP environment: Max execution time: 30 seconds | Max execution memory: 128M | Max file upload: 2M

Kunena menu details:

Warning: Spoiler!

Joomla default template details : gantry | author: RocketTheme, LLC | version: 4.1.31 | creationdate: April 11, 2016

Kunena default template details : Blue Eagle | author: Kunena Team | version: 4.0.10 | creationdate: 2016-02-18

Kunena version detailed: Kunena 4.0.10 | 2016-02-18 [ Villavicencio ]
| Kunena detailed configuration:

Warning: Spoiler!
| Kunena integration settings:
Warning: Spoiler!
| Joomla! detailed language files installed:
Warning: Spoiler!

Third-party components: None

Third-party SEF components: None

Plugins: Search - Kunena Search 3.1.2

Modules: Kunena Latest 3.1.2.1 | Kunena Stats 3.1.2 | Kunena Login 3.1.2 | Kunena Search 3.1.2


Could you please check this and find out the culprit?

Thank you.

www.joomlagate.com/

Chinese Joomla Users' Portal

Please Log in or Create an account to join the conversation.

More
7 years 11 months ago - 7 years 11 months ago #10 by AndreyS
I have exactly the same problem. Ver.: 4.0.10
I did not change anything. Just I noticed that when downloading a file's name is inserted all the absolute path to the file. The same name appears in the message. Although the file on the server with the correct name.
What to do?
Last edit: 7 years 11 months ago by AndreyS.

Please Log in or Create an account to join the conversation.

Time to create page: 0.915 seconds