Kunena 7.0.4 Released

The Kunena team has announce the arrival of Kunena 7.0.4 [K 7.0.4] in stable which is now available for download as a native Joomla extension for J! 5.4.x/6.0.x. This version addresses most of the issues that were discovered in K 6.2 / K 6.3 / K 6.4 and issues discovered during the last development stages of K 7.0

Important txt attachement revealed my absolute folder path

More
10 years 3 weeks ago - 10 years 3 weeks ago #174419 by baijianpeng
My server runs on CentOS. You know that it is a security consideration to NOT let public know the ABSOLUTE Path of your Joomla folders.

Well, today I noticed that just a simple TXT format attachement will reveal the absolute path on my server.

Someone on my forum uploaded a txt file named "rterror2.txt", but after submission, the filename was converted to :
Code:
-home-u1234-web-uhiker.com-public_html-media-kunena-attachments-41969-rterror2.txt

If you replace those dash characters with slash, you will get the absolute path:
Code:
/home/u1234/web/uhiker.com/public_html/media/kunena/attachments/41969/rterror2.txt

The worse is, you don't have to download this attachement to see its filename then know the path, it is just showing there in the post with full file name which is indicating the absolute path of the website!

Don't you think this is horrible?

I think this is a bug of Kunena 4.0.10.

Hope you will fix it in Kunena 5.

Thank you.

www.joomlagate.com/

Chinese Joomla Users' Portal
Last edit: 10 years 3 weeks ago by baijianpeng.

Please Log in or Create an account to join the conversation.

More
10 years 3 weeks ago #174420 by 810
looks like a wrong .htaccess file.

When I add a txt, I can see only the normal url, like www.website.com/media/kunena/attachments/48/test.txt

Please Log in or Create an account to join the conversation.

More
10 years 3 weeks ago #174421 by baijianpeng
Maybe because yur are using Kunena 5 but I was using Kunena 4.0.10?

I attached my .htaccess file here, could you please help to check this file and find the possible cause in it?


File Attachment:

File Name: htaccess.zip
File Size:4.06 KB



Thank you.

www.joomlagate.com/

Chinese Joomla Users' Portal

Please Log in or Create an account to join the conversation.

More
10 years 3 weeks ago #174423 by 810
yes, its your htaccess, I get now errors:

Rendering Error in layout BBCode/Image: Property "url" is not defined in /home/****/domains/***/public_html/components/com_kunena/template/crypsis/layouts/bbcode/image/unauthorised.php on line 15
Layout was rendered in /home/****/domains/****/public_html/components/com_kunena/template/crypsis/layouts/message/item/default.php on line 83

Please Log in or Create an account to join the conversation.

More
10 years 3 weeks ago #174424 by 810
ok that is a new bug what I get on the errors, will check your htaccess again

Please Log in or Create an account to join the conversation.

More
10 years 3 weeks ago #174425 by 810
ok I use now k4, I have no issues, I see the normal path.

Please Log in or Create an account to join the conversation.

Time to create page: 0.299 seconds