Pages: [1]   Go Down
  Print  
Author Topic: Security Fix: frame.php  (Read 1035 times)
757jterrell
Administrator
Hero Member
*****
Offline Offline

Posts: 1637



View Profile WWW
« on: October 29, 2010, 05:37:20 PM »

With the cooperation of Scott Klarr (http://diffusionstudios.com/) we are pleased to release this security update:

This will prevent people from uploading free credits into your  ads.

Go to your frame.php file, line 19 to 23 and add what is in bold:

include("header.php");

$id = mysql_real_escape_string($_REQUEST['id']);

$sql = $Db1->query("SELECT * FROM $type WHERE id='$id'");
Logged

Upgrade to an SDR 3
Claudeski
Newbie
*
Offline Offline

Posts: 28


View Profile
« Reply #1 on: October 30, 2010, 08:38:59 PM »

Thanks for the additional fix but even with this I'm still getting link ads both created and modified.
Logged
757jterrell
Administrator
Hero Member
*****
Offline Offline

Posts: 1637



View Profile WWW
« Reply #2 on: October 31, 2010, 11:21:13 AM »

can I ask what version of the script you are using?? it may help us identify what the problem is.
Logged

Claudeski
Newbie
*
Offline Offline

Posts: 28


View Profile
« Reply #3 on: October 31, 2010, 07:25:05 PM »

I'm still using MRV3.
Logged
757jterrell
Administrator
Hero Member
*****
Offline Offline

Posts: 1637



View Profile WWW
« Reply #4 on: October 31, 2010, 07:51:34 PM »

Have you done these things already?

http://auroraadmintraining.info/index.php/topic,152.0.html
Logged

Claudeski
Newbie
*
Offline Offline

Posts: 28


View Profile
« Reply #5 on: November 01, 2010, 03:05:55 AM »


My config.php had a permission of 0666 instead of 0777 or 0664 but has now been changed, could this have been the problem?. Otherwise, all those holes have been fixed.
Logged
757jterrell
Administrator
Hero Member
*****
Offline Offline

Posts: 1637



View Profile WWW
« Reply #6 on: November 01, 2010, 05:57:03 PM »

Yes that would do it, permission 0666 allows people to access and write to your database. Change it to 0644 ASAP.
Logged

Claudeski
Newbie
*
Offline Offline

Posts: 28


View Profile
« Reply #7 on: November 01, 2010, 07:55:12 PM »

Yes that would do it, permission 0666 allows people to access and write to your database. Change it to 0644 ASAP.

Yep already changed. Thanks for the help.
Logged
syaikhoni
Newbie
*
Offline Offline

Posts: 19



View Profile WWW
« Reply #8 on: April 14, 2011, 04:51:54 AM »

ok thaks
Logged

Get a SDR 3 NOW at http://ptcfactory.info

The best and most up to date Aurora script in the market!!
Pages: [1]   Go Up
  Print  
 
Jump to: