Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
May 19, 2012, 06:37:26 AM
News:
New to the forum ? Please introduce yourself in the member introduction area
Home
Help
Search
Login
Register
auroraadmintraining.info
>
Fixes, Mods, Help etc.
>
Aurora Security Updates
>
Security Fix: Memebers/composeMsg.php & Members/contact.php
Pages: [
1
]
Go Down
« previous
next »
Print
Author
Topic: Security Fix: Memebers/composeMsg.php & Members/contact.php (Read 228 times)
757jterrell
Administrator
Hero Member
Offline
Posts: 1637
Security Fix: Memebers/composeMsg.php & Members/contact.php
«
on:
July 30, 2011, 05:48:13 PM »
This will prevent an xss attack on these pages. These 2 pages that are almost the exact same.
This is included in the SDR 3, 8-1-11 Update.
Members/composeMsg.php, go to line 84 to 86 and you will see this set of codes:
<tr>
<td colspan=2><textarea name=\"message\" style=\"width: 100%; height: 200px\">$messages</textarea></td>
</tr>
Change the middle line to look like this:
<tr>
<td colspan=2><textarea name=\"message\" style=\"width: 100%; height: 200px\">". htmlspecialchars($message, ENT_QUOTES)."</textarea></td>
</tr>
Now lets do the other page, go to your members/contact.php and go to lines 84 to 86 were you see this set of codes:
<tr>
<td colspan=2><textarea name=\"message\" style=\"width: 100%; height: 200px\">$messages</textarea></td>
</tr>
Change the middle line to look like this:
<tr>
<td colspan=2><textarea name=\"message\" style=\"width: 100%; height: 200px\">". htmlspecialchars($message, ENT_QUOTES)."</textarea></td>
</tr>
Also on both pages add the following:
after $includes[title]="Compose Message";
ADD:
$error = '';
«
Last Edit: July 31, 2011, 08:34:36 AM by 757jterrell
»
Logged
Check out the SDR 3 NOW!!
Upgrade Now!!!
Upgrade to an SDR 3
chicoi08
Full Member
Offline
Posts: 237
Re: Security Fix: Memebers/composeMsg.php & Members/contact.php
«
Reply #1 on:
July 30, 2011, 07:00:37 PM »
Thank you for posting!
Logged
BuxOverFlow.com - Advertise with US
Get a SDR 3 NOW at http://ptcfactory.info
The best and most up to date Aurora script in the market!!
Pages: [
1
]
Go Up
Print
« previous
next »
Jump to:
Please select a destination:
-----------------------------
General Forum
-----------------------------
=> General Information
=====> Things going into the premium
-----------------------------
Fixes, Mods, Help etc.
-----------------------------
=> Aurora Help & Support
=> SDR 3 Help
=> Aurora Fixes
=> Aurora Security Updates
=> Free Mods
=> Developers
=> Designs & Layouts
=> Cpanel Help
=> Unauthorized Sellers
-----------------------------
Owners Corner
-----------------------------
=> Tips & Recommendations
=> Advertising Exchange Offers
=> Cheaters List
-----------------------------
Chit-Chat
-----------------------------
=> Chit-Chat
=> Member Introductions
=> List Your Website
=> Non-English Forum
-----------------------------
Resources
-----------------------------
=> Templates for Sale
=> Addons for Sale
=> Forums
=> Great Traffic
=> Hosting
-----------------------------
SDR 3 (& SDR 2s after 2-15-11 Update) Operating Instructions
-----------------------------
=> General Info
=> Site Functions
=> Selling
=> Orders
=> Payouts
=> Ad Functions
=> Manage Ads
=> Members
=> Find Cheaters
=> Communication
=> Tools
-----------------------------
Aurora Script General Instructions
-----------------------------
=> Admin Panel: Support Tickets
=> Admin Panel: Stats
=> Admin Panel: Orders
=> Admin Panel: Lottery
=> Admin Panel: Payouts
=> Admin Panel: Manage Ads
=> Admin Panel: Members
===> Manage
===> Referrals
=> Admin Panel: Communication
=> Admin Panel: Tools
===> Anti Cheating
===> Point Store
===> Site Content
===> Specials
=> Admin Panel: Settings
===> Selling
===> Site Settings
===> Members Settings
===> Admin Panel
Loading...