<?xml version="1.0" encoding="utf-8"?>
<feed xml:lang="en" xmlns="http://www.w3.org/2005/Atom"><title>Recent changes to bugs</title><link href="https://sourceforge.net/p/phpwebsite/bugs/" rel="alternate"/><link href="https://sourceforge.net/p/phpwebsite/bugs/feed.atom" rel="self"/><id>https://sourceforge.net/p/phpwebsite/bugs/</id><updated>2013-08-24T13:22:49.941000Z</updated><subtitle>Recent changes to bugs</subtitle><entry><title>Vlist/File Cabinet Bug</title><link href="https://sourceforge.net/p/phpwebsite/bugs/1869/" rel="alternate"/><published>2013-08-24T13:22:49.941000Z</published><updated>2013-08-24T13:22:49.941000Z</updated><author><name>Englesos</name><uri>https://sourceforge.net/u/englesos/</uri></author><id>https://sourceforge.net1fd5bff8b0b5d20e9422ad6d7f74e1cc7e9e771e</id><summary type="html">&lt;div class="markdown_content"&gt;&lt;p&gt;images uploaded via file cabinet to vlist have reduced colour depth as compared to the full sized images - see example here - &lt;a href="http://www.yearlyrentalscyprus.com/newr/vlist/listing/6" rel="nofollow"&gt;http://www.yearlyrentalscyprus.com/newr/vlist/listing/6&lt;/a&gt;&lt;br /&gt;
This seems to occur at random but I haver been totally unable to find a difference between images that cause the problem and images that do not.&lt;/p&gt;
&lt;p&gt;If you could have a look and let me know your thoughts I would be most grateful.  If you need access to the hosting account/server then I will be happy to provide.&lt;/p&gt;
&lt;p&gt;Many thanks&lt;/p&gt;
&lt;p&gt;Gerry Barrett&lt;/p&gt;&lt;/div&gt;</summary></entry><entry><title>XSS over GET</title><link href="https://sourceforge.net/p/phpwebsite/bugs/1868/" rel="alternate"/><published>2012-12-17T09:42:41Z</published><updated>2012-12-17T09:42:41Z</updated><author><name>ihaiha</name><uri>https://sourceforge.net/u/ihaihaihaiha/</uri></author><id>https://sourceforge.netaa7378ea293b8973176e499cd8d41a0905acc8e5</id><summary type="html">&lt;div class="markdown_content"&gt;&lt;p&gt;Hi, there is a XSS vulnerability because of wrong validation of "cm" parameter.&lt;/p&gt;
&lt;p&gt;Check it out:&lt;br /&gt;
&lt;a href="http://phpwebsite_1_7_3/index.php?module=filecabinet&amp;amp;cm=XSS_HERE&amp;amp;itn=icon&amp;amp;rf=0&amp;amp;fid=0&amp;amp;fr=1&amp;amp;ml=1&amp;amp;mw=60&amp;amp;mh=60&amp;amp;fud=0&amp;amp;ftype=1&amp;amp;fop=fm_folders&amp;amp;authkey=sialala"&gt;http://phpwebsite_1_7_3/index.php?module=filecabinet&amp;amp;cm=XSS_HERE&amp;amp;itn=icon&amp;amp;rf=0&amp;amp;fid=0&amp;amp;fr=1&amp;amp;ml=1&amp;amp;mw=60&amp;amp;mh=60&amp;amp;fud=0&amp;amp;ftype=1&amp;amp;fop=fm_folders&amp;amp;authkey=sialala&lt;/a&gt;&lt;/p&gt;&lt;/div&gt;</summary></entry><entry><title>end user script permissions</title><link href="https://sourceforge.net/p/phpwebsite/bugs/1867/" rel="alternate"/><published>2011-01-26T22:44:41Z</published><updated>2011-01-26T22:44:41Z</updated><author><name>Thomas de Jesus</name><uri>https://sourceforge.net/u/trf000/</uri></author><id>https://sourceforge.net3b69732de13ecb39dbba6c7da0f8362c7482a2dd</id><summary type="html">&lt;div class="markdown_content"&gt;&lt;p&gt;Since the 1.7.0 update, define('ALLOW_SCRIPT_TAGS', true); is no longer added to the config file automatically. without it the Allow script tag input permission in users is rendered useless.&lt;/p&gt;&lt;/div&gt;</summary></entry><entry><title>blank not allowed in mysql password</title><link href="https://sourceforge.net/p/phpwebsite/bugs/1866/" rel="alternate"/><published>2010-08-04T10:59:17Z</published><updated>2010-08-04T10:59:17Z</updated><author><name>Guohua Tang</name><uri>https://sourceforge.net/u/icycandy/</uri></author><id>https://sourceforge.net2bd3a06ce1114309ca09dc1a253767f39c1b3362</id><summary type="html">&lt;div class="markdown_content"&gt;&lt;p&gt;phpWebSite 1.7.0&lt;br /&gt;
CentOS 5.5&lt;br /&gt;
PHP 5.1.6&lt;br /&gt;
MySQL 5.0.77&lt;/p&gt;
&lt;p&gt;I have tried to install the latest phpWebSite 1.7.0. When confinging database settings, I found that blanks are not allowed in mysql password.&lt;br /&gt;
Whereas my password for mysql has a blank, for example, "love you".&lt;br /&gt;
I hope the next release of phpWebSite will repair this bug.&lt;/p&gt;&lt;/div&gt;</summary></entry><entry><title>security.php error on webpage</title><link href="https://sourceforge.net/p/phpwebsite/bugs/1865/" rel="alternate"/><published>2009-08-26T22:30:21Z</published><updated>2009-08-26T22:30:21Z</updated><author><name>Wayne Hammond</name><uri>https://sourceforge.net/u/houhwx/</uri></author><id>https://sourceforge.net6867bc86625f10db19e8ed665320a7a94636e997</id><summary type="html">&lt;div class="markdown_content"&gt;&lt;p&gt;Have been trying to upgrade from 0.1.0..2 to 1.6.3.  Renamed public_html directory and created a new public_directory folder, copied the files from phpwebsite_1_6_3 archive into the directory.  Created a new data base and bata base user as per directions. Installed the website, boosted many of the modules, then ran convert to get data from original site into new site.  Procedure seemed to proceed without incident.&lt;/p&gt;
&lt;p&gt;Renamed setup and convert directories.  Opend website.  Now having problems with all of the pages and menus.  Some items seem to almost work, but many work haphazardly.  Menus give an error when clicking on most links and I have to delete the data after the domain name to get back to the site. All the while there is a message at the top of the screen "ion is active. You cannot change the session module's ini settings at this time. in /home2/glenmea1/public_html/inc/Security.php on line 45"&lt;/p&gt;
&lt;p&gt;The hosting company cannot help me.&lt;br /&gt;
&lt;/p&gt;
&lt;p&gt;The hosting company is using cpanel.&lt;br /&gt;
cPanel Version  11.24.5-RELEASE&lt;br /&gt;
cPanel Build    37946&lt;br /&gt;
Apache version  2.2.13 (Unix)&lt;br /&gt;
PHP version 5.2.9&lt;br /&gt;
MySQL version   5.0.81-community-log&lt;br /&gt;
Architecture    x86_64&lt;br /&gt;
Operating system    Linux&lt;/p&gt;&lt;/div&gt;</summary></entry><entry><title>404 error under specific circumstances</title><link href="https://sourceforge.net/p/phpwebsite/bugs/1864/" rel="alternate"/><published>2009-06-05T16:41:37Z</published><updated>2009-06-05T16:41:37Z</updated><author><name>Andrew Patterson</name><uri>https://sourceforge.net/u/intuitart/</uri></author><id>https://sourceforge.netd5e4c03dd819f785426491ae9c3b44a4fe073ab4</id><summary type="html">&lt;div class="markdown_content"&gt;&lt;p&gt;Environment&lt;/p&gt;
&lt;p&gt;phpwebsite 1.6.2, Core 1.9.4&lt;br /&gt;
See &lt;a href="http://phpws.net/phpinfo.php"&gt;http://phpws.net/phpinfo.php&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Situation&lt;/p&gt;
&lt;p&gt;404 error occurs when accessing a branch site with a url like &lt;a href="http://www.domain.com/branch"&gt;http://www.domain.com/branch&lt;/a&gt; and $_SERVER['REDIRECT_URL'] gets set and contains /branch/index.php. The problem, as near as I can tell, is that getCurrentUrl returns null instead of 'index.php'. When there is no branch involved, 'index.php' is returned. Or when running pws on another host with an identical pws installation except $_SERVER['REDIRECT_URL'] does NOT get set, 'index.php' is returned even when accessing the branch url without the trailing 'index.php'.&lt;/p&gt;
&lt;p&gt;The call to getCurrentUrl that fails is in forwardInfo(). That fails when the forward() function is run from mod/access/inc/init.php.&lt;/p&gt;
&lt;p&gt;I see a comment in getCurrentUrl that "some users reported problems using redirect_url so parsing uri instead". The problem I am seeing now may be a side effect of that change. Parsing redirect_url works in this situation, so my interim fix is to parse that, but I'm not sure what problems other users were reporting so it may not be the best permanent fix.&lt;/p&gt;
&lt;p&gt;This was not easy to describe, so ping me with any questions. And if you want some testing in different environments, I can help with that.&lt;/p&gt;
&lt;p&gt;Andrew P.&lt;/p&gt;&lt;/div&gt;</summary></entry><entry><title>Restricted page in menu causes php error</title><link href="https://sourceforge.net/p/phpwebsite/bugs/1863/" rel="alternate"/><published>2009-05-06T13:22:00Z</published><updated>2009-05-06T13:22:00Z</updated><author><name>Verdon Vaillancourt</name><uri>https://sourceforge.net/u/verdonv/</uri></author><id>https://sourceforge.netf4d1c35748aa3863736296984f96361f8ad928ea</id><summary type="html">&lt;div class="markdown_content"&gt;&lt;p&gt;Creating a pagesmith page (which is added to the menu automatically) and applying view restrictions to it seems to cause a fatal php error when a member of the group logs into the site. The menu item is not displayed to annon visitors, as is correct.&lt;/p&gt;
&lt;p&gt;For instance, a pagesmith page is created and added to the menu. View restrictions are applied to that page, restricting the view to members of two groups. When a user logs in who is a member of one of those groups, the following php error occurs...&lt;br /&gt;
PHP Fatal error:  Call to a member function loadChildren() on a non-object in /home/user/public_html/mod/menu/class/Menu_Item.php on line 246&lt;/p&gt;&lt;/div&gt;</summary></entry><entry><title>Blog Previous Entry view doesn't always display</title><link href="https://sourceforge.net/p/phpwebsite/bugs/1862/" rel="alternate"/><published>2009-04-28T18:18:01Z</published><updated>2009-04-28T18:18:01Z</updated><author><name>Verdon Vaillancourt</name><uri>https://sourceforge.net/u/verdonv/</uri></author><id>https://sourceforge.netb772312d7efae553a788a50555281597e9c7230c</id><summary type="html">&lt;div class="markdown_content"&gt;&lt;p&gt;The previous entries sidebox for blog, for anonymous viewers doesn't always display. Resetting the cache seems to temporarily help. Disabling the cache does help. &lt;/p&gt;&lt;/div&gt;</summary></entry><entry><title>text replaces icon in menu admin</title><link href="https://sourceforge.net/p/phpwebsite/bugs/1861/" rel="alternate"/><published>2009-04-13T06:57:49Z</published><updated>2009-04-13T06:57:49Z</updated><author><name>Englesos</name><uri>https://sourceforge.net/u/englesos/</uri></author><id>https://sourceforge.net57c261b9fcf039bfeeadc1b43749bfefe75fd74d</id><summary type="html">&lt;div class="markdown_content"&gt;&lt;p&gt;Php Version: 5.2.9&lt;br /&gt;
Web Server: Apache version 2.2.11 (Unix)&lt;br /&gt;
Operating System: Linux&lt;br /&gt;
SQL Server: 5.0.77-community&lt;br /&gt;
Browser: IE 8.0.6001&lt;br /&gt;
PhpWebSite Version: 1.6.3&lt;/p&gt;
&lt;p&gt;Hi - when using menu admin, the final icon in the row of four icons displayed when mousing over the spanner and screwdriver icon is missing, and a text link MENU_LINK_INDENT_INCREASE is displayed.&lt;br /&gt;
The link functionality is unaffected, everything seems to work, it seems to be just a display bug.&lt;/p&gt;
&lt;p&gt;Many thanks&lt;/p&gt;&lt;/div&gt;</summary></entry><entry><title>Boost doesn't un-boost 1.6.1</title><link href="https://sourceforge.net/p/phpwebsite/bugs/1860/" rel="alternate"/><published>2009-02-23T16:17:15Z</published><updated>2009-02-23T16:17:15Z</updated><author><name>Thomas de Jesus</name><uri>https://sourceforge.net/u/trf000/</uri></author><id>https://sourceforge.net04ec5c35d8b3a7234f36b7dd3f71f4da2b8180d4</id><summary type="html">&lt;div class="markdown_content"&gt;&lt;p&gt;No error thrown that I can see, but boost doesn't unboost any mods.&lt;/p&gt;&lt;/div&gt;</summary></entry></feed>