<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Recent changes to bugs</title><link>https://sourceforge.net/p/phpwebsite/bugs/</link><description>Recent changes to bugs</description><atom:link href="https://sourceforge.net/p/phpwebsite/bugs/feed.rss" rel="self"/><language>en</language><lastBuildDate>Sat, 24 Aug 2013 13:22:49 -0000</lastBuildDate><atom:link href="https://sourceforge.net/p/phpwebsite/bugs/feed.rss" rel="self" type="application/rss+xml"/><item><title>Vlist/File Cabinet Bug</title><link>https://sourceforge.net/p/phpwebsite/bugs/1869/</link><description>&lt;div class="markdown_content"&gt;&lt;p&gt;images uploaded via file cabinet to vlist have reduced colour depth as compared to the full sized images - see example here - &lt;a href="http://www.yearlyrentalscyprus.com/newr/vlist/listing/6" rel="nofollow"&gt;http://www.yearlyrentalscyprus.com/newr/vlist/listing/6&lt;/a&gt;&lt;br /&gt;
This seems to occur at random but I haver been totally unable to find a difference between images that cause the problem and images that do not.&lt;/p&gt;
&lt;p&gt;If you could have a look and let me know your thoughts I would be most grateful.  If you need access to the hosting account/server then I will be happy to provide.&lt;/p&gt;
&lt;p&gt;Many thanks&lt;/p&gt;
&lt;p&gt;Gerry Barrett&lt;/p&gt;&lt;/div&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Englesos</dc:creator><pubDate>Sat, 24 Aug 2013 13:22:49 -0000</pubDate><guid>https://sourceforge.net1fd5bff8b0b5d20e9422ad6d7f74e1cc7e9e771e</guid></item><item><title>XSS over GET</title><link>https://sourceforge.net/p/phpwebsite/bugs/1868/</link><description>&lt;div class="markdown_content"&gt;&lt;p&gt;Hi, there is a XSS vulnerability because of wrong validation of "cm" parameter.&lt;/p&gt;
&lt;p&gt;Check it out:&lt;br /&gt;
&lt;a href="http://phpwebsite_1_7_3/index.php?module=filecabinet&amp;amp;cm=XSS_HERE&amp;amp;itn=icon&amp;amp;rf=0&amp;amp;fid=0&amp;amp;fr=1&amp;amp;ml=1&amp;amp;mw=60&amp;amp;mh=60&amp;amp;fud=0&amp;amp;ftype=1&amp;amp;fop=fm_folders&amp;amp;authkey=sialala"&gt;http://phpwebsite_1_7_3/index.php?module=filecabinet&amp;amp;cm=XSS_HERE&amp;amp;itn=icon&amp;amp;rf=0&amp;amp;fid=0&amp;amp;fr=1&amp;amp;ml=1&amp;amp;mw=60&amp;amp;mh=60&amp;amp;fud=0&amp;amp;ftype=1&amp;amp;fop=fm_folders&amp;amp;authkey=sialala&lt;/a&gt;&lt;/p&gt;&lt;/div&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">ihaiha</dc:creator><pubDate>Mon, 17 Dec 2012 09:42:41 -0000</pubDate><guid>https://sourceforge.netaa7378ea293b8973176e499cd8d41a0905acc8e5</guid></item><item><title>end user script permissions</title><link>https://sourceforge.net/p/phpwebsite/bugs/1867/</link><description>&lt;div class="markdown_content"&gt;&lt;p&gt;Since the 1.7.0 update, define('ALLOW_SCRIPT_TAGS', true); is no longer added to the config file automatically. without it the Allow script tag input permission in users is rendered useless.&lt;/p&gt;&lt;/div&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Thomas de Jesus</dc:creator><pubDate>Wed, 26 Jan 2011 22:44:41 -0000</pubDate><guid>https://sourceforge.net3b69732de13ecb39dbba6c7da0f8362c7482a2dd</guid></item><item><title>blank not allowed in mysql password</title><link>https://sourceforge.net/p/phpwebsite/bugs/1866/</link><description>&lt;div class="markdown_content"&gt;&lt;p&gt;phpWebSite 1.7.0&lt;br /&gt;
CentOS 5.5&lt;br /&gt;
PHP 5.1.6&lt;br /&gt;
MySQL 5.0.77&lt;/p&gt;
&lt;p&gt;I have tried to install the latest phpWebSite 1.7.0. When confinging database settings, I found that blanks are not allowed in mysql password.&lt;br /&gt;
Whereas my password for mysql has a blank, for example, "love you".&lt;br /&gt;
I hope the next release of phpWebSite will repair this bug.&lt;/p&gt;&lt;/div&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Guohua Tang</dc:creator><pubDate>Wed, 04 Aug 2010 10:59:17 -0000</pubDate><guid>https://sourceforge.net2bd3a06ce1114309ca09dc1a253767f39c1b3362</guid></item><item><title>security.php error on webpage</title><link>https://sourceforge.net/p/phpwebsite/bugs/1865/</link><description>&lt;div class="markdown_content"&gt;&lt;p&gt;Have been trying to upgrade from 0.1.0..2 to 1.6.3.  Renamed public_html directory and created a new public_directory folder, copied the files from phpwebsite_1_6_3 archive into the directory.  Created a new data base and bata base user as per directions. Installed the website, boosted many of the modules, then ran convert to get data from original site into new site.  Procedure seemed to proceed without incident.&lt;/p&gt;
&lt;p&gt;Renamed setup and convert directories.  Opend website.  Now having problems with all of the pages and menus.  Some items seem to almost work, but many work haphazardly.  Menus give an error when clicking on most links and I have to delete the data after the domain name to get back to the site. All the while there is a message at the top of the screen "ion is active. You cannot change the session module's ini settings at this time. in /home2/glenmea1/public_html/inc/Security.php on line 45"&lt;/p&gt;
&lt;p&gt;The hosting company cannot help me.&lt;br /&gt;
&lt;/p&gt;
&lt;p&gt;The hosting company is using cpanel.&lt;br /&gt;
cPanel Version  11.24.5-RELEASE&lt;br /&gt;
cPanel Build    37946&lt;br /&gt;
Apache version  2.2.13 (Unix)&lt;br /&gt;
PHP version 5.2.9&lt;br /&gt;
MySQL version   5.0.81-community-log&lt;br /&gt;
Architecture    x86_64&lt;br /&gt;
Operating system    Linux&lt;/p&gt;&lt;/div&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Wayne Hammond</dc:creator><pubDate>Wed, 26 Aug 2009 22:30:21 -0000</pubDate><guid>https://sourceforge.net6867bc86625f10db19e8ed665320a7a94636e997</guid></item><item><title>404 error under specific circumstances</title><link>https://sourceforge.net/p/phpwebsite/bugs/1864/</link><description>&lt;div class="markdown_content"&gt;&lt;p&gt;Environment&lt;/p&gt;
&lt;p&gt;phpwebsite 1.6.2, Core 1.9.4&lt;br /&gt;
See &lt;a href="http://phpws.net/phpinfo.php"&gt;http://phpws.net/phpinfo.php&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Situation&lt;/p&gt;
&lt;p&gt;404 error occurs when accessing a branch site with a url like &lt;a href="http://www.domain.com/branch"&gt;http://www.domain.com/branch&lt;/a&gt; and $_SERVER['REDIRECT_URL'] gets set and contains /branch/index.php. The problem, as near as I can tell, is that getCurrentUrl returns null instead of 'index.php'. When there is no branch involved, 'index.php' is returned. Or when running pws on another host with an identical pws installation except $_SERVER['REDIRECT_URL'] does NOT get set, 'index.php' is returned even when accessing the branch url without the trailing 'index.php'.&lt;/p&gt;
&lt;p&gt;The call to getCurrentUrl that fails is in forwardInfo(). That fails when the forward() function is run from mod/access/inc/init.php.&lt;/p&gt;
&lt;p&gt;I see a comment in getCurrentUrl that "some users reported problems using redirect_url so parsing uri instead". The problem I am seeing now may be a side effect of that change. Parsing redirect_url works in this situation, so my interim fix is to parse that, but I'm not sure what problems other users were reporting so it may not be the best permanent fix.&lt;/p&gt;
&lt;p&gt;This was not easy to describe, so ping me with any questions. And if you want some testing in different environments, I can help with that.&lt;/p&gt;
&lt;p&gt;Andrew P.&lt;/p&gt;&lt;/div&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Andrew Patterson</dc:creator><pubDate>Fri, 05 Jun 2009 16:41:37 -0000</pubDate><guid>https://sourceforge.netd5e4c03dd819f785426491ae9c3b44a4fe073ab4</guid></item><item><title>Restricted page in menu causes php error</title><link>https://sourceforge.net/p/phpwebsite/bugs/1863/</link><description>&lt;div class="markdown_content"&gt;&lt;p&gt;Creating a pagesmith page (which is added to the menu automatically) and applying view restrictions to it seems to cause a fatal php error when a member of the group logs into the site. The menu item is not displayed to annon visitors, as is correct.&lt;/p&gt;
&lt;p&gt;For instance, a pagesmith page is created and added to the menu. View restrictions are applied to that page, restricting the view to members of two groups. When a user logs in who is a member of one of those groups, the following php error occurs...&lt;br /&gt;
PHP Fatal error:  Call to a member function loadChildren() on a non-object in /home/user/public_html/mod/menu/class/Menu_Item.php on line 246&lt;/p&gt;&lt;/div&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Verdon Vaillancourt</dc:creator><pubDate>Wed, 06 May 2009 13:22:00 -0000</pubDate><guid>https://sourceforge.netf4d1c35748aa3863736296984f96361f8ad928ea</guid></item><item><title>Blog Previous Entry view doesn't always display</title><link>https://sourceforge.net/p/phpwebsite/bugs/1862/</link><description>&lt;div class="markdown_content"&gt;&lt;p&gt;The previous entries sidebox for blog, for anonymous viewers doesn't always display. Resetting the cache seems to temporarily help. Disabling the cache does help. &lt;/p&gt;&lt;/div&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Verdon Vaillancourt</dc:creator><pubDate>Tue, 28 Apr 2009 18:18:01 -0000</pubDate><guid>https://sourceforge.netb772312d7efae553a788a50555281597e9c7230c</guid></item><item><title>text replaces icon in menu admin</title><link>https://sourceforge.net/p/phpwebsite/bugs/1861/</link><description>&lt;div class="markdown_content"&gt;&lt;p&gt;Php Version: 5.2.9&lt;br /&gt;
Web Server: Apache version 2.2.11 (Unix)&lt;br /&gt;
Operating System: Linux&lt;br /&gt;
SQL Server: 5.0.77-community&lt;br /&gt;
Browser: IE 8.0.6001&lt;br /&gt;
PhpWebSite Version: 1.6.3&lt;/p&gt;
&lt;p&gt;Hi - when using menu admin, the final icon in the row of four icons displayed when mousing over the spanner and screwdriver icon is missing, and a text link MENU_LINK_INDENT_INCREASE is displayed.&lt;br /&gt;
The link functionality is unaffected, everything seems to work, it seems to be just a display bug.&lt;/p&gt;
&lt;p&gt;Many thanks&lt;/p&gt;&lt;/div&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Englesos</dc:creator><pubDate>Mon, 13 Apr 2009 06:57:49 -0000</pubDate><guid>https://sourceforge.net57c261b9fcf039bfeeadc1b43749bfefe75fd74d</guid></item><item><title>Boost doesn't un-boost 1.6.1</title><link>https://sourceforge.net/p/phpwebsite/bugs/1860/</link><description>&lt;div class="markdown_content"&gt;&lt;p&gt;No error thrown that I can see, but boost doesn't unboost any mods.&lt;/p&gt;&lt;/div&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Thomas de Jesus</dc:creator><pubDate>Mon, 23 Feb 2009 16:17:15 -0000</pubDate><guid>https://sourceforge.net04ec5c35d8b3a7234f36b7dd3f71f4da2b8180d4</guid></item></channel></rss>