|
|
Zoom and CB Plugin installed on JP!
|
|
Date: 2005/12/01 03:33
|
By: yatesf
|
Status: User
|
|
|
Karma: 0  
|
|
Fresh Joomlapolitan  | Posts: 14 |   | |
|
This thread discusses the Content article: Zoom and CB Plugin installed on JP!
Man, oh man! So glad you guys got this out so quickly. I'm anxious for the bug tested release, so that I can implement for my community. This is a really valuable plugin in my opinion. Great job Pete for inventing it and to Trail for assisting in the refinement -Fred
|
|
The administrator has disabled public write access. |
|
|
|
Re:Zoom and CB Plugin installed on JP!
|
|
Date: 2005/12/01 23:51
|
By: trail
|
Status: Admin
|
|
|
Karma: 656  
|
|
Admin  | Posts: 473 |   | |
|
For the third time: zoom has a ugly bug making it possible for any user to delete any other users images.
If you install the zoom plugin, you have to lower security in zoom, causing this secuirty leak to be enabled.
Use at your own risk. You have been warned.
Post edited by: trail, at: 2005/12/01 17:52 DJ Trail. CB Co-Founder & Test-Lead. Plugins: My Age, Starsign Matchmaking Horoscope, My Visitor, My Highscores, My ProfileID, My Components: Import & Invite Karma Casino (Use Test / Test) My Modules: Many 
|
|
The administrator has disabled public write access. |
|
|
|
Re:Zoom and CB Plugin installed on JP!
|
|
Date: 2005/12/02 00:04
|
By: rick
|
Status: User
|
|
|
Karma: 43  
|
|
Gold Joomlapolitan  | Posts: 290 |   | |
|
DJ,
Do you think it is possable to fix/patch it to close the security hole? Rick
Running: Joomla! 1.0.7 Stable Community Builder 1.0 rc2 SMF 1.1 RC2
|
|
The administrator has disabled public write access. |
|
|
|
Re:Zoom and CB Plugin installed on JP!
|
|
Date: 2005/12/02 01:46
|
By: trail
|
Status: Admin
|
|
|
Karma: 656  
|
|
Admin  | Posts: 473 |   | |
|
Yes but in order to patch the hole, the bug must become known.. if Z00M author doesn't reply to my email and doesn't fix it.. and this -remote-from-zoom-forum- posts the bug in the open (with fix) then a lot of wanna-be-arseholes could use the info to exploit the bug on sites with admins that don't frequent this site and who logically assume they can get security updates from the z00m site..
I think its reasonable to give the z00m author a few weeks to fix this himself before i post the bug out in the open.. even if it comes along with a fix.
The next option is for me to release my enhanced z00m version.. but did you just hear how that sounded.. zoom-e ? NEVER will i make that mistake No.. i think we have to wait for Z00M author to fix it.. 
Post edited by: trail, at: 2005/12/01 19:54 DJ Trail. CB Co-Founder & Test-Lead. Plugins: My Age, Starsign Matchmaking Horoscope, My Visitor, My Highscores, My ProfileID, My Components: Import & Invite Karma Casino (Use Test / Test) My Modules: Many 
|
|
The administrator has disabled public write access. |
|
|
|
Re:Zoom and CB Plugin installed on JP!
|
|
Date: 2005/12/02 04:57
|
By: irgendwer
|
Status: User
|
|
|
Karma: 2  
|
|
Senior Joomlapolitan  | Posts: 87 |   | |
|
Is it possible to not view the user galleries in the main gallery area or create a folder in the gallery mainarea which contains the user galleries? Cause this kinda sucks when you have normal galleries which almost disappear in all the user galleries. South Korea's got Seoul
|
|
The administrator has disabled public write access. |
|
|
|
Re:Zoom and CB Plugin installed on JP!
|
|
Date: 2005/12/05 11:28
|
By: dsendecki
|
Status: User
|
|
|
Karma: 13  
|
|
Gold Joomlapolitan  | Posts: 386 |   | |
|
See that you guys fixed the security problem with the delete bug. Any progress on the lightboc problems? Thanks guys, this plugin looks cool.
Thanks in advance!
When I try to lightbox a gallery, I get:
Fatal error: Call to a member function on a non-object in /home/joomlapo/public_html/components/com_zoom/www/view.php on line 98
Also, when I try to view my gallery, I get redirected to the homepage because of a malformed URL:
http://www.joomlapolis.com/component/index.php/ Small Press Exchange | Free eBook templates for self publishing | My Blog
|
|
The administrator has disabled public write access. |
|
|