11
Quote:
pjeutr wrote:
Try adding the following at the top of init_basic.php
Seems to work for me, dunno why it should be possible that the base base can be a url.
// Hack prevention.
if (!empty($_REQUEST["GALLERY_BASEDIR"])) {
error_log("Security violation\n" .$_REQUEST["GALLERY_BASEDIR"]);
exit;
}
Ill give this a try in a 4 year old established site and see what happens. sence its attacked on a daly basis.
@ Billy
Moving to a new galley setup would be the best idea, but some people have grown acustom to there setup, and some times those setps,gallerys can contain well over a few gigs in picutes, lol time and money they wish not to spend on a transfer, money they wish to invest into makeing the cerrent setup work.
@ BS
Ill check these out, from what ive been reading 2.1B4 doesnt have this isue. so im looking for this version to test out.
@ all
Please go to the following link and read it.
http://www.securityfocus.com/bid/27155this isue has been noted by others,meaning little time till it becomes a large problem. to find a fix or repair is in high demand.
Marc