1
xoobaru
Java and extGallery dependency on same for uploads
  • 2013/1/28 14:54

  • xoobaru

  • Just can't stay away

  • Posts: 494

  • Since: 2010/12/2


Hello readers,

Java is in trouble as national level alerts have been issued by DHS (Department of Homeland Security) to turn Java off because it now presents dangerous hacking vulnerabilities to its users.

Additionally, Firefox has been automatically turning off Java plugins and marking them unsafe in the event the user tries to turn them back on. It is more than just a release or update issue, Java seems to have trouble staying on top of their threat matrix and is steadily losing ground in the race.

When testing the public upload feature of extGallery 1.11, the "plugin disabled" notice appeared, which turned out to be directly related to the dangerous Java plugin having been turned off. I am wondering why public gallery uploads for this module depend on Java when other upload features such as user uploaded Avatars in XOOPS uses PHP successfully.

I respect the Java warning as valid, and have disabled public upload capability as it cannot be used safely. There may be other modules with such a dependency, but I am not aware of them. Just wanted to get this out there.

2
Anonymous
Re: Java and extGallery dependency on same for uploads
  • 2013/1/28 15:30

  • Anonymous

  • Posts: 0

  • Since:


Extgallery has also a public upload feature without Java. In admin you can choose for standard (without java) or extended (java).

3
xoobaru
Re: Java and extGallery dependency on same for uploads
  • 2013/1/28 16:28

  • xoobaru

  • Just can't stay away

  • Posts: 494

  • Since: 2010/12/2


Well shucks...
I located and changed the config, which looks like it changes the php file that is called.

Appears that Java is not the only one with an issue, but we will not mention any names here to avoid embarrassing the original submitter....


at least the Java alert still needed to be raised

4
Cifug
Re: Java and extGallery dependency on same for uploads
  • 2013/1/28 21:36

  • Cifug

  • Quite a regular

  • Posts: 208

  • Since: 2007/12/13


Must have been in the last windows update as my jupload script has also stopped working.

I know about the "batch upload" feature but it isn't always useful or efficient.

Is there any way to set up multiple file uploads in "standard" type page?

Regards,
Marty.

5
Anonymous
Re: Java and extGallery dependency on same for uploads
  • 2013/1/28 21:49

  • Anonymous

  • Posts: 0

  • Since:


Just wait for the coming Java update Cifug. Oracle is a big company and Java an important product, I'll bet with you they are sweating to fix current problems

6
Cifug
Re: Java and extGallery dependency on same for uploads
  • 2013/1/28 22:00

  • Cifug

  • Quite a regular

  • Posts: 208

  • Since: 2007/12/13


Quote:
flipse wrote:
Just wait for the coming Java update Cifug. Oracle is a big company and Java an important product, I'll bet with you they are sweating to fix current problems

Oh ok cool

Will we have to update the applet or is the vulnerability in windows?

Login

Who's Online

363 user(s) are online (220 user(s) are browsing Support Forums)


Members: 0


Guests: 363


more...

Donat-O-Meter

Stats
Goal: $100.00
Due Date: Nov 30
Gross Amount: $0.00
Net Balance: $0.00
Left to go: $100.00
Make donations with PayPal!

Latest GitHub Commits