Directory traversal vulnerability on Xoops CMS module "tutorials"
Short description:
An attacker can use this flaw to execute arbitrary code of his choice on the remote system, run with the privileges of httpd. The code can be written in any scripting language whose parser is run in the remote system in cooporation with httpd, whether as module or executable.
I work already on the translation of tutorials created on the french version. I hope that this site becomes the "official" site of the new "theme development team".
The url of the new english support web site is http://www.xoops-themes.org. It should be available in 12-24 hours (sorry - DNS)
The much anticipated release of MyHeadlines v4.2.1 is now complete. The downloads are online. Here are the highlights:
Template Layout System - Now MyHeadlines is fully customizable! As the admin you have easy access to the raw HTML of the MyHeadlines output and can skin the module to match your site's theme.
Sections - MyHeadlines now supports the creation of static news pages where the site admin may group multiple sources together. This is quite similar in nature to the Business or Sports sections of your local news paper.
Improved Graphical Interface - The more recognizable "plus / minus" interface replaces the campy "\__" ASCII art of the previous versions. This also fixes nasty UNICODE artifacts if your local language is a 2 byte system (Asia, and others)
Blogger API and RSD Support - This is the number one requested feature since the birth of MyHeadlines.
Find A Source - Allows for searching for sources from the massive 20,000+ database of RSS feeds over at Syndic8.
This evening I have released my latest version of TSW [The Saint WAMP]. TSW is a multilinguale (english/german) WAMP-Installer-Routine like Foxserv, or Appserv, only better
The reason for that is the shipped Xoops 2.0.2
Other components are: + Apache 1.3.27 which is for controlling Apache2: + Apache 2.0.46 + PHP 4.3.2 + PERL 5.8.0 (806) + MySQL 4.0.13
The distribution has also a FTP-Server integrated and several other components (Applications & Webapplications)
As mentioned above, Xoops is one of the new features in this version 2.5
Thx Joker @http://localfoo.net (The download is for registered users only, but this is free and doesn't hurt :)
Now that someone has taken the initiative and created an Xoops Module development team. I think we can all agree that version 2 is surely lacking in the theme department. I think we need to form an "official" theme development team.
Unlike the modules and the core, there are several tutorials on how to create themes for X2, and a list of all the Smarty Classes as well. So there's no reason why X2 should be lacking in Themes, especially original, fresh ones (not the same variations of nuke style themes that we've come to know).
I'm no graphic designer so probably wouldn't be a good contributor to this. I'm willing to create a new website devoted to X2 Theme Development. I know there is an Xoops Theme site somewhere, but it's not in English, therefore not very usefull to us English speaking folks.
We can even give away DVDs or something for the top theme developer of the month.
This is a general invitation to developers to sign up for the first XOOPS Module Development project: a XOOPS eCommerce module. By popular demand the XOOPS Module Development Team has decided that the first project will be the development of a full blown eCommerce module for XOOPS. We would like to invite all developers who want to participate actively in this project to send an e-mail with your level of experience, motivation, feature wishes and an estimate of your available time to herko@modules.xoops2.com. Experience with eCommerce apps like osCommerce is an advantage.
What can I say, I just love makin' themes.... I am gonna take a little break making them though, I should get a full night sleep every once in a while, but it's in my downloads secion. I called it "Xbox" , first of all because I'm a fan, and second because I like havin'a theme for a theme which makes it easier to create something.
I am organizing a community for CyberPsychology studies. This website in powered by Xoops v.2.0.2 and all modules that I installed seems to be working fine. I would like to congratulate and thanks to all of you for this wonderful CMS and also for the huge support for users! If you would like to review it, give suggestion and so on , please be my guest! My Portal was possible because all of you! THANKS!