From 1f51482a0c4d152ca876844212b0f8f3cb9387af Mon Sep 17 00:00:00 2001 From: nilsteampassnet Date: Wed, 24 May 2023 08:59:22 +0200 Subject: [PATCH] 3.0.9 Fix vulnerability in form folder creation --- includes/config/include.php | 2 +- {install1 => install}/css/install.css | 0 .../css/overcast/images/animated-overlay.gif | Bin .../images/ui-bg_flat_0_aaaaaa_40x100.png | Bin .../images/ui-bg_flat_0_eeeeee_40x100.png | Bin .../images/ui-bg_flat_55_c0402a_40x100.png | Bin .../images/ui-bg_flat_55_eeeeee_40x100.png | Bin .../images/ui-bg_glass_100_f8f8f8_1x400.png | Bin .../images/ui-bg_glass_35_dddddd_1x400.png | Bin .../images/ui-bg_glass_60_eeeeee_1x400.png | Bin .../ui-bg_inset-hard_75_999999_1x100.png | Bin .../ui-bg_inset-soft_50_c9c9c9_1x100.png | Bin .../images/ui-icons_3383bb_256x240.png | Bin .../images/ui-icons_454545_256x240.png | Bin .../images/ui-icons_70b2e1_256x240.png | Bin .../images/ui-icons_999999_256x240.png | Bin .../images/ui-icons_fbc856_256x240.png | Bin .../overcast/jquery-ui-1.10.3.custom.min.css | 0 {install1 => install}/images/76.gif | Bin {install1 => install}/images/ajax-loader.gif | Bin {install1 => install}/images/cross.png | Bin {install1 => install}/images/error.png | Bin .../images/exclamation-red.png | Bin .../images/information-white.png | Bin {install1 => install}/images/minus-circle.png | Bin {install1 => install}/images/tick-circle.png | Bin {install1 => install}/images/tick.png | Bin {install1 => install}/install.js | 0 {install1 => install}/install.php | 0 {install1 => install}/install.queries.php | 0 {install1/install => install}/js/aes.min.js | 0 .../js/crypt/aes.class.php | 0 .../install => install}/js/crypt/aes.min.js | 0 .../js/crypt/aesctr.class.php | 0 .../install => install}/js/jquery-ui.min.js | 0 .../install => install}/js/jquery.min.js | 0 {install1/install => install}/libs/aesctr.php | 0 {install1 => install}/migrate_users_to_v3.php | 0 {install1 => install}/tp.functions.php | 0 {install1 => install}/upgrade.php | 0 {install1 => install}/upgrade_ajax.php | 0 {install1 => install}/upgrade_run_3.0.0.php | 0 .../upgrade_run_3.0.0_fields.php | 0 .../upgrade_run_3.0.0_files.php | 0 .../upgrade_run_3.0.0_logs.php | 0 .../upgrade_run_3.0.0_passwords.php | 0 .../upgrade_run_3.0.0_suggestions.php | 0 .../upgrade_run_3.0.0_users.php | 0 {install1 => install}/upgrade_run_3.0.php | 0 .../upgrade_scripts_manager.php | 0 install1/install/css/install.css | 123 ---- .../css/overcast/images/animated-overlay.gif | Bin 1738 -> 0 bytes .../images/ui-bg_flat_0_aaaaaa_40x100.png | Bin 212 -> 0 bytes .../images/ui-bg_flat_0_eeeeee_40x100.png | Bin 220 -> 0 bytes .../images/ui-bg_flat_55_c0402a_40x100.png | Bin 205 -> 0 bytes .../images/ui-bg_flat_55_eeeeee_40x100.png | Bin 220 -> 0 bytes .../images/ui-bg_glass_100_f8f8f8_1x400.png | Bin 259 -> 0 bytes .../images/ui-bg_glass_35_dddddd_1x400.png | Bin 254 -> 0 bytes .../images/ui-bg_glass_60_eeeeee_1x400.png | Bin 254 -> 0 bytes .../ui-bg_inset-hard_75_999999_1x100.png | Bin 247 -> 0 bytes .../ui-bg_inset-soft_50_c9c9c9_1x100.png | Bin 254 -> 0 bytes .../images/ui-icons_3383bb_256x240.png | Bin 4430 -> 0 bytes .../images/ui-icons_454545_256x240.png | Bin 4431 -> 0 bytes .../images/ui-icons_70b2e1_256x240.png | Bin 4430 -> 0 bytes .../images/ui-icons_999999_256x240.png | Bin 4431 -> 0 bytes .../images/ui-icons_fbc856_256x240.png | Bin 4430 -> 0 bytes .../overcast/jquery-ui-1.10.3.custom.min.css | 5 - install1/install/images/76.gif | Bin 5440 -> 0 bytes install1/install/images/ajax-loader.gif | Bin 882 -> 0 bytes install1/install/images/cross.png | Bin 655 -> 0 bytes install1/install/images/error.png | Bin 666 -> 0 bytes install1/install/images/exclamation-red.png | Bin 696 -> 0 bytes install1/install/images/information-white.png | Bin 707 -> 0 bytes install1/install/images/minus-circle.png | Bin 655 -> 0 bytes install1/install/images/tick-circle.png | Bin 724 -> 0 bytes install1/install/images/tick.png | Bin 634 -> 0 bytes install1/js/aes.min.js | 457 ------------- install1/js/crypt/aes.class.php | 207 ------ install1/js/crypt/aes.min.js | 457 ------------- install1/js/crypt/aesctr.class.php | 191 ------ install1/js/jquery-ui.min.js | 638 ------------------ install1/js/jquery.min.js | 18 - install1/libs/aesctr.php | 406 ----------- pages/items.js.php | 10 +- pages/users.js.php | 2 +- sources/main.functions.php | 4 +- 86 files changed, 9 insertions(+), 2511 deletions(-) rename {install1 => install}/css/install.css (100%) rename {install1 => install}/css/overcast/images/animated-overlay.gif (100%) rename {install1 => install}/css/overcast/images/ui-bg_flat_0_aaaaaa_40x100.png (100%) rename {install1 => install}/css/overcast/images/ui-bg_flat_0_eeeeee_40x100.png (100%) rename {install1 => install}/css/overcast/images/ui-bg_flat_55_c0402a_40x100.png (100%) rename {install1 => install}/css/overcast/images/ui-bg_flat_55_eeeeee_40x100.png (100%) rename {install1 => install}/css/overcast/images/ui-bg_glass_100_f8f8f8_1x400.png (100%) rename {install1 => install}/css/overcast/images/ui-bg_glass_35_dddddd_1x400.png (100%) rename {install1 => install}/css/overcast/images/ui-bg_glass_60_eeeeee_1x400.png (100%) rename {install1 => install}/css/overcast/images/ui-bg_inset-hard_75_999999_1x100.png (100%) rename {install1 => install}/css/overcast/images/ui-bg_inset-soft_50_c9c9c9_1x100.png (100%) rename {install1 => install}/css/overcast/images/ui-icons_3383bb_256x240.png (100%) rename {install1 => install}/css/overcast/images/ui-icons_454545_256x240.png (100%) rename {install1 => install}/css/overcast/images/ui-icons_70b2e1_256x240.png (100%) rename {install1 => install}/css/overcast/images/ui-icons_999999_256x240.png (100%) rename {install1 => install}/css/overcast/images/ui-icons_fbc856_256x240.png (100%) rename {install1 => install}/css/overcast/jquery-ui-1.10.3.custom.min.css (100%) rename {install1 => install}/images/76.gif (100%) rename {install1 => install}/images/ajax-loader.gif (100%) rename {install1 => install}/images/cross.png (100%) rename {install1 => install}/images/error.png (100%) rename {install1 => install}/images/exclamation-red.png (100%) rename {install1 => install}/images/information-white.png (100%) rename {install1 => install}/images/minus-circle.png (100%) rename {install1 => install}/images/tick-circle.png (100%) rename {install1 => install}/images/tick.png (100%) rename {install1 => install}/install.js (100%) rename {install1 => install}/install.php (100%) rename {install1 => install}/install.queries.php (100%) rename {install1/install => install}/js/aes.min.js (100%) rename {install1/install => install}/js/crypt/aes.class.php (100%) rename {install1/install => install}/js/crypt/aes.min.js (100%) rename {install1/install => install}/js/crypt/aesctr.class.php (100%) rename {install1/install => install}/js/jquery-ui.min.js (100%) rename {install1/install => install}/js/jquery.min.js (100%) rename {install1/install => install}/libs/aesctr.php (100%) rename {install1 => install}/migrate_users_to_v3.php (100%) rename {install1 => install}/tp.functions.php (100%) rename {install1 => install}/upgrade.php (100%) rename {install1 => install}/upgrade_ajax.php (100%) rename {install1 => install}/upgrade_run_3.0.0.php (100%) rename {install1 => install}/upgrade_run_3.0.0_fields.php (100%) rename {install1 => install}/upgrade_run_3.0.0_files.php (100%) rename {install1 => install}/upgrade_run_3.0.0_logs.php (100%) rename {install1 => install}/upgrade_run_3.0.0_passwords.php (100%) rename {install1 => install}/upgrade_run_3.0.0_suggestions.php (100%) rename {install1 => install}/upgrade_run_3.0.0_users.php (100%) rename {install1 => install}/upgrade_run_3.0.php (100%) rename {install1 => install}/upgrade_scripts_manager.php (100%) delete mode 100755 install1/install/css/install.css delete mode 100755 install1/install/css/overcast/images/animated-overlay.gif delete mode 100755 install1/install/css/overcast/images/ui-bg_flat_0_aaaaaa_40x100.png delete mode 100755 install1/install/css/overcast/images/ui-bg_flat_0_eeeeee_40x100.png delete mode 100755 install1/install/css/overcast/images/ui-bg_flat_55_c0402a_40x100.png delete mode 100755 install1/install/css/overcast/images/ui-bg_flat_55_eeeeee_40x100.png delete mode 100755 install1/install/css/overcast/images/ui-bg_glass_100_f8f8f8_1x400.png delete mode 100755 install1/install/css/overcast/images/ui-bg_glass_35_dddddd_1x400.png delete mode 100755 install1/install/css/overcast/images/ui-bg_glass_60_eeeeee_1x400.png delete mode 100755 install1/install/css/overcast/images/ui-bg_inset-hard_75_999999_1x100.png delete mode 100755 install1/install/css/overcast/images/ui-bg_inset-soft_50_c9c9c9_1x100.png delete mode 100755 install1/install/css/overcast/images/ui-icons_3383bb_256x240.png delete mode 100755 install1/install/css/overcast/images/ui-icons_454545_256x240.png delete mode 100755 install1/install/css/overcast/images/ui-icons_70b2e1_256x240.png delete mode 100755 install1/install/css/overcast/images/ui-icons_999999_256x240.png delete mode 100755 install1/install/css/overcast/images/ui-icons_fbc856_256x240.png delete mode 100755 install1/install/css/overcast/jquery-ui-1.10.3.custom.min.css delete mode 100755 install1/install/images/76.gif delete mode 100755 install1/install/images/ajax-loader.gif delete mode 100755 install1/install/images/cross.png delete mode 100755 install1/install/images/error.png delete mode 100755 install1/install/images/exclamation-red.png delete mode 100755 install1/install/images/information-white.png delete mode 100755 install1/install/images/minus-circle.png delete mode 100755 install1/install/images/tick-circle.png delete mode 100755 install1/install/images/tick.png delete mode 100755 install1/js/aes.min.js delete mode 100755 install1/js/crypt/aes.class.php delete mode 100755 install1/js/crypt/aes.min.js delete mode 100755 install1/js/crypt/aesctr.class.php delete mode 100755 install1/js/jquery-ui.min.js delete mode 100755 install1/js/jquery.min.js delete mode 100755 install1/libs/aesctr.php diff --git a/includes/config/include.php b/includes/config/include.php index e39d33a29..6d1528975 100755 --- a/includes/config/include.php +++ b/includes/config/include.php @@ -29,7 +29,7 @@ define('TP_ALLOWED_TAGS', '