close ad
Install the LAtest Updates to Work with CC 2017 and CC 2018
open ad
View Menu

Technical Support Forums

Free, outstanding support from WebAssist and your colleagues

rating

Security Issue - Server Asset Folder

Thread began 8/26/2011 4:40 am by contactus306424 | Last modified 9/19/2011 11:21 am by Dave Buchholz | 1855 views | 8 replies |

contactus306424

Security Issue - Server Asset Folder

Are you aware that direct unsecure access can be made to the server asset area using the following URL (cms is the PowerCMS folder), you don't need a username or password to gain access.

index.php?lang=default&kfm_caller_type=fck&type=Image

Anyone else concerned about this?

Sign in to reply to this post

Jason ByrnesWebAssist

This is fixed in Power CMS 2.1.1.

to fix it in earlier version. edit the HTMLEditor/editor/plugins/kfm/configuration.php file. change:

php:
<?php require_once( "../../../../Connections/PowerCMSConnection.php" ); ?>

<?php 
require_once( "../../../WA_Globals.php" ); ?>



to:

php:
<?php require_once( "../../../../Connections/PowerCMSConnection.php" ); ?>

<?php 
require_once( "../../../WA_Globals.php" ); ?>
<?php 
require_once( "../../../../WA_SecurityAssist/Helper_PHP.php" ); ?>
<?php
if (!WA_Auth_RulePasses("Administrator")){
    die();
}
?>
Sign in to reply to this post

contactus306424

Great, thanks for your assistance...

Sign in to reply to this post

contactus306424

I get the following Errors with that modification

Warning: Cannot modify header information - headers already sent by (output started at /home/vanguard/public_html/cmscontrol/HTMLEditor/editor/plugins/kfm/configuration.php:4) in /home/vanguard/public_html/cmscontrol/HTMLEditor/editor/plugins/kfm/includes/session.class.php on line 31

Warning: Cannot modify header information - headers already sent by (output started at /home/vanguard/public_html/cmscontrol/HTMLEditor/editor/plugins/kfm/configuration.php:4) in /home/vanguard/public_html/cmscontrol/HTMLEditor/editor/plugins/kfm/index.php on line 73

Sign in to reply to this post

Ray BorduinWebAssist

It looks like you might have an extra space character on line 4 of /HTMLEditor/editor/plugins/kfm/configuration.php.

That is just a guess... If you attach a copy of that page I can look into it further.

Sign in to reply to this post

contactus306424

Thanks ray, you are correct there was an extra space in there, all working fine now...

Sign in to reply to this post

msummers194171

It appears that I have the same exploit going on my PowerStore site. But my configuration.php file has this content -

<?php require_once( "../../../../Connections/PowerStoreConnection.php" ); ?>
<?php require_once( "../../../../webassist/framework/library.php" ); ?>
<?php
/**
* KFM - Kae's File Manager

How should I implement this fix?

Sign in to reply to this post

Jason ByrnesWebAssist

There is a fix for this available in the Known Issues section of the Power Store download center page.

Sign in to reply to this post

Dave BuchholzBeta Tester

Jason, surely the fact that the fix is available should be publicised, I have a number of clients who have been affected by this issue and none of them were aware of this fix.

Sign in to reply to this post

Build websites with a little help from your friends

Your friends over here at WebAssist! These Dreamweaver extensions will assist you in building unlimited, custom websites.

Build websites from already-built web applications

These out-of-the-box solutions provide you proven, tested applications that can be up and running now.  Build a store, a gallery, or a web-based email solution.

Want your website pre-built and hosted?

Close Windowclose

Rate your experience or provide feedback on this page

Account or customer service questions?
Please user our contact form.

Need technical support?
Please visit support to ask a question

Content

rating

Layout

rating

Ease of use

rating

security code refresh image

We do not respond to comments submitted from this page directly, but we do read and analyze any feedback and will use it to help make your experience better in the future.

Close Windowclose

We were unable to retrieve the attached file

Close Windowclose

Attach and remove files

add attachmentAdd attachment
Close Windowclose

Enter the URL you would like to link to in your post

Close Windowclose

This is how you use right click RTF editing

Enable right click RTF editing option allows you to add html markup into your tutorial such as images, bulleted lists, files and more...

-- click to close --

Uploading file...