Ticket #686 (closed Bug: expired)

Opened 7 years ago

Last modified 3 years ago

FCKeditor.Net: UserFilesPath

Reported by: anonymous Owned by:
Priority: Normal Milestone:
Component: Server : ASP.Net Version:
Keywords: SF Discussion Cc: fredck

Description

in "FileWorkerBase.cs" -> "UserFilesPath" property there is a mistake in order to determine which of "sUserFilesPath" variable will be set. Watch this:

[original code]

...
...
// Otherwise use the default value.
if ( sUserFilesPath == null || sUserFilesPath.Length
== 0 )
sUserFilesPath = DEFAULT_USER_FILES_PATH ;

// Try to get from the URL.
if ( sUserFilesPath == null || sUserFilesPath.Length
== 0 )
{
sUserFilesPath = Request.QueryString
["ServerPath"] ;
}
...

code

spotted? "Try to get from the URL." never works.

[new code]

...
...
// Otherwise use the default value.
// Try to get from the URL.
if ( sUserFilesPath == null || sUserFilesPath.Length
== 0 )
{
sUserFilesPath = Request.QueryString
["ServerPath"] ;
}
if ( sUserFilesPath == null || sUserFilesPath.Length
== 0 )
sUserFilesPath = DEFAULT_USER_FILES_PATH ;
...

code

Greetings, Gürhan Başbuğ.


Moved from SF:
http://sourceforge.net/tracker/index.php?func=detail&aid=1368066&group_id=75348&atid=543653

Change History

comment:1 Changed 7 years ago by martinkou

  • Cc fredck added

Because of security issues, the possibility of passing the UserFilesPath through the URL has been disabled. It is a quite easily hackable feature. We must still decide if it is a good thing to leave this hole opened on FCKeditor.


Moved from SF. Original poster: fredck

comment:2 Changed 7 years ago by martinkou

  • Reporter changed from martinkou to anonymous

comment:3 Changed 7 years ago by alfonsoml

  • Component changed from General to Server : ASP.Net

comment:4 Changed 6 years ago by w.olchawa

  • Keywords Discussion added

comment:5 Changed 3 years ago by wwalc

  • Status changed from new to closed
  • Resolution set to expired

There is a new ASP.NET control available: CKEditor for ASP.NET. The issue is no longer valid as the new control does not have the built-in file browser and the old one is no longer maintained.

Note: See TracTickets for help on using tickets.
© 2003 – 2012 CKSource – Frederico Knabben. All rights reserved. | Terms of use | Privacy policy