Skip site navigation (1)Skip section navigation (2)
Date:      Wed, 3 Mar 2004 16:28:25 +0100
From:      Simon Barner <barner@in.tum.de>
To:        rfa@msumain.edu.ph
Cc:        freebsd-questions@freebsd.org
Subject:   Re: phpnuke forbidden, how to install?
Message-ID:  <20040303152825.GA427@zi025.glhnet.mhn.de>
In-Reply-To: <3665.203.177.105.170.1078314472.squirrel@bayok.msumain.edu.ph>
References:  <3665.203.177.105.170.1078314472.squirrel@bayok.msumain.edu.ph>

next in thread | previous in thread | raw e-mail | index | archive | help

--XsQoSWH+UP9D9v3l
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
Content-Transfer-Encoding: quoted-printable

rfa@msumain.edu.ph wrote:
> i wanted to install phpnuke for content but after cvsuping i found out th=
at
>=20
> =3D=3D=3D>  phpnuke-6.9 is forbidden: SQL injection vulnerability in Php-=
Nuke <=3D
> 7.1.0.

Hi,

I have created a patch that contains the security fixes from the web
site.

It's available here:

http://home.leo.org/~barner/phpnuke-sec-fixes.patch.bz2

Could you please test whether phpnuke works as exspected after applying
the patch?

 cd /usr/ports/www
 cat /path/to/phpnuke-sec-fixes.patch.bz2 | bunzip2 | patch -p
 cd phpnuke
 find . -name "*.orig" -exec rm {} \;
 make build

If your tests are successfull, I will file a PR in order to the the port
updated.

Simon

--XsQoSWH+UP9D9v3l
Content-Type: application/pgp-signature
Content-Disposition: inline

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.4 (FreeBSD)

iD8DBQFARfmZCkn+/eutqCoRAl40AKDHGSINJugCsqSDY8Mtcge4VPOiWwCgqM3w
AJ3Z3NLGPkE4vJ7vrl//clk=
=BJqi
-----END PGP SIGNATURE-----

--XsQoSWH+UP9D9v3l--



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?20040303152825.GA427>