General Community > Global WebsiteBaker 2.8.x discussion

SQL Injection vulnerability

(1/3) > >>

Mallepree:
Sorry... but WBCE definitively is NOT WebsiteBaker.

As the development of WBCE took place from the beginning without any consultation with WB, it's no longer guaranteed that all functions and files are compatible.

Therefore, I must strongly warn to use patches from third-party software. 

Only yesterday we were designated in the WBCE forum as a liar when we gave out a security alert here.
This behavior is certainly not a basis for a fairly cooperation.

Manuela

tez:
Do I understand it correctly the SQL Injection Fix zip-file can be installed as an Addon?
Or manually by FTP?

Cheerz,

Tez Oner

jacobi22:

--- Quote from: Tez Oner on February 27, 2016, 08:52:54 PM ---Do I understand it correctly the SQL Injection Fix zip-file can be installed as an Addon?
Or manually by FTP?


--- End quote ---

manually by FTP

see readme:
Step 1
- Upload all the files into the coresponding directories on your Webspace

P.S: the in this package included folder install is not needed, also the config.php.new

tez:
Hey,

got this error trying to run the upgrade script:


--- Code: ---There was an uncatched exception: Unknown MySQL server host 'mysql02:3306' (2) in line (51) of (/framework/class.database.php)
--- End code ---

Any ideas, tried it serveral times, but error keep showing up.


Cheerz,

Tez Oner

jacobi22:
looks for me like a old module, that use a mysql-function instead of mysqli (maybe mysql_connect) in the file "upgrade.php" of this module
you can start the manual upgrade from all your used non-core-modules (not delivered with the SP-Package), to found the troublemaker

Navigation

[0] Message Index

[#] Next page

Go to full version