Forums / Developer / Users editing their own details

Users editing their own details

Author Message

Tony Wood

Sunday 18 May 2003 11:10:46 am

SNIP

Tony Wood : twitter.com/tonywood
Vision with Technology
Experts in eZ Publish consulting & development

Power to the Editor!

Free eZ Training : http://www.VisionWT.com/training
eZ Future Podcast : http://www.VisionWT.com/eZ-Future

Selmah Maxim

Monday 19 May 2003 12:19:40 am

Hi ..

check the permissions for users !

Tony Wood

Monday 19 May 2003 12:41:06 am

SNIP

Tony Wood : twitter.com/tonywood
Vision with Technology
Experts in eZ Publish consulting & development

Power to the Editor!

Free eZ Training : http://www.VisionWT.com/training
eZ Future Podcast : http://www.VisionWT.com/eZ-Future

Selmah Maxim

Monday 19 May 2003 2:37:18 am

peeb

Gabriel Ambuehl

Monday 19 May 2003 2:40:32 am

Selmah,
read http://ez.no/developer/ez_publish_3/bug_reports/urgent_security_risk_privilege_escalation_in_default_install

as to why the demo uses the IMHO braindead setup it does, I have no idea.

Visit http://triligon.org

Selmah Maxim

Monday 19 May 2003 2:41:03 am

beep

Tony Wood

Monday 19 May 2003 2:42:02 am

SNIP

Tony Wood : twitter.com/tonywood
Vision with Technology
Experts in eZ Publish consulting & development

Power to the Editor!

Free eZ Training : http://www.VisionWT.com/training
eZ Future Podcast : http://www.VisionWT.com/eZ-Future

Tony Wood

Monday 19 May 2003 2:45:48 am

SNIP

Tony Wood : twitter.com/tonywood
Vision with Technology
Experts in eZ Publish consulting & development

Power to the Editor!

Free eZ Training : http://www.VisionWT.com/training
eZ Future Podcast : http://www.VisionWT.com/eZ-Future

Selmah Maxim

Monday 19 May 2003 2:49:15 am

beep

Selmah Maxim

Monday 19 May 2003 2:53:18 am

beep

Selmah Maxim

Monday 19 May 2003 2:58:14 am

the bug that edit.php must check the user id in the session and the requested user id !

Tony Wood

Monday 19 May 2003 3:02:23 am

SNIP

Tony Wood : twitter.com/tonywood
Vision with Technology
Experts in eZ Publish consulting & development

Power to the Editor!

Free eZ Training : http://www.VisionWT.com/training
eZ Future Podcast : http://www.VisionWT.com/eZ-Future

Selmah Maxim

Monday 19 May 2003 3:04:08 am

yeah ...
how did ez team didn`t check this bug ... i think all ez sites is buged !

Tony Wood

Monday 19 May 2003 3:08:54 am

This is a problem i will not discuss further here as it have some issues.... Also can you remove reference to if from your messages as a fix needs to be provided ASAP for this...

Tony Wood : twitter.com/tonywood
Vision with Technology
Experts in eZ Publish consulting & development

Power to the Editor!

Free eZ Training : http://www.VisionWT.com/training
eZ Future Podcast : http://www.VisionWT.com/eZ-Future

Selmah Maxim

Monday 19 May 2003 3:09:34 am

opppsss ...

I think better if one of editors close, or delete this forum !

Tony Wood

Monday 19 May 2003 3:14:31 am

Selmah,

Please remove your references to the problem till a fix can be provided.

eZ, please remove this forum thread so versions are not available.

Tony

Tony Wood : twitter.com/tonywood
Vision with Technology
Experts in eZ Publish consulting & development

Power to the Editor!

Free eZ Training : http://www.VisionWT.com/training
eZ Future Podcast : http://www.VisionWT.com/eZ-Future

Selmah Maxim

Monday 19 May 2003 3:21:18 am

btw ..

i found something else, bigger bug, found while am testing on my localhost, this bug make ez32 admin interface open for guests !

Tony Wood

Monday 19 May 2003 3:22:31 am

email it to [email protected].

Do not place on the forum..

Tony Wood : twitter.com/tonywood
Vision with Technology
Experts in eZ Publish consulting & development

Power to the Editor!

Free eZ Training : http://www.VisionWT.com/training
eZ Future Podcast : http://www.VisionWT.com/eZ-Future

Tony Wood

Monday 19 May 2003 3:23:50 am

Good eye though Selmah, you should be on the eZ security advisory :)

Tony Wood : twitter.com/tonywood
Vision with Technology
Experts in eZ Publish consulting & development

Power to the Editor!

Free eZ Training : http://www.VisionWT.com/training
eZ Future Podcast : http://www.VisionWT.com/eZ-Future

Selmah Maxim

Monday 19 May 2003 3:27:55 am

thx :)

but is sad that ez have such bug :(