<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
	<title type="html"><![CDATA[PunBB Forums - Automatic Image Upload with Thumbnails]]></title>
	<link rel="self" href="http://punbb.informer.com/forums/feed/atom/topic/15285/"/>
	<updated>2009-03-28T18:01:05Z</updated>
	<generator>PunBB</generator>
	<id>http://punbb.informer.com/forums/topic/15285/automatic-image-upload-with-thumbnails/</id>
		<entry>
			<title type="html"><![CDATA[Re: Automatic Image Upload with Thumbnails]]></title>
			<link rel="alternate" href="http://punbb.informer.com/forums/post/126188/#p126188"/>
			<content type="html"><![CDATA[<p><strong>Automatic Image Upload with Thumbnails 1.3.6beta now available.</strong></p><p>Click <a href="http://www.punres.org/viewtopic.php?pid=25482#p25482">here</a> for more details.</p>]]></content>
			<author>
				<name><![CDATA[Koos]]></name>
				<uri>http://punbb.informer.com/forums/user/9972/</uri>
			</author>
			<updated>2009-03-28T18:01:05Z</updated>
			<id>http://punbb.informer.com/forums/post/126188/#p126188</id>
		</entry>
		<entry>
			<title type="html"><![CDATA[Re: Automatic Image Upload with Thumbnails]]></title>
			<link rel="alternate" href="http://punbb.informer.com/forums/post/124691/#p124691"/>
			<content type="html"><![CDATA[<div class="quotebox"><cite>Koos wrote:</cite><blockquote><div class="quotebox"><cite>new morning wrote:</cite><blockquote><p>Well, I fixed that part of the pb : I had to CHMOD all files in the &#039;cache&#039; directory. Now I still can&#039;t use this mod : I get a blank screen.&nbsp; can someone have a look at what happens ? (<a href="http://www.francafrique.infos.st">www.francafrique.infos.st</a>) / <a href="http://www.francafrique.infos.st/uploadimg.php">http://www.francafrique.infos.st/uploadimg.php</a></p></blockquote></div><p>Are you using the latest version of this mod (v1.3.3)? Also make sure that your&nbsp; php version is not outdated, and that gd has been configured properly.</p></blockquote></div><p>I am suffering this problem too. <br />Applied chmods already. <br />Can anyone give me tips ? <a href="http://ostudiolabs.com/forum/upload/uploadimg.php">http://ostudiolabs.com/forum/upload/uploadimg.php</a></p><p>edit- I have fixed it. I just deleted the files&nbsp; and re unzipped them into the forum directory. thx!</p>]]></content>
			<author>
				<name><![CDATA[dapxin]]></name>
				<uri>http://punbb.informer.com/forums/user/14865/</uri>
			</author>
			<updated>2009-02-15T22:43:45Z</updated>
			<id>http://punbb.informer.com/forums/post/124691/#p124691</id>
		</entry>
		<entry>
			<title type="html"><![CDATA[Re: Automatic Image Upload with Thumbnails]]></title>
			<link rel="alternate" href="http://punbb.informer.com/forums/post/124502/#p124502"/>
			<content type="html"><![CDATA[<div class="quotebox"><cite>proweb wrote:</cite><blockquote><p>T</p><p>Note:&nbsp; it is not for 1.3</p></blockquote></div><br /><p>ooosh.</p>]]></content>
			<author>
				<name><![CDATA[dapxin]]></name>
				<uri>http://punbb.informer.com/forums/user/14865/</uri>
			</author>
			<updated>2009-02-12T18:50:32Z</updated>
			<id>http://punbb.informer.com/forums/post/124502/#p124502</id>
		</entry>
		<entry>
			<title type="html"><![CDATA[Re: Automatic Image Upload with Thumbnails]]></title>
			<link rel="alternate" href="http://punbb.informer.com/forums/post/124501/#p124501"/>
			<content type="html"><![CDATA[<p>This is by far my favorite mod for punBB.&nbsp; Koos did a beautiful job writing it and it works perfectly for all my 1.2 installations without a single problem.</p><p>Note:&nbsp; it is not for 1.3</p>]]></content>
			<author>
				<name><![CDATA[proweb]]></name>
				<uri>http://punbb.informer.com/forums/user/12309/</uri>
			</author>
			<updated>2009-02-12T18:39:44Z</updated>
			<id>http://punbb.informer.com/forums/post/124501/#p124501</id>
		</entry>
		<entry>
			<title type="html"><![CDATA[Re: Automatic Image Upload with Thumbnails]]></title>
			<link rel="alternate" href="http://punbb.informer.com/forums/post/124499/#p124499"/>
			<content type="html"><![CDATA[<p>Hi guys, </p><p>Does anyone know if this is still safe to use ?</p><p>I am trying to set it up on my forum, but having issues.</p>]]></content>
			<author>
				<name><![CDATA[dapxin]]></name>
				<uri>http://punbb.informer.com/forums/user/14865/</uri>
			</author>
			<updated>2009-02-12T17:45:50Z</updated>
			<id>http://punbb.informer.com/forums/post/124499/#p124499</id>
		</entry>
		<entry>
			<title type="html"><![CDATA[Re: Automatic Image Upload with Thumbnails]]></title>
			<link rel="alternate" href="http://punbb.informer.com/forums/post/115485/#p115485"/>
			<content type="html"><![CDATA[<p><strong><span style="color: red">IMPORTANT UPDATE - V1.3.5 RELEASED</span></strong></p><p>Thanks for the feedback. Peter Österberg contacted me last year about this vulnerability which was found in v1.3.2 and confirmed in v1.3.3. I attempted to fix it in v1.3.4, but there are some things I missed.&nbsp; This is indeed a very serious vulnerability - and I have now released v1.3.5. Everyone should update to this version. <a href="http://www.punres.org/files.php?pid=362">Download from punres.org</a></p><p>I have also created the file <strong>uploadimg_check.php</strong> which will check for potentially harmful files that were uploaded with previous versions and give you the option to delete them. Click <a href="http://koos.50webs.com/uploads/uploadimg_check.zip">here</a> to download it. Note that you must be logged in as Admin to use it.</p>]]></content>
			<author>
				<name><![CDATA[Koos]]></name>
				<uri>http://punbb.informer.com/forums/user/9972/</uri>
			</author>
			<updated>2008-06-15T19:42:37Z</updated>
			<id>http://punbb.informer.com/forums/post/115485/#p115485</id>
		</entry>
		<entry>
			<title type="html"><![CDATA[Re: Automatic Image Upload with Thumbnails]]></title>
			<link rel="alternate" href="http://punbb.informer.com/forums/post/115442/#p115442"/>
			<content type="html"><![CDATA[<p><strong>Vulnerability in the Automatic Image Upload with Thumbnails v. 1.3.4</strong></p><div class="quotebox"><blockquote><p><strong>Description:</strong><br />Peter Österberg has discovered a vulnerability in the Automatic Image Upload with Thumbnails module for PunBB, which can be exploited by malicious users to conduct cross-site scripting attacks and to compromise a vulnerable system.</p><p>The uploadimg.php script fails to validate the extension of an uploaded file. This can be exploited to upload files with &quot;.html&quot; or &quot;.php&quot; extensions by passing an allowed MIME media type in the HTTP headers.</p><p>Successful exploitation allows to conduct cross-site scripting attacks or to execute arbitrary PHP code on the server, but requires valid user credentials in a group that is allowed to upload files.</p></blockquote></div><p><a href="http://secunia.com/advisories/28138">http://secunia.com/advisories/28138</a></p><p>solution:<br />open <strong>uploadimg.php</strong> and find line (~193):<br /></p><div class="codebox"><pre><code>// Determine whether file is correct filetype-
if (!((($_FILES[&#039;imagefile&#039;][&#039;type&#039;] == &quot;image/jpg&quot; || $_FILES[&#039;imagefile&#039;][&#039;type&#039;] == &quot;image/jpeg&quot; || $_FILES[&#039;imagefile&#039;][&#039;type&#039;] == &quot;image/pjpeg&quot;) &amp;&amp; ($allow_jpg_uploads == &quot;1&quot;)) || (($_FILES[&#039;imagefile&#039;][&#039;type&#039;] == &quot;image/png&quot; || $_FILES[&#039;imagefile&#039;][&#039;type&#039;] == &quot;image/x-png&quot;) &amp;&amp; ($allow_png_uploads == &quot;1&quot;)) || (($_FILES[&#039;imagefile&#039;][&#039;type&#039;] == &quot;image/gif&quot;) &amp;&amp; ($allow_gif_uploads == &quot;1&quot;))))</code></pre></div><p>replace with (added extension checking):<br /></p><div class="codebox"><pre><code>if (!((($_FILES[&#039;imagefile&#039;][&#039;type&#039;] == &quot;image/jpg&quot; || $_FILES[&#039;imagefile&#039;][&#039;type&#039;] == &quot;image/jpeg&quot; || $_FILES[&#039;imagefile&#039;][&#039;type&#039;] == &quot;image/pjpeg&quot;) &amp;&amp; ($imagefilename_ext == &#039;jpg&#039; || $imagefilename_ext == &#039;jpeg&#039;) &amp;&amp; ($allow_jpg_uploads == &quot;1&quot;)) || (($_FILES[&#039;imagefile&#039;][&#039;type&#039;] == &quot;image/png&quot; || $_FILES[&#039;imagefile&#039;][&#039;type&#039;] == &quot;image/x-png&quot;) &amp;&amp; ($imagefilename_ext == &#039;png&#039;) &amp;&amp; ($allow_png_uploads == &quot;1&quot;)) || (($_FILES[&#039;imagefile&#039;][&#039;type&#039;] == &quot;image/gif&quot;) &amp;&amp; ($imagefilename_ext == &#039;gif&#039;) &amp;&amp; ($allow_gif_uploads == &quot;1&quot;))))</code></pre></div><p>be careful! <img src="http://punbb.informer.com/forums/img/smilies/wink.png" width="15" height="15" alt="wink" /></p>]]></content>
			<author>
				<name><![CDATA[lokeez]]></name>
				<uri>http://punbb.informer.com/forums/user/13277/</uri>
			</author>
			<updated>2008-06-14T14:04:07Z</updated>
			<id>http://punbb.informer.com/forums/post/115442/#p115442</id>
		</entry>
		<entry>
			<title type="html"><![CDATA[Re: Automatic Image Upload with Thumbnails]]></title>
			<link rel="alternate" href="http://punbb.informer.com/forums/post/106814/#p106814"/>
			<content type="html"><![CDATA[<p>PunRes</p>]]></content>
			<author>
				<name><![CDATA[yemgi]]></name>
				<uri>http://punbb.informer.com/forums/user/10135/</uri>
			</author>
			<updated>2008-01-11T22:09:40Z</updated>
			<id>http://punbb.informer.com/forums/post/106814/#p106814</id>
		</entry>
		<entry>
			<title type="html"><![CDATA[Re: Automatic Image Upload with Thumbnails]]></title>
			<link rel="alternate" href="http://punbb.informer.com/forums/post/106813/#p106813"/>
			<content type="html"><![CDATA[<div class="quotebox"><cite>Koos wrote:</cite><blockquote><p>Automatic Image Upload with Thumbnails 1.3.4 now available. ...</p></blockquote></div><p>Where?</p>]]></content>
			<author>
				<name><![CDATA[Peter]]></name>
				<uri>http://punbb.informer.com/forums/user/6086/</uri>
			</author>
			<updated>2008-01-11T21:47:49Z</updated>
			<id>http://punbb.informer.com/forums/post/106813/#p106813</id>
		</entry>
		<entry>
			<title type="html"><![CDATA[Re: Automatic Image Upload with Thumbnails]]></title>
			<link rel="alternate" href="http://punbb.informer.com/forums/post/106805/#p106805"/>
			<content type="html"><![CDATA[<p>Automatic Image Upload with Thumbnails 1.3.4 now available. I would advice everyone to update - since this release includes an important vulnerability fix. Here are some of the changes made in this version:</p><p>* Rewrote the &quot;uploadimg.php&quot; page<br />* Fixed a vulnerability<br />* All pages now valid XHTML 1.0 Strict<br />* Stats totals now also include thumb size</p>]]></content>
			<author>
				<name><![CDATA[Koos]]></name>
				<uri>http://punbb.informer.com/forums/user/9972/</uri>
			</author>
			<updated>2008-01-11T21:16:13Z</updated>
			<id>http://punbb.informer.com/forums/post/106805/#p106805</id>
		</entry>
		<entry>
			<title type="html"><![CDATA[Re: Automatic Image Upload with Thumbnails]]></title>
			<link rel="alternate" href="http://punbb.informer.com/forums/post/104299/#p104299"/>
			<content type="html"><![CDATA[<p>That looks fine. <img src="http://punbb.informer.com/forums/img/smilies/smile.png" width="15" height="15" alt="smile" /></p>]]></content>
			<author>
				<name><![CDATA[MattF]]></name>
				<uri>http://punbb.informer.com/forums/user/9938/</uri>
			</author>
			<updated>2007-11-25T16:10:13Z</updated>
			<id>http://punbb.informer.com/forums/post/104299/#p104299</id>
		</entry>
		<entry>
			<title type="html"><![CDATA[Re: Automatic Image Upload with Thumbnails]]></title>
			<link rel="alternate" href="http://punbb.informer.com/forums/post/104290/#p104290"/>
			<content type="html"><![CDATA[<p>I was under PHP 4 and asked to upgrade to PHP 5... I hoppe this will solve the problem.</p><br /><p>By the way, is this GD correctly configured ?</p><div class="quotebox"><blockquote><p>gd :<br />GD Support &nbsp; &nbsp; enabled<br />GD Version &nbsp; &nbsp; 2.0 or higher<br />FreeType Support &nbsp; &nbsp; enabled<br />FreeType Linkage &nbsp; &nbsp; with freetype<br />T1Lib Support &nbsp; &nbsp; enabled<br />GIF Read Support &nbsp; &nbsp; enabled<br />GIF Create Support &nbsp; &nbsp; enabled<br />JPG Support &nbsp; &nbsp; enabled<br />PNG Support &nbsp; &nbsp; enabled<br />WBMP Support &nbsp; &nbsp; enabled</p></blockquote></div>]]></content>
			<author>
				<name><![CDATA[new morning]]></name>
				<uri>http://punbb.informer.com/forums/user/11905/</uri>
			</author>
			<updated>2007-11-25T11:57:05Z</updated>
			<id>http://punbb.informer.com/forums/post/104290/#p104290</id>
		</entry>
		<entry>
			<title type="html"><![CDATA[Re: Automatic Image Upload with Thumbnails]]></title>
			<link rel="alternate" href="http://punbb.informer.com/forums/post/104268/#p104268"/>
			<content type="html"><![CDATA[<div class="quotebox"><cite>new morning wrote:</cite><blockquote><p>phpMyAdmin 2.7.0-pl1</p></blockquote></div><p>PHP, not the PHP admin programme.</p><br /><div class="quotebox"><cite>new morning wrote:</cite><blockquote><p>What is GD ?</p></blockquote></div><p>Graphics library.</p>]]></content>
			<author>
				<name><![CDATA[MattF]]></name>
				<uri>http://punbb.informer.com/forums/user/9938/</uri>
			</author>
			<updated>2007-11-24T18:50:00Z</updated>
			<id>http://punbb.informer.com/forums/post/104268/#p104268</id>
		</entry>
		<entry>
			<title type="html"><![CDATA[Re: Automatic Image Upload with Thumbnails]]></title>
			<link rel="alternate" href="http://punbb.informer.com/forums/post/104260/#p104260"/>
			<content type="html"><![CDATA[<div class="quotebox"><cite>Koos wrote:</cite><blockquote><p>Are you using the latest version of this mod (v1.3.3)?</p></blockquote></div><p>Yes</p><p>-&nbsp; Also make sure that your&nbsp; php version is not outdated<br />phpMyAdmin 2.7.0-pl1</p><br /><p>- and that gd has been configured properly.</p><p>What is GD ?</p>]]></content>
			<author>
				<name><![CDATA[new morning]]></name>
				<uri>http://punbb.informer.com/forums/user/11905/</uri>
			</author>
			<updated>2007-11-24T15:57:30Z</updated>
			<id>http://punbb.informer.com/forums/post/104260/#p104260</id>
		</entry>
		<entry>
			<title type="html"><![CDATA[Re: Automatic Image Upload with Thumbnails]]></title>
			<link rel="alternate" href="http://punbb.informer.com/forums/post/104250/#p104250"/>
			<content type="html"><![CDATA[<div class="quotebox"><cite>new morning wrote:</cite><blockquote><p>Well, I fixed that part of the pb : I had to CHMOD all files in the &#039;cache&#039; directory. Now I still can&#039;t use this mod : I get a blank screen.&nbsp; can someone have a look at what happens ? (<a href="http://www.francafrique.infos.st">www.francafrique.infos.st</a>) / <a href="http://www.francafrique.infos.st/uploadimg.php">http://www.francafrique.infos.st/uploadimg.php</a></p></blockquote></div><p>Are you using the latest version of this mod (v1.3.3)? Also make sure that your&nbsp; php version is not outdated, and that gd has been configured properly.</p>]]></content>
			<author>
				<name><![CDATA[Koos]]></name>
				<uri>http://punbb.informer.com/forums/user/9972/</uri>
			</author>
			<updated>2007-11-24T08:49:51Z</updated>
			<id>http://punbb.informer.com/forums/post/104250/#p104250</id>
		</entry>
</feed>
