<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0">
	<channel>
		<title><![CDATA[PunBB Forums - Automatic Image Upload with Thumbnails]]></title>
		<link>http://punbb.informer.com/forums/topic/15285/automatic-image-upload-with-thumbnails/</link>
		<description><![CDATA[The most recent posts in Automatic Image Upload with Thumbnails.]]></description>
		<lastBuildDate>Sat, 28 Mar 2009 18:01:05 +0000</lastBuildDate>
		<generator>PunBB</generator>
		<item>
			<title><![CDATA[Re: Automatic Image Upload with Thumbnails]]></title>
			<link>http://punbb.informer.com/forums/post/126188/#p126188</link>
			<description><![CDATA[<p><strong>Automatic Image Upload with Thumbnails 1.3.6beta now available.</strong></p><p>Click <a href="http://www.punres.org/viewtopic.php?pid=25482#p25482">here</a> for more details.</p>]]></description>
			<author><![CDATA[dummy@example.com (Koos)]]></author>
			<pubDate>Sat, 28 Mar 2009 18:01:05 +0000</pubDate>
			<guid>http://punbb.informer.com/forums/post/126188/#p126188</guid>
		</item>
		<item>
			<title><![CDATA[Re: Automatic Image Upload with Thumbnails]]></title>
			<link>http://punbb.informer.com/forums/post/124691/#p124691</link>
			<description><![CDATA[<div class="quotebox"><cite>Koos wrote:</cite><blockquote><div class="quotebox"><cite>new morning wrote:</cite><blockquote><p>Well, I fixed that part of the pb : I had to CHMOD all files in the &#039;cache&#039; directory. Now I still can&#039;t use this mod : I get a blank screen.&nbsp; can someone have a look at what happens ? (<a href="http://www.francafrique.infos.st">www.francafrique.infos.st</a>) / <a href="http://www.francafrique.infos.st/uploadimg.php">http://www.francafrique.infos.st/uploadimg.php</a></p></blockquote></div><p>Are you using the latest version of this mod (v1.3.3)? Also make sure that your&nbsp; php version is not outdated, and that gd has been configured properly.</p></blockquote></div><p>I am suffering this problem too. <br />Applied chmods already. <br />Can anyone give me tips ? <a href="http://ostudiolabs.com/forum/upload/uploadimg.php">http://ostudiolabs.com/forum/upload/uploadimg.php</a></p><p>edit- I have fixed it. I just deleted the files&nbsp; and re unzipped them into the forum directory. thx!</p>]]></description>
			<author><![CDATA[dummy@example.com (dapxin)]]></author>
			<pubDate>Sun, 15 Feb 2009 22:43:45 +0000</pubDate>
			<guid>http://punbb.informer.com/forums/post/124691/#p124691</guid>
		</item>
		<item>
			<title><![CDATA[Re: Automatic Image Upload with Thumbnails]]></title>
			<link>http://punbb.informer.com/forums/post/124502/#p124502</link>
			<description><![CDATA[<div class="quotebox"><cite>proweb wrote:</cite><blockquote><p>T</p><p>Note:&nbsp; it is not for 1.3</p></blockquote></div><br /><p>ooosh.</p>]]></description>
			<author><![CDATA[dummy@example.com (dapxin)]]></author>
			<pubDate>Thu, 12 Feb 2009 18:50:32 +0000</pubDate>
			<guid>http://punbb.informer.com/forums/post/124502/#p124502</guid>
		</item>
		<item>
			<title><![CDATA[Re: Automatic Image Upload with Thumbnails]]></title>
			<link>http://punbb.informer.com/forums/post/124501/#p124501</link>
			<description><![CDATA[<p>This is by far my favorite mod for punBB.&nbsp; Koos did a beautiful job writing it and it works perfectly for all my 1.2 installations without a single problem.</p><p>Note:&nbsp; it is not for 1.3</p>]]></description>
			<author><![CDATA[dummy@example.com (proweb)]]></author>
			<pubDate>Thu, 12 Feb 2009 18:39:44 +0000</pubDate>
			<guid>http://punbb.informer.com/forums/post/124501/#p124501</guid>
		</item>
		<item>
			<title><![CDATA[Re: Automatic Image Upload with Thumbnails]]></title>
			<link>http://punbb.informer.com/forums/post/124499/#p124499</link>
			<description><![CDATA[<p>Hi guys, </p><p>Does anyone know if this is still safe to use ?</p><p>I am trying to set it up on my forum, but having issues.</p>]]></description>
			<author><![CDATA[dummy@example.com (dapxin)]]></author>
			<pubDate>Thu, 12 Feb 2009 17:45:50 +0000</pubDate>
			<guid>http://punbb.informer.com/forums/post/124499/#p124499</guid>
		</item>
		<item>
			<title><![CDATA[Re: Automatic Image Upload with Thumbnails]]></title>
			<link>http://punbb.informer.com/forums/post/115485/#p115485</link>
			<description><![CDATA[<p><strong><span style="color: red">IMPORTANT UPDATE - V1.3.5 RELEASED</span></strong></p><p>Thanks for the feedback. Peter Österberg contacted me last year about this vulnerability which was found in v1.3.2 and confirmed in v1.3.3. I attempted to fix it in v1.3.4, but there are some things I missed.&nbsp; This is indeed a very serious vulnerability - and I have now released v1.3.5. Everyone should update to this version. <a href="http://www.punres.org/files.php?pid=362">Download from punres.org</a></p><p>I have also created the file <strong>uploadimg_check.php</strong> which will check for potentially harmful files that were uploaded with previous versions and give you the option to delete them. Click <a href="http://koos.50webs.com/uploads/uploadimg_check.zip">here</a> to download it. Note that you must be logged in as Admin to use it.</p>]]></description>
			<author><![CDATA[dummy@example.com (Koos)]]></author>
			<pubDate>Sun, 15 Jun 2008 19:42:37 +0000</pubDate>
			<guid>http://punbb.informer.com/forums/post/115485/#p115485</guid>
		</item>
		<item>
			<title><![CDATA[Re: Automatic Image Upload with Thumbnails]]></title>
			<link>http://punbb.informer.com/forums/post/115442/#p115442</link>
			<description><![CDATA[<p><strong>Vulnerability in the Automatic Image Upload with Thumbnails v. 1.3.4</strong></p><div class="quotebox"><blockquote><p><strong>Description:</strong><br />Peter Österberg has discovered a vulnerability in the Automatic Image Upload with Thumbnails module for PunBB, which can be exploited by malicious users to conduct cross-site scripting attacks and to compromise a vulnerable system.</p><p>The uploadimg.php script fails to validate the extension of an uploaded file. This can be exploited to upload files with &quot;.html&quot; or &quot;.php&quot; extensions by passing an allowed MIME media type in the HTTP headers.</p><p>Successful exploitation allows to conduct cross-site scripting attacks or to execute arbitrary PHP code on the server, but requires valid user credentials in a group that is allowed to upload files.</p></blockquote></div><p><a href="http://secunia.com/advisories/28138">http://secunia.com/advisories/28138</a></p><p>solution:<br />open <strong>uploadimg.php</strong> and find line (~193):<br /></p><div class="codebox"><pre><code>// Determine whether file is correct filetype-
if (!((($_FILES[&#039;imagefile&#039;][&#039;type&#039;] == &quot;image/jpg&quot; || $_FILES[&#039;imagefile&#039;][&#039;type&#039;] == &quot;image/jpeg&quot; || $_FILES[&#039;imagefile&#039;][&#039;type&#039;] == &quot;image/pjpeg&quot;) &amp;&amp; ($allow_jpg_uploads == &quot;1&quot;)) || (($_FILES[&#039;imagefile&#039;][&#039;type&#039;] == &quot;image/png&quot; || $_FILES[&#039;imagefile&#039;][&#039;type&#039;] == &quot;image/x-png&quot;) &amp;&amp; ($allow_png_uploads == &quot;1&quot;)) || (($_FILES[&#039;imagefile&#039;][&#039;type&#039;] == &quot;image/gif&quot;) &amp;&amp; ($allow_gif_uploads == &quot;1&quot;))))</code></pre></div><p>replace with (added extension checking):<br /></p><div class="codebox"><pre><code>if (!((($_FILES[&#039;imagefile&#039;][&#039;type&#039;] == &quot;image/jpg&quot; || $_FILES[&#039;imagefile&#039;][&#039;type&#039;] == &quot;image/jpeg&quot; || $_FILES[&#039;imagefile&#039;][&#039;type&#039;] == &quot;image/pjpeg&quot;) &amp;&amp; ($imagefilename_ext == &#039;jpg&#039; || $imagefilename_ext == &#039;jpeg&#039;) &amp;&amp; ($allow_jpg_uploads == &quot;1&quot;)) || (($_FILES[&#039;imagefile&#039;][&#039;type&#039;] == &quot;image/png&quot; || $_FILES[&#039;imagefile&#039;][&#039;type&#039;] == &quot;image/x-png&quot;) &amp;&amp; ($imagefilename_ext == &#039;png&#039;) &amp;&amp; ($allow_png_uploads == &quot;1&quot;)) || (($_FILES[&#039;imagefile&#039;][&#039;type&#039;] == &quot;image/gif&quot;) &amp;&amp; ($imagefilename_ext == &#039;gif&#039;) &amp;&amp; ($allow_gif_uploads == &quot;1&quot;))))</code></pre></div><p>be careful! <img src="http://punbb.informer.com/forums/img/smilies/wink.png" width="15" height="15" alt="wink" /></p>]]></description>
			<author><![CDATA[dummy@example.com (lokeez)]]></author>
			<pubDate>Sat, 14 Jun 2008 14:04:07 +0000</pubDate>
			<guid>http://punbb.informer.com/forums/post/115442/#p115442</guid>
		</item>
		<item>
			<title><![CDATA[Re: Automatic Image Upload with Thumbnails]]></title>
			<link>http://punbb.informer.com/forums/post/106814/#p106814</link>
			<description><![CDATA[<p>PunRes</p>]]></description>
			<author><![CDATA[dummy@example.com (yemgi)]]></author>
			<pubDate>Fri, 11 Jan 2008 22:09:40 +0000</pubDate>
			<guid>http://punbb.informer.com/forums/post/106814/#p106814</guid>
		</item>
		<item>
			<title><![CDATA[Re: Automatic Image Upload with Thumbnails]]></title>
			<link>http://punbb.informer.com/forums/post/106813/#p106813</link>
			<description><![CDATA[<div class="quotebox"><cite>Koos wrote:</cite><blockquote><p>Automatic Image Upload with Thumbnails 1.3.4 now available. ...</p></blockquote></div><p>Where?</p>]]></description>
			<author><![CDATA[dummy@example.com (Peter)]]></author>
			<pubDate>Fri, 11 Jan 2008 21:47:49 +0000</pubDate>
			<guid>http://punbb.informer.com/forums/post/106813/#p106813</guid>
		</item>
		<item>
			<title><![CDATA[Re: Automatic Image Upload with Thumbnails]]></title>
			<link>http://punbb.informer.com/forums/post/106805/#p106805</link>
			<description><![CDATA[<p>Automatic Image Upload with Thumbnails 1.3.4 now available. I would advice everyone to update - since this release includes an important vulnerability fix. Here are some of the changes made in this version:</p><p>* Rewrote the &quot;uploadimg.php&quot; page<br />* Fixed a vulnerability<br />* All pages now valid XHTML 1.0 Strict<br />* Stats totals now also include thumb size</p>]]></description>
			<author><![CDATA[dummy@example.com (Koos)]]></author>
			<pubDate>Fri, 11 Jan 2008 21:16:13 +0000</pubDate>
			<guid>http://punbb.informer.com/forums/post/106805/#p106805</guid>
		</item>
		<item>
			<title><![CDATA[Re: Automatic Image Upload with Thumbnails]]></title>
			<link>http://punbb.informer.com/forums/post/104299/#p104299</link>
			<description><![CDATA[<p>That looks fine. <img src="http://punbb.informer.com/forums/img/smilies/smile.png" width="15" height="15" alt="smile" /></p>]]></description>
			<author><![CDATA[dummy@example.com (MattF)]]></author>
			<pubDate>Sun, 25 Nov 2007 16:10:13 +0000</pubDate>
			<guid>http://punbb.informer.com/forums/post/104299/#p104299</guid>
		</item>
		<item>
			<title><![CDATA[Re: Automatic Image Upload with Thumbnails]]></title>
			<link>http://punbb.informer.com/forums/post/104290/#p104290</link>
			<description><![CDATA[<p>I was under PHP 4 and asked to upgrade to PHP 5... I hoppe this will solve the problem.</p><br /><p>By the way, is this GD correctly configured ?</p><div class="quotebox"><blockquote><p>gd :<br />GD Support &nbsp; &nbsp; enabled<br />GD Version &nbsp; &nbsp; 2.0 or higher<br />FreeType Support &nbsp; &nbsp; enabled<br />FreeType Linkage &nbsp; &nbsp; with freetype<br />T1Lib Support &nbsp; &nbsp; enabled<br />GIF Read Support &nbsp; &nbsp; enabled<br />GIF Create Support &nbsp; &nbsp; enabled<br />JPG Support &nbsp; &nbsp; enabled<br />PNG Support &nbsp; &nbsp; enabled<br />WBMP Support &nbsp; &nbsp; enabled</p></blockquote></div>]]></description>
			<author><![CDATA[dummy@example.com (new morning)]]></author>
			<pubDate>Sun, 25 Nov 2007 11:57:05 +0000</pubDate>
			<guid>http://punbb.informer.com/forums/post/104290/#p104290</guid>
		</item>
		<item>
			<title><![CDATA[Re: Automatic Image Upload with Thumbnails]]></title>
			<link>http://punbb.informer.com/forums/post/104268/#p104268</link>
			<description><![CDATA[<div class="quotebox"><cite>new morning wrote:</cite><blockquote><p>phpMyAdmin 2.7.0-pl1</p></blockquote></div><p>PHP, not the PHP admin programme.</p><br /><div class="quotebox"><cite>new morning wrote:</cite><blockquote><p>What is GD ?</p></blockquote></div><p>Graphics library.</p>]]></description>
			<author><![CDATA[dummy@example.com (MattF)]]></author>
			<pubDate>Sat, 24 Nov 2007 18:50:00 +0000</pubDate>
			<guid>http://punbb.informer.com/forums/post/104268/#p104268</guid>
		</item>
		<item>
			<title><![CDATA[Re: Automatic Image Upload with Thumbnails]]></title>
			<link>http://punbb.informer.com/forums/post/104260/#p104260</link>
			<description><![CDATA[<div class="quotebox"><cite>Koos wrote:</cite><blockquote><p>Are you using the latest version of this mod (v1.3.3)?</p></blockquote></div><p>Yes</p><p>-&nbsp; Also make sure that your&nbsp; php version is not outdated<br />phpMyAdmin 2.7.0-pl1</p><br /><p>- and that gd has been configured properly.</p><p>What is GD ?</p>]]></description>
			<author><![CDATA[dummy@example.com (new morning)]]></author>
			<pubDate>Sat, 24 Nov 2007 15:57:30 +0000</pubDate>
			<guid>http://punbb.informer.com/forums/post/104260/#p104260</guid>
		</item>
		<item>
			<title><![CDATA[Re: Automatic Image Upload with Thumbnails]]></title>
			<link>http://punbb.informer.com/forums/post/104250/#p104250</link>
			<description><![CDATA[<div class="quotebox"><cite>new morning wrote:</cite><blockquote><p>Well, I fixed that part of the pb : I had to CHMOD all files in the &#039;cache&#039; directory. Now I still can&#039;t use this mod : I get a blank screen.&nbsp; can someone have a look at what happens ? (<a href="http://www.francafrique.infos.st">www.francafrique.infos.st</a>) / <a href="http://www.francafrique.infos.st/uploadimg.php">http://www.francafrique.infos.st/uploadimg.php</a></p></blockquote></div><p>Are you using the latest version of this mod (v1.3.3)? Also make sure that your&nbsp; php version is not outdated, and that gd has been configured properly.</p>]]></description>
			<author><![CDATA[dummy@example.com (Koos)]]></author>
			<pubDate>Sat, 24 Nov 2007 08:49:51 +0000</pubDate>
			<guid>http://punbb.informer.com/forums/post/104250/#p104250</guid>
		</item>
	</channel>
</rss>
