Snitz Forums 2000
Snitz Forums 2000
Home | Profile | Register | Active Topics | Members | Search | FAQ
Username:
Password:
Save Password
Forgot your Password?

 All Forums
 Snitz Forums 2000 DEV-Group
 DEV Bug Reports (Closed)
 New Security related bug-fix - pop_mail.asp
 Forum Locked  Topic Locked
 Printer Friendly
Author Previous Topic Topic Next Topic  

RichardKinser
Snitz Forums Admin

USA
16655 Posts

Posted - 17 August 2002 :  08:43:42  Show Profile
Please download this fixed copy and overwrite your current file:
(this should be compatible with v3.3.xx and v3.1sr4)

http://forum.snitz.com/download/pop_mail.zip

Hamlin
Advanced Member

United Kingdom
2386 Posts

Posted - 17 August 2002 :  09:08:45  Show Profile
It seems you no longer get the email boxes if you are not logged in, was this part of the fix?

I just get this text now

quote:

Send an EMAIL Message

Close Window



Where as before if I was not logged in I would get the chance to enter my infomation...
Go to Top of Page

theory
Starting Member

29 Posts

Posted - 17 August 2002 :  09:10:41  Show Profile
Does this apply to the Internationalized version?
Go to Top of Page

RichardKinser
Snitz Forums Admin

USA
16655 Posts

Posted - 17 August 2002 :  09:21:32  Show Profile
quote:
Originally posted by Hamlin

It seems you no longer get the email boxes if you are not logged in, was this part of the fix?

I just get this text now

quote:

Send an EMAIL Message

Close Window



Where as before if I was not logged in I would get the chance to enter my infomation...


No, not really. But it could. I've never unchecked the "Require Logon for sending Mail" in the e-mail options so I didn't test this fix with it. But, you should know that if you don't require logon for mail, the person can put in any username and any e-mail address they want, it is not checked against the database.
Go to Top of Page

RichardKinser
Snitz Forums Admin

USA
16655 Posts

Posted - 17 August 2002 :  09:22:40  Show Profile
quote:
Originally posted by theory

Does this apply to the Internationalized version?

No, Bozden will have to release a fix for the internationalized version, or someone else who is familiar with it. You can probably download the file and compare the changes with your file and just make the changes yourself.
Go to Top of Page

RichardKinser
Snitz Forums Admin

USA
16655 Posts

Posted - 17 August 2002 :  09:54:39  Show Profile
I had to add some missing text in the file, if you have already downloaded it, please redownload it again.
Go to Top of Page

Deleted
deleted

4116 Posts

Posted - 17 August 2002 :  11:43:26  Show Profile
quote:
Originally posted by theory

Does this apply to the Internationalized version?



I'm working on it now. I'll release patch005 ASAP.

Stop the WAR!
Go to Top of Page

mortioli
Average Member

United Kingdom
898 Posts

Posted - 17 August 2002 :  12:13:19  Show Profile  Visit mortioli's Homepage  Send mortioli an AOL message  Send mortioli a Yahoo! Message
Is it possible to provide the codes needed to be changed?

I think I've changed my pop_mail, so would be great if the changes could be pointed out.

Thanks!
Go to Top of Page

D3mon
Senior Member

United Kingdom
1685 Posts

Posted - 17 August 2002 :  12:41:05  Show Profile  Visit D3mon's Homepage
Just wondering if it would pose a security threat to publish just the affected lines? If so, I'll copy over my original and re-modify it.


Snitz 'Speedball' : Site Integration Mod : Friendly Registration Mod
"In war, the victorious strategist only seeks battle after the victory has been won"
Go to Top of Page

Deleted
deleted

4116 Posts

Posted - 17 August 2002 :  13:48:37  Show Profile
Fixed in v4b03patch005 (released now, download link here).

Stop the WAR!
Go to Top of Page

Anacrusis
Junior Member

USA
219 Posts

Posted - 17 August 2002 :  14:32:51  Show Profile  Visit Anacrusis's Homepage  Send Anacrusis an AOL message
What are the changes that have been made? I've modified my pop_mail.asp quite a bit and would not like to overwrite it.

The Internet ClubHouse
www.internet-clubhouse.com
Go to Top of Page

RichardKinser
Snitz Forums Admin

USA
16655 Posts

Posted - 17 August 2002 :  16:07:19  Show Profile
If you've changed your file, just download this one and compare the 2 and make the necessary changes to yours.
Go to Top of Page

mortioli
Average Member

United Kingdom
898 Posts

Posted - 17 August 2002 :  16:49:18  Show Profile  Visit mortioli's Homepage  Send mortioli an AOL message  Send mortioli a Yahoo! Message
I've tried to compare them, but theres to much which has changed between the two.
Go to Top of Page

RichardKinser
Snitz Forums Admin

USA
16655 Posts

Posted - 17 August 2002 :  16:56:55  Show Profile
the major parts to fix are:

on line #43:

replace this:

set rs = Server.CreateObject("ADODB.RecordSet")


with this:

if Request.QueryString("ID") <> "" and IsNumeric(Request.QueryString("ID")) = True then
intMemberID = cLng(Request.QueryString("ID"))
else
intMemberID = 0
end if



on line #53:

change this:

	rs = my_Conn.Execute (strSql)


to this:

	set rs = my_Conn.Execute (strSql)



then on line #51 & line #167:

replace this:

Request.QueryString("ID")


with this:

intMemberID
Go to Top of Page

mortioli
Average Member

United Kingdom
898 Posts

Posted - 20 August 2002 :  16:52:07  Show Profile  Visit mortioli's Homepage  Send mortioli an AOL message  Send mortioli a Yahoo! Message
Cheers
Go to Top of Page
  Previous Topic Topic Next Topic  
 Forum Locked  Topic Locked
 Printer Friendly
Jump To:
Snitz Forums 2000 © 2000-2021 Snitz™ Communications Go To Top Of Page
This page was generated in 0.19 seconds. Powered By: Snitz Forums 2000 Version 3.4.07