Re: Missing access checks in CreatePage and AppendText plugins
"Marc-Etienne Vargenau \(Nokia\) via Phpwiki-talk" <[email protected]> Thu, 4 Sep 2025 07:52:06 +0000
| Newsgroups | gmane.comp.web.wiki.phpwiki.talk |
|---|---|
| Message-ID | <DU2SPRMB0035B59B8C99D3BFE1284F3FAC00A@DU2SPRMB0035.eurprd07.prod.outlook.com> |
--===============1973130827094373436== Content-Language: fr-FR Content-Type: multipart/alternative; boundary="_000_DU2SPRMB0035B59B8C99D3BFE1284F3FAC00ADU2SPRMB0035eurprd_" --_000_DU2SPRMB0035B59B8C99D3BFE1284F3FAC00ADU2SPRMB0035eurprd_ Content-Type: text/plain; charset="iso-8859-1" Content-Transfer-Encoding: quoted-printable Hi Harold, The latest version of PhpWiki is 1.6.6. You can see the version you are running by displaying the SystemInfo page: http://phpwiki.demo.free.fr/index.php/SystemInfo In the source code, the version can be found in files Makefile, lib/prepend= .php and all pgsrc files. The patches from Christof Meerwald (see below) are not yet in version 1.6.6= , I will publish a new version with them. Best regards, Marc-Etienne -- Marc-Etienne Vargenau [email protected]<mailto:marc-etienne.v= [email protected]> Nokia, 12, rue Jean-Bart, 91300 Massy, FRANCE Mobile: +33 6 24 49 78 68<tel:+33624497868> Senior Specialist Open Source Planned absence: none De : Harold Hallikainen <[email protected]> Date : mercredi, 3 septembre 2025 =E0 19:55 =C0 : Discussion on PhpWiki features, bugs, development. <phpwiki-talk@list= s.sourceforge.net> Objet : Re: [Phpwiki-talk] Missing access checks in CreatePage and AppendTe= xt plugins CAUTION: This is an external email. Please be very careful when clicking li= nks or opening attachments. See the URL nok.it/ext for additional informati= on. I've had this update on my list of things to do, but had not yet gotten to it. This morning, there were a bunch of new blank pages on one of my wikis. So, I deleted them and did the update. Is there an easy way to tell what version I have installed to make sure I did it correctly? The wiki is running, but I'd like to make sure it is running the latest code. Also, one of the newly created pages has a title that is blank, and I cannot delete it through the admin interface. Is there a way to delete it? THANKS! Harold On Wed, July 30, 2025 12:59 am, Marc-Etienne Vargenau \(Nokia\) via Phpwiki-talk wrote: > Hi Christof, > > > Thank you for your patches. > I have published them in Subversion. > > > Best regards, > > > Marc-Etienne > > > -- > Marc-Etienne Vargenau > [email protected]<mailto:[email protected]> > Nokia, 12, rue Jean-Bart, 91300 Massy, FRANCE > Mobile: +33 6 24 49 78 68<tel:+33624497868> > Senior Specialist Open Source > Planned absence: 4-22 August > > > De : Christof Meerwald via Phpwiki-talk > <[email protected]> > Date : mardi, 29 juillet 2025 =E0 23:24 > =C0 : Phpwiki-talk <[email protected]> > Cc : Christof Meerwald <[email protected]> > Objet : Re: [Phpwiki-talk] Missing access checks in CreatePage and > AppendText plugins > > > CAUTION: This is an external email. Please be very careful when clicking > links or opening attachments. See the URL nok.it/ext for additional > information. > > > > On Tue, Jul 29, 2025 at 11:04:24PM +0200, Christof Meerwald wrote: > >> Noticed that the CreatePage and AppendText plugins let unauthenticated >> users create pages or let them append text to pages, e.g. > > Actually, WikiAdminDeleteAcl is also missing an access check, patch > attached. > > > Christof > > > -- > https://eur03.safelinks.protection.outlook.com/?url=3Dhttps%3A%2F%2Fcmeer= w.o%2F&data=3D05%7C02%7Cmarc-etienne.vargenau%40nokia.com%7C3f24d955fb20401= 444b408ddeb1316e7%7C5d4717519675428d917b70f44f9630b0%7C0%7C0%7C638925189423= 530808%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIs= IlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&sdata=3DOiyIJ= xyrNr9KpLerPD282%2FaY5pxuOv4YK2Btjw8baCQ%3D&reserved=3D0<https://cmeerw.o/> > rg%2F&data=3D05%7C02%7Cmarc-etienne.vargenau%40nokia.com%7C4e796218c09f47= fe > 61f408ddcee6362f%7C5d4717519675428d917b70f44f9630b0%7C0%7C0%7C63889421050 > 8983458%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwM > CIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&sdata=3D= w% > 2B9pGigz7tN%2BhTJYA2nrg%2FgQ34nH6B59h0smjnzcheg%3D&reserved=3D0<https://c= me > erw.org/> sip:cmeerw at cmeerw.org > mailto:cmeerw at cmeerw.org xmpp:cmeerw at cmeerw.org > _______________________________________________ > Phpwiki-talk mailing list > [email protected] > https://eur03.safelinks.protection.outlook.com/?url=3Dhttps%3A%2F%2Flists= .sourceforge.net%2Flists%2Flistinfo%2Fphpwiki-talk&data=3D05%7C02%7Cmarc-et= ienne.vargenau%40nokia.com%7C3f24d955fb20401444b408ddeb1316e7%7C5d471751967= 5428d917b70f44f9630b0%7C0%7C0%7C638925189423568480%7CUnknown%7CTWFpbGZsb3d8= eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCI= sIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&sdata=3D6Ovckr72RjkaAZq5TDwJVzgrc4heKIWvaLqh= XIp70h0%3D&reserved=3D0<https://lists.sourceforge.net/lists/listinfo/phpwik= i-talk> > > -- Not sent from an iPhone. -- Not sent from an iPhone. _______________________________________________ Phpwiki-talk mailing list [email protected] https://eur03.safelinks.protection.outlook.com/?url=3Dhttps%3A%2F%2Flists.s= ourceforge.net%2Flists%2Flistinfo%2Fphpwiki-talk&data=3D05%7C02%7Cmarc-etie= nne.vargenau%40nokia.com%7C3f24d955fb20401444b408ddeb1316e7%7C5d47175196754= 28d917b70f44f9630b0%7C0%7C0%7C638925189423585832%7CUnknown%7CTWFpbGZsb3d8ey= JFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsI= ldUIjoyfQ%3D%3D%7C0%7C%7C%7C&sdata=3Dv7VnGkTGpbMbdsl6Se8FSYmZptpfMw4%2F1ZR9= hIAnYQc%3D&reserved=3D0<https://lists.sourceforge.net/lists/listinfo/phpwik= i-talk> --_000_DU2SPRMB0035B59B8C99D3BFE1284F3FAC00ADU2SPRMB0035eurprd_ Content-Type: text/html; charset="iso-8859-1" Content-Transfer-Encoding: quoted-printable <html> <head> <meta http-equiv=3D"Content-Type" content=3D"text/html; charset=3Diso-8859-= 1"> </head> <body> <div dir=3D"ltr" style=3D"font-family: Aptos, Arial, Helvetica, sans-serif;= font-size: 12pt; color: rgb(0, 0, 0);"> Hi Harold,</div> <div dir=3D"ltr" style=3D"font-family: Aptos, Arial, Helvetica, sans-serif;= font-size: 12pt; color: rgb(0, 0, 0);"> <br> </div> <div dir=3D"ltr" style=3D"font-family: Aptos, Arial, Helvetica, sans-serif;= font-size: 12pt; color: rgb(0, 0, 0);"> The latest version of PhpWiki is 1.6.6.</div> <div dir=3D"ltr" style=3D"font-family: Aptos, Arial, Helvetica, sans-serif;= font-size: 12pt; color: rgb(0, 0, 0);"> <br> </div> <div style=3D"font-family: Aptos, Arial, Helvetica, sans-serif; font-size: = 12pt; color: rgb(0, 0, 0);"> You can see the version you are running by displaying the SystemInfo p= age:</div> <div style=3D"font-family: Aptos, Arial, Helvetica, sans-serif; font-size: = 12pt; color: rgb(0, 0, 0);"> <a href=3D"http://phpwiki.demo.free.fr/index.php/SystemInfo" data-outlook-i= d=3D"f5397af8-0c44-42b7-a6ec-55ab444771af">http://phpwiki.demo.free.fr/inde= x.php/SystemInfo</a></div> <div dir=3D"ltr" style=3D"font-family: Aptos, Arial, Helvetica, sans-serif;= font-size: 12pt; color: rgb(0, 0, 0);"> <br> </div> <p style=3D"line-height: normal; margin: 0px;"><span style=3D"font-family: = Aptos, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);"= >In the source code, the version can be found in files </span><span style=3D"font-family: Menlo; font-size: 11px; color: rgb(0, 0,= 0);">Makefile, lib/prepend.php</span><span style=3D"font-family: Aptos, Ar= ial, Helvetica, sans-serif; font-size: 11px; color: rgb(0, 0, 0);"> </= span><span style=3D"font-family: Aptos, Arial, Helvetica, sans-serif; font-= size: 12pt; color: rgb(0, 0, 0);">and all pgsrc files. </span></p> <div dir=3D"ltr" style=3D"font-family: Aptos, Arial, Helvetica, sans-serif;= font-size: 12pt; color: rgb(0, 0, 0);"> <br> </div> <div dir=3D"ltr" style=3D"font-family: Aptos, Arial, Helvetica, sans-serif;= font-size: 12pt; color: rgb(0, 0, 0);"> The patches from Christof Meerwald (see below) are not yet in version 1.6.6= , I will publish a new version with them.</div> <div dir=3D"ltr" style=3D"font-family: Aptos, Arial, Helvetica, sans-serif;= font-size: 12pt; color: rgb(0, 0, 0);"> <br> </div> <div dir=3D"ltr" style=3D"font-family: Aptos, Arial, Helvetica, sans-serif;= font-size: 12pt; color: rgb(0, 0, 0);"> Best regards,</div> <div dir=3D"ltr" style=3D"font-family: Aptos, Arial, Helvetica, sans-serif;= font-size: 12pt; color: rgb(0, 0, 0);"> <br> </div> <div dir=3D"ltr" style=3D"font-family: Aptos, Arial, Helvetica, sans-serif;= font-size: 12pt; color: rgb(0, 0, 0);"> Marc-Etienne</div> <div dir=3D"ltr" style=3D"font-family: Aptos, Arial, Helvetica, sans-serif;= font-size: 12pt; color: rgb(0, 0, 0);"> <br> </div> <div id=3D"ms-outlook-mobile-signature"> <p style=3D"margin: 0cm; font-family: Calibri, sans-serif; font-size: 11pt;= "><span style=3D"font-family: "Courier New"; font-size: 10pt; col= or: rgb(33, 33, 33);">-- <br> Marc-Etienne Vargenau </span><span style=3D"font-family: "Courier= New"; font-size: 10pt; color: rgb(0, 120, 215);"><u><a href=3D"mailto= :[email protected]" title=3D"mailto:marc-etienne.vargenau@nok= ia.com" data-outlook-id=3D"4e9a427a-b45a-495b-9d0a-7f87c76d561a" style=3D"m= argin-top: 0px; margin-bottom: 0px;">[email protected]</a></u= ></span><span style=3D"font-family: "Courier New"; font-size: 10p= t; color: rgb(33, 33, 33);"><br> Nokia, 12, rue Jean-Bart, 91300 Massy, FRANCE<br> Mobile: </span><span style=3D"font-family: "Courier New"; font-si= ze: 10pt; color: rgb(0, 120, 215);"><u><a href=3D"tel:+33624497868" data-ou= tlook-id=3D"f5300059-1445-4c88-b1dc-72c9fb79cf3c" style=3D"margin-top: 0px;= margin-bottom: 0px;">+33 6 24 49 78 68</a></u></span></p> <p style=3D"text-align: left; margin: 0cm; font-family: Calibri, sans-serif= ; font-size: 11pt;"> <span style=3D"font-family: "Courier New"; font-size: 10pt; color= : rgb(33, 33, 33);">Senior Specialist Open Source<br> Planned absence:</span><span style=3D"font-family: "Courier New";= color: rgb(33, 33, 33);"><b> none</b></span></p> </div> <div id=3D"mail-editor-reference-message-container"> <div class=3D"ms-outlook-mobile-reference-message skipProofing"> <meta name=3D"Generator" content=3D"Microsoft Exchange Server"> </div> <div class=3D"ms-outlook-mobile-reference-message skipProofing" style=3D"te= xt-align: left; padding: 3pt 0in 0in; border-width: 1pt medium medium; bord= er-style: solid none none; border-color: rgb(181, 196, 223) currentcolor cu= rrentcolor; font-family: Aptos; font-size: 12pt; color: black;"> <b>De : </b>Harold Hallikainen <[email protected]><br> <b>Date : </b>mercredi, 3 septembre 2025 =E0 19:55<br> <b>=C0 : </b>Discussion on PhpWiki features, bugs, development. <ph= [email protected]><br> <b>Objet : </b>Re: [Phpwiki-talk] Missing access checks in CreatePage = and AppendText plugins<br> <br> </div> <div class=3D"PlainText" style=3D"font-size: 11pt;"><br> CAUTION: This is an external email. Please be very careful when clicking li= nks or opening attachments. See the URL nok.it/ext for additional informati= on.<br> <br> <br> <br> I've had this update on my list of things to do, but had not yet gotten to<= br> it. This morning, there were a bunch of new blank pages on one of my<br> wikis. So, I deleted them and did the update. Is there an easy way to tell<= br> what version I have installed to make sure I did it correctly? The wiki is<= br> running, but I'd like to make sure it is running the latest code.<br> <br> Also, one of the newly created pages has a title that is blank, and I<br> cannot delete it through the admin interface. Is there a way to delete it?<= br> <br> THANKS!<br> <br> Harold<br> <br> <br> On Wed, July 30, 2025 12:59 am, Marc-Etienne Vargenau \(Nokia\) via<br> Phpwiki-talk wrote:<br> > Hi Christof,<br> ><br> ><br> > Thank you for your patches.<br> > I have published them in Subversion.<br> ><br> ><br> > Best regards,<br> ><br> ><br> > Marc-Etienne<br> ><br> ><br> > --<br> > Marc-Etienne Vargenau<br> > [email protected]<mailto:marc-etienne.vargenau@nokia.= com><br> > Nokia, 12, rue Jean-Bart, 91300 Massy, FRANCE<br> > Mobile: +33 6 24 49 78 68<tel:+33624497868><br> > Senior Specialist Open Source<br> > Planned absence: 4-22 August<br> ><br> ><br> > De : Christof Meerwald via Phpwiki-talk<br> > <[email protected]><br> > Date : mardi, 29 juillet 2025 =E0 23:24<br> > =C0 : Phpwiki-talk <[email protected]><br> > Cc : Christof Meerwald <[email protected]><br> > Objet : Re: [Phpwiki-talk] Missing access checks in CreatePage and<br> > AppendText plugins<br> ><br> ><br> > CAUTION: This is an external email. Please be very careful when clicki= ng<br> > links or opening attachments. See the URL nok.it/ext for additional<br= > > information.<br> ><br> ><br> ><br> > On Tue, Jul 29, 2025 at 11:04:24PM +0200, Christof Meerwald wrote:<br> ><br> >> Noticed that the CreatePage and AppendText plugins let unauthentic= ated<br> >> users create pages or let them append text to pages, e.g.<br> ><br> > Actually, WikiAdminDeleteAcl is also missing an access check, patch<br= > > attached.<br> ><br> ><br> > Christof<br> ><br> ><br> > --<br> > <a href=3D"https://cmeerw.o/" data-outlook-id=3D"22312b0a-9763-439b-8e= 15-25882e229aee"> https://eur03.safelinks.protection.outlook.com/?url=3Dhttps%3A%2F%2Fcmeerw.= o%2F&data=3D05%7C02%7Cmarc-etienne.vargenau%40nokia.com%7C3f24d955fb204= 01444b408ddeb1316e7%7C5d4717519675428d917b70f44f9630b0%7C0%7C0%7C6389251894= 23530808%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMC= IsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&sdata= =3DOiyIJxyrNr9KpLerPD282%2FaY5pxuOv4YK2Btjw8baCQ%3D&reserved=3D0</a><br= > > rg%2F&data=3D05%7C02%7Cmarc-etienne.vargenau%40nokia.com%7C4e79621= 8c09f47fe<br> > 61f408ddcee6362f%7C5d4717519675428d917b70f44f9630b0%7C0%7C0%7C63889421= 050<br> > 8983458%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMD= AwM<br> > CIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&s= data=3Dw%<br> > 2B9pGigz7tN%2BhTJYA2nrg%2FgQ34nH6B59h0smjnzcheg%3D&reserved=3D0<= ;https://cme<br> > erw.org/> &nbs= p; &= nbsp; sip:cmeerw at cmeerw.org<br> > <a href=3D"mailto:cmeerw" data-outlook-id=3D"7f233571-6a25-4230-93e5-1= 5d00b863b79"> mailto:cmeerw</a> at cmeerw.org &nb= sp; xmpp:= cmeerw at cmeerw.org<br> > _______________________________________________<br> > Phpwiki-talk mailing list<br> > [email protected]<br> > <a href=3D"https://lists.sourceforge.net/lists/listinfo/phpwiki-talk" = data-outlook-id=3D"912d64eb-bc7d-4e3e-a9bb-45b11d5e943a"> https://eur03.safelinks.protection.outlook.com/?url=3Dhttps%3A%2F%2Flists.s= ourceforge.net%2Flists%2Flistinfo%2Fphpwiki-talk&data=3D05%7C02%7Cmarc-= etienne.vargenau%40nokia.com%7C3f24d955fb20401444b408ddeb1316e7%7C5d4717519= 675428d917b70f44f9630b0%7C0%7C0%7C638925189423568480%7CUnknown%7CTWFpbGZsb3= d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpb= CIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&sdata=3D6Ovckr72RjkaAZq5TDwJVzgrc4heKI= WvaLqhXIp70h0%3D&reserved=3D0</a><br> ><br> ><br> <br> <br> --<br> Not sent from an iPhone.<br> <br> <br> --<br> Not sent from an iPhone.<br> <br> <br> _______________________________________________<br> Phpwiki-talk mailing list<br> [email protected]<br> <a href=3D"https://lists.sourceforge.net/lists/listinfo/phpwiki-talk" data-= outlook-id=3D"698b7a82-5df1-4285-b336-f6dbddf9050f">https://eur03.safelinks= .protection.outlook.com/?url=3Dhttps%3A%2F%2Flists.sourceforge.net%2Flists%= 2Flistinfo%2Fphpwiki-talk&data=3D05%7C02%7Cmarc-etienne.vargenau%40noki= a.com%7C3f24d955fb20401444b408ddeb1316e7%7C5d4717519675428d917b70f44f9630b0= %7C0%7C0%7C638925189423585832%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRyd= WUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0= %7C%7C%7C&sdata=3Dv7VnGkTGpbMbdsl6Se8FSYmZptpfMw4%2F1ZR9hIAnYQc%3D&= reserved=3D0</a><br> </div> </div> </body> </html> --_000_DU2SPRMB0035B59B8C99D3BFE1284F3FAC00ADU2SPRMB0035eurprd_-- --===============1973130827094373436== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline --===============1973130827094373436== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline _______________________________________________ Phpwiki-talk mailing list [email protected] https://lists.sourceforge.net/lists/listinfo/phpwiki-talk --===============1973130827094373436==--