General Users have Admin Rights?!?! General Users have Admin Rights?!?!
 

News:

cpg1.5.48 Security release - upgrade mandatory!
The Coppermine development team is releasing a security update for Coppermine in order to counter a recently discovered vulnerability. It is important that all users who run version cpg1.5.46 or older update to this latest version as soon as possible.
[more]

Main Menu

General Users have Admin Rights?!?!

Started by Cyberpawz, August 19, 2005, 05:17:24 AM

Previous topic - Next topic

0 Members and 2 Guests are viewing this topic.

Cyberpawz

OK, this is a problem...

(https://coppermine-gallery.com/forum/proxy.php?request=http%3A%2F%2Fwww.cyberpawz.com%2Fimages%2FScreenShot.jpg&hash=5427b48d4782848e64bb842982a1b15decc2ffde)

This is from an end users telling me she has authorization to ban users.  She doesn't have administrator rights, no one except I do... What in god's name is going on, and how can I fix this.  This is a very, very big problem that needs to be fixed before some immature person on the site realizes this and may not be as giving as this person who told me about this, and decide to delete people on purpose.

Tranz

Log in as admin and go through the users list to see what they are assigned to. Also, change your admin password to be on the safe side. Do you have the latest version, 1.3.3?

Cyberpawz

Quote from: TranzNDance on August 19, 2005, 06:32:41 AM
Log in as admin and go through the users list to see what they are assigned to. Also, change your admin password to be on the safe side. Do you have the latest version, 1.3.3?

Yes, I have 1.3.3...

Everyone except a handful of people are Registered users... everyone else is a specialized group, which has no privileges whatsoever.

Oh, and I've already changed my password, it doesn't matter... I have a test account there, and even the test account has admin rights.

Cyberpawz

Oh, BTW here is the test account screen shot...

(https://coppermine-gallery.com/forum/proxy.php?request=http%3A%2F%2Fwww.cyberpawz.com%2Fimages%2Fproblem1.jpg&hash=b1d430032ba08fcfc433c43f5a221043c230b82f)

Joachim Müller

afaik you have heavily modified your coppermine install. Roll back the modifications you have applied, I'm sure that this whacky behaviour will go away then. Please post a link to your site and a non-admin test user account as well.

Cyberpawz

Quote from: GauGau on August 19, 2005, 07:38:40 AM
afaik you have heavily modified your coppermine install. Roll back the modifications you have applied, I'm sure that this whacky behaviour will go away then. Please post a link to your site and a non-admin test user account as well.

Actually I haven't done anything to the coppermine setup period... I took it out of the box per say and used it... otherwise it's been a standard setup...

And for rolling back the modifications, how do I do that?

Oh, and I can't post a link here to the site, for it seems no matter who registers they become a moderator... (I personally just set up a new user and they have admin privileges without being an admin)

Joachim Müller

then send me a PM with the link and an actual admin account please.

Cyberpawz

Any updates? I really would like to know if this is something that I need to edit inside the database or not.

Cyberpawz

Ok, this is getting annoying, I've not heard a thing, and the bug is still here... even after the last patch... any help would be appreciated Gau.

Nibbler

Perhaps he is busy. Feel free to PM me a link and FTP login if you would be happy for me to investigate.