no relative browsing in apache no relative browsing in apache
 

News:

cpg1.5.48 Security release - upgrade mandatory!
The Coppermine development team is releasing a security update for Coppermine in order to counter a recently discovered vulnerability. It is important that all users who run version cpg1.5.46 or older update to this latest version as soon as possible.
[more]

Main Menu

no relative browsing in apache

Started by Dead J. Dona, March 20, 2006, 04:05:07 PM

Previous topic - Next topic

0 Members and 1 Guest are viewing this topic.

Dead J. Dona

Hi everybody.

I try to bridge CPG and phpBB and get some problem.

There's no relative browsing in our Apache configuration. Admin switch it on when I run bridging wizard and then turn it off after installation.
I don't even sure that this is Apache not something else.
So I can't login now into CPG. I switch off bridging and can login now, but that's doesn't solve main problem.
When bridging is on, login link looks like /login.php?link=../gallery, so server give me 500 error and nothing more.

What can I do??
wbr, Me. Dead J. Dona

Joachim Müller

When requesting bridge support - mandatory!
I think you got things wrong with "relative paths" - this is an http/html thing that must work - it can't be turned off in apache config.


Dead J. Dona

I know bout mandatory things, but this information cant help.

When I run bridging wizard, server shows me 500 error. Then I call admin anâ run wizard over again. Admin says that he disabled .. in URL. He enabled it, I run wizard and he turned it off again.
And then gallery broke... It uses paths like /login.php?link=../forums/ and when I click at this link server shows me 500 error.

I can't swear that admin switch this option in Apache, maybe this is something else, I can ask him right now.
wbr, Me. Dead J. Dona

Dead J. Dona

this is Mod Secure for apache browsing with .. in URL fully disabled.

What can I do?
wbr, Me. Dead J. Dona

Nibbler

No real solution known - try to come up with something yourself or find less restrictive hosting.