403 Forbidden - Mid Album Caption - After Batch Add 403 Forbidden - Mid Album Caption - After Batch Add
 

News:

CPG Release 1.6.26
Correct PHP8.2 issues with user and language managers.
Additional fixes for PHP 8.2
Correct PHP8 error with SMF 2.0 bridge.
Correct IPTC supplimental category parsing.
Download and info HERE

Main Menu

403 Forbidden - Mid Album Caption - After Batch Add

Started by Aeronautic, January 05, 2007, 08:49:49 AM

Previous topic - Next topic

0 Members and 1 Guest are viewing this topic.

Aeronautic

Read the other threads - can't see this anywhere else.

In my long used 1.4.9 stock footage gallery.

Tonight I batch added some 40 files to a new album. Then set about to add keywords, captions, etc. Been doing this for months. Logged in as the only user - admin. Not getting kicked out.

But after adding say the 30th caption and hitting "Apply Modifications," but after captions and such have been saved for many of these same files already, this last addition generates this error (403 in my logs) and I've got a custom 403 page which CPG is kicking due to the 403 that read thus:

Hello MYIPADDRESS You came from http://www.aeronauticpictures.com/royalty-free-stock-footage/editpics.php?album=105&start=25&count=25 and wanted to see /royalty-free-stock-footage/editpics.php?album=105&start=25&count=25 Sorry, but you are not allowed to view that resource.


Keep in mind the permissions are the same for this album as all my others and that I did just save the captions for most of the other files. This seems tied to the amount of captions added. Captions here meaning any file specific data like title, price or format info.

Huh?

FYI: displayimage.php is moded with the paypal cart.
Plugins: Final_Extract2 v1.0

Album itself is viewable by anyone.

Also checked the integrity of the database but it seems to check out okay. Problem persists with both IE and Netscape.

Checked my .htaccess file too and see nothing that would do this. Seems CPG's auto refresh is kicking to something forbidden. Also just changed no visitor uploads to allowed even though I'm the only user. That produced the same error.

Turning on debug I got this error right away:

/include/functions.inc.php

    * Warning line 483: sprintf(): Too few arguments


And trying to edit the caption again at the start I get many instances of this when the page loads, but before attempting to save:

/editpics.php

    * Notice line 408: Undefined variable: or


Trying to save produces only the 403 error above, nothing from CPG debug.

Thanks!

Nibbler

Sounds like mod_security or the Hardening patch. Are you/your host using either of these?

Aeronautic

Hi Nibbler - thanks for taking a look.

mod_security is running on the server but (or perhaps related) I've got some new facts that may solve the mystery for me and anyone else that comes looking at this thread.

First a question: Are there code rules in the CPG core to prevent hacking for text strings in the "Title" field like those user selectable for "filenames"?

I can't see any if there are, but by removing a string where I'd used a "-" (a 2nd one actually) in the title of the offending record (again this is the default "Title" field) breaking up a couple of words like "Star" and "Purple Gas Clouds" (astronomy subject) it worked fine again.

This is after also trying to edit the field in the single record style (edit information when viewing file) which also had failed in the same manner earlier.

And what's really strange is that I've got many records in the CPG database where I'd titled something like "Military Stock Footage - Formation - Navy - US Marine Corps F/A-18 Hornet - E-2C - A-6 - F-14 - S-3 - EA-6B" (That's the worst/longest example - but it works fine)

Even the one that caused this failure is live with "Space Stock Footage - Star and Purple Gas Clouds"

But it failed as described at the top of this thread when I tried "Space Stock Footage - Star - Purple Gas Clouds"

!!

Any ideas? I'd like to avoid the problem in the future but from my examples of working pages you can see why I'd have thought my first version of the astronomy one would work.

Many many thanks!

Aeronautic

Updating this issue - which is an enigma wrapped in a mystery.

I changed the template to mac_ox_x  - I say that just in case it has anything to do with improved function.

As an aside it seems to be loading faster than hardwired.

Okay, I just added a new album full of video clips. I captioned them.

And I added some uber-hyphenated "Titles" while saving my work as I went along, fully expecting this problem to return at any time. It did not. Not even with a title like this one:

Aerial Stock Footage of Canada - Canadian Cities - HD - High Definition - Vancouver - British Columbia - Toronto - Ontario

Based on the issue I had before, unless the template did have something to do with this, I can't see for the life of me why that works.

I had no problems with titles like this for any clip in that album!

???