First I want to thank the team for the great job.
The problem for me is that I can not for the moment upgrade the whole functions.inc.php file because I did a lot of changes there.
Is possible to have only the lines of code to change in this file? I mean something step by step, like replace this with these.
Regards.
In functions.inc.php [function user_get_profile]
Replace
if (isset($_COOKIE[$CONFIG['cookie_name'].'_data'])) {
$USER = @unserialize(@base64_decode($_COOKIE[$CONFIG['cookie_name'].'_data']));
}
with
if (isset($_COOKIE[$CONFIG['cookie_name'].'_data'])) {
$USER = @unserialize(@base64_decode($_COOKIE[$CONFIG['cookie_name'].'_data']));
$USER['lang'] = strtr($USER['lang'], '$/\\:*?"\'<>|`', '____________');
}
That is the only security related change in that file.
Thank you Sir.
Regards
For reference: the subject "About the new security release" is a bit vague. It should read "About the security release cpg1.4.19".
You could have used a diff viewer like WinMerge (http://forum.coppermine-gallery.net/index.php/topic,31423.msg229891.html#msg229891) to figure out the changes