Donate Share

phpmyfamily

Tracker: Bugs

9 security flaw: automatic log-in - ID: 973962
Last Update: Comment added ( simesb )

When a visitor (someone who's not logged in) clicks to
download a document and then leaves the page, they
are automatically logged in as 'nobody.'
'Nobody' now has the right to add people, change
information, upload and delete documents and images,
and is even given the option to change password
(although not sure what the system considers the
current password to be).
Of course, they do not have the option to admin, it's
just as if I had created a user called nobody. When
logged in as 'nobody' if I try to access admin.php, I get
the forbidden error, and then am logged back out
completely when returning to the page I was just at.
I am using version 1.3.0.


Valerie Holfield ( vholifield ) - 2004-06-16 15:45

9

Closed

None

Simon Booth

Security

v1.3.0

Public


Comments ( 3 )




Date: 2004-06-19 20:22
Sender: simesbProject Admin

Logged In: YES
user_id=313649

This bug only affected users with a php ini setting of "register_globals
= On" It has now been fixed for this group of users.


Date: 2004-06-16 16:45
Sender: vholifield

Logged In: YES
user_id=1060565

Well, I was doing some editing, so I've been logged in for a
while - and nothing happened after I downloaded a
document. I stayed logged in as 'admin.' As far as I can tell,
nothing changed.


Date: 2004-06-16 16:37
Sender: simesbProject Admin

Logged In: YES
user_id=313649

Hi

Can you please confirm what happens if you are already
logged in. Do you change to be "nobody" or do you remain as
your current user?

Simon


Log in to comment.

Attached File

No Files Currently Attached

Changes ( 6 )

Field Old Value Date By
status_id Open 2004-06-19 20:22 simesb
close_date - 2004-06-19 20:22 simesb
category_id None 2004-06-16 16:29 simesb
artifact_group_id None 2004-06-16 16:29 simesb
priority 5 2004-06-16 16:29 simesb
assigned_to nobody 2004-06-16 16:29 simesb