Support This Site

FacileForms 1.4.7 Security Release Print E-mail
Written by Peter Koch   
Wednesday, 27 September 2006
Image

A cross-site scripting vulnerability has been identified and fixed in the FacileForms 1.4.7 Security Release. The vulnerability required either PHP's register globals to be enabled, or the RG_EMULATION setting of Joomla/Mambo to on (1) which is unfortunately the default in current joomla and mambo installations. If both register globals as well as RG_EMULATION are off, the exploit was not possible.

It is advised to upgrade to 1.4.7 ASAP, and for your own safety also turn off register globals and RG_EMULATION. FacileForms 1.4.7 is available now in the Download Section, and there is a patch available for 1.4.6g as well.

Comments

alexwalker
2006-10-11 05:19:31
I tried to upgrade from 4.1.5 to 4.1.7 but I got a failed message to say unable to create directory com_facileform. I had uninstalled 4.1.5 and could see that the component had been removed in Xplorer. My register globals were OFF in both php.ini and globals.php. Any suggestions please?
boesh
2006-10-15 04:21:39
How to upgrade, just copy all the files over the old ones?
Boldee
2006-10-15 11:05:36
http://www.facileforms.biz/wiki/Upgrading
perler
2006-10-26 10:41:59
with the recent exploits, could you please establish a security mailing list? i don't have time to check back here regularly - but as we see, i should.. 
 
thanks, 
 
PAT
Newbytes
2006-11-24 06:56:43
Hello Peter 
 
I have a suggestion for you to improve the RSS feeds on youre site: 
 
Can you please change the Title of the RSS feeds from this website from "Powered by Mambo 4.5.2" to e.g :  
"Facile Form News" or something else with facileforms.  
 
Just go to Components -> Syndicate and change the title .. 
 
Now almost all Mambo sites with newsfeeds have the "Powered by mambo ..." message and that is a bit of a challenge to find the right feeds in youre rss-reader kinda program ( like in the new yahoo mail) 
 
 
Warm regards 
Marco 
Newbytes.nl
itpf
2006-12-01 13:05:39
Hello everyone, 
 
i am not able to understand the 6th page of the tutorial as it is totally different from the 1.4.7 facile forms  
sould someone help. 
thank u in advance 
 
Regards 
itpf
mathdeveloper
2007-01-07 10:55:59
My impression is that if you upgrade from version 1.4.4 to 1.4.7 then that the upgrade does not affect the database. I compared create.sql in the zip files for the components of version 1.4.4 and 1.4.7 and they were the same. 
 
www.numericalexample.com
seanang
2007-01-14 04:35:20
Hi Peter, 
 
I tried to upgrade from 1.4.6 to 1.4.7 but when I uninstall, there is a php error. So i check the net, and found your insruction. 
 
I followed your instructions, but when I delete the jos_facileforms, the site went KABOOM, when i check it. 
 
Now I am not able to access my joomla site and I also can access the Joomla Administrative panel anymore. 
 
What should I do? 
 
 
Your instructions 
 
Go to Components - Facile Forms - Manage Backend Menus  
Switch to the Samples package  
Select all menu items by clicking the checkbox left to the heading Menu Item  
Click either the Unpublish or the Delete button  
Repeat the previous steps for all other packages including the blank package  
Uninstall the Facile Forms component, module and mambot with the Joomla/Mambo installers  
Run phpMyAdmin to manually remove the Facile Forms tables (jos_facileforms_* or mos_facileforms_*)  
Delete tables created by other forms based on Facile. Consult documentation of the respective packages about what tables they are creating.
khawasli
2007-04-12 05:36:53
Well I have the latest version but I found another cross site scripting vulnerability in facileforms. Does anyone know how i can contact the administrators of this site? I don't see their contact anywhere... here's my email 
khawasli@gmail.com
jmeyer74
2007-04-15 09:10:52
Absolutly great ! :grin Thaaaaaanks
gelbehexe
2007-05-01 12:13:58
Hello Peter, 
 
I started to use Joomla a few days ago and very soon I got "first contact" to FacileForms.  
 
First of all I have to say thank you for that great work. 
 
But while using it I met two problems. 
 
1. My standard language is german and I told Joomla to use utf-8. Ok, not a big problem to convert the relevant language files to utf-8. But maybe it makes sense to implement both: iso-8859-1(5) and utf-8? 
 
2. While one of my goals when creating a webpage is to produce valid XHTML. So I run into problems because events (e. g. onclick) in FacileForms are all written by combining lowercase and uppercase. This is not valid XHTML, because the specification does only allow lowercase.  
The second little obstacle to get valid XHTML affects only if the width and/or height of textareas were given in pixels. In this case there will no rows/cols attributes in html output, which are both required for valid XHTML. Workaround is easy - one can use cols/ row sunits instead of pixels and use css to give the dimensions exactly. 
 
I used a (very long) bash command line to convert the contents of the com-package and I can post it here, if you or anyone else is interested in. Just tell. 
 
Greetings 
 
Petra
fizot
2007-05-02 03:38:48
sakp
2008-05-19 17:03:07
I install the 1.4.7 version and everything went perfect. 
 
When I try to make a new form using the tutorial I observe that the script tab (I want to use the library script as the example) did not do anything. Just click to radio button and nothing happen. In the example when you press the library radio button shows the drop down menu of the library scripts. 
 
Any idea why this happen??? 
 
Any way to solve the problem??? 
 
The software works fine except this thing which is crucial!!! 
 
Thank you in advance
afomenko
2009-06-06 18:05:15
Download section is broken. Anybody knows if site is still maintained??
trentonwilmore
2009-10-17 13:16:25
i am not able to understand the 6th page of the tutorial as it is totally different from the 1.4.7 facile forms  
sould someone help.  
 
 
associate degree in nursing online | online associate degree | life experience mba degree
zancudopilucho
2009-10-23 17:55:10
que pasa con la seccion descargas.
christmassms
2010-05-08 02:12:20
Very nicely written post it contains useful information for me. I am happy to find your distinguished way of writing the post. Now you make it easy for me to understand and implement the concept. Thank you for the post. Debt Settlement
jameskg
2010-05-13 23:57:29
I did upgrade to upgrade to 1.4.7 but had some problems configuring my system. But I finally figured it out after many hours. six sigma online Six Sigma Online | project management certificationProject Management Certification Online
dellatlas
2010-06-02 23:31:35
Thanks for this article, very helpful! 
 
The best air purifiers
christmassms
2010-06-12 17:45:31
Quality is everything, so we need to ensure that there are values on what we are sharing to keep our subscribers interested. Getting them annoyed is one thing we must note do! San Francisco Interior Designer
christmassms
2010-06-12 17:46:20
Quality is everything, so we need to ensure that there are values on what we are sharing to keep our subscribers interested. Getting them annoyed is one thing we must note do! San Francisco Interior Designer
christmassms
2010-06-28 14:01:03
It is advised to upgrade to 1.4.7 ASAP, and for your own safety also turn off register globals and RG_EMULATION. FacileForms 1.4.7 is available now in the Download Section, and there is a patch available for 1.4.6g as well. promotional products
basecom
2010-07-06 17:01:08
I did upgrade to upgrade to 1.4.7 but had some problems. probably relevant character set.  
muhasebe programı | pimapen
rick854
2010-08-19 21:08:47
I also upgraded to the 1.4.7 version and had the same problems. Must be a couple of issues with this release ? service & maintenance procedures can be done with motorcycle manuals online and pro manuals
rick854
2010-08-19 21:12:14
I also upgraded to this version 1.4.7 had no problems so far. have the patch, so prob that is it. 
pro manuals
adultbluray
2010-08-24 22:54:36
Thank yiu vrey much for teh article 
adult dvd

Only registered users can write comments.
Please login or register.

 
< Prev   Next >