Piwigo Bugtracker

Piwigo bug tracker has moved to Github

This bugtracker is kept to provide history on old issues.


View Issue Details Jump to Notes ] Issue History ] Print ]
IDProjectCategoryView StatusDate SubmittedLast Update
0002828Piwigoconfigurationpublic2013.01.31 19:232014.03.31 14:13
Reporterblion 
Assigned Torvelices 
PrioritynormalSeverityminorReproducibilityalways
StatusclosedResolutionfixed 
PlatformANYOSANYOS VersionANY
Product Version2.4.1 
Target VersionFixed in Version2.5.0 
Summary0002828: Watermark tool bug.
DescriptionThere's a weak point using watermark tool. There's a way to obtain the original file without the watermark.
Steps To ReproduceThe way to obtain the original file is to get de dynamic image url:

/domain.com/i.php?/upload/2013/01/28/20130131000001-66b88f69-me.jpg

and then, you can get the original file url by just deleting two things.

/domain.com/i.php?/upload/2013/01/28/20130131000001-66b88f69-me.jpg
/domain.com/upload/2013/01/28/20130131000001-66b88f69.jpg
TagsNo tags attached.
browserany
Database engine and versionANY
PHP versionANY
Web serverApache 1.3.x
Attached Files

- Relationships

-  Notes
(0007390)
plg (manager)
2014.03.31 14:13

You can use new feature $conf['original_url_protection'] = 'all';

- Issue History
Date Modified Username Field Change
2013.01.31 19:23 blion New Issue
2013.01.31 19:23 blion browser => any
2013.01.31 19:23 blion Database engine and version => ANY
2013.01.31 19:23 blion PHP version => ANY
2013.01.31 19:23 blion Web server => Apache 1.3.x
2014.03.31 14:13 plg Note Added: 0007390
2014.03.31 14:13 plg Assigned To => rvelices
2014.03.31 14:13 plg Status new => closed
2014.03.31 14:13 plg Resolution open => fixed
2014.03.31 14:13 plg Fixed in Version => 2.5.0


Copyright © 2000 - 2019 MantisBT Team
Contact
Powered by Mantis Bugtracker