Hello/Hi/Greetings,
my Piwigo server is running over 6 years, but since last weekend, I found out that I can't access to home page (default, index.php) once login with any accounts. Without login (as guest), home page is displayed normally, I can access to any sub-album after login, except home page. For this I didn't get any error message, just a blank home page screen. Any help is very appreciated! Thanks!
Piwigo URL: http://wuyegallery.serveuser.com/piwigo/
Offline
Check the server logs for when you are accessing the home page.
Offline
Hi
do you mean Piwigo log?
below is the log (under piwigo\_data\logs) after login and home page is blank.
[2024-07-30 20:27:28] [DEBUG] [i.php]
src_path: 'IMG_E3803.JPG'
derivative_path: 'IMG_E3803-sq.JPG'
o_size: '1586 924 1465464'
d_size: '120 120 14400'
mem_usage: 12.199999999999999
timing: array(
'load' => 261,
'rotate' => '',
'crop' => 15,
'scale' => 19,
'sharpen' => '',
'watermark' => '',
'save' => 2,
'send' => 1,
'total' => 299,
)
Offline
I mean the web server logs. If you don't know what that is or what to look for then ask your hosting provider.
Offline
A blank page or WSOD white screen of death could be an issue with your environment. Likely there would be a php warning on the php logs for a memory limit error. if PHP display warnings are disabled you would only see this the blank page. Maybe a file was deleted, but I concur the web hosting logs should be more revealing. Watch the logs while hitting those pages and see what pops up or look at the timestamps.
The log you shared doesn't provide anything useful unfortunately.
Offline
Hi
I have the same problem, but for one single album of 7 albums. When clicking on the album from the homepage, a white page is shown. No error message, the url seems to be correct.
I first noticed the blank album on 13th July 2024, so it's not all new.
Today, I tried: updating to Piwigo 14.5.0. Turning off all plugins. Uninstall and install Piwigo (with the same database and the same "galleries" folder).
I can download a text file "access.log" through FTP. Is this the right web server log? What do I need to look for? It seems to be either a log of access to the website (which is jsut the gallery at the moment) or things that the server is doing itself.
The log with date from 22th July does not contain the album with the white page.
Thank you in advance.
Offline
access.log is normally the web server (nginx/apache).
Look for error.log or php.access.log. What options do you have available to pick from?
Offline
Thank you, this helps.
I also found access.Merged.log and error.log.
The error.log from today is quite full, but not fuller as the access.log. Here are the last few lines:
2024/08/01 20:30:15 [error] 3218039#3218039: *92435918 access forbidden by rule, client: 114.119.145.233, server: carusoworld.ch, request: "GET /gallery/index.php?/categories/posted-monthly-list-2019-9/start-15&lang=tr_TR HTTP/1.1", host: "www.carusoworld.ch"
2024/08/01 20:30:15 [error] 3218039#3218039: *92435918 access forbidden by rule, client: 114.119.145.233, server: carusoworld.ch, request: "GET /gallery/index.php?/categories/posted-monthly-list-2019-9/start-15&lang=tr_TR HTTP/1.1", host: "www.carusoworld.ch"
2024/08/01 20:30:59 [error] 3218095#3218095: *92437189 access forbidden by rule, client: 47.128.56.44, server: carusoworld.ch, request: "GET /gallery/picture.php?%20%20%20%20/8408/categories/created-monthly-calendar-2011-6-26&%20%20%20%20metadata HTTP/2.0", host: "carusoworld.ch"
2024/08/01 20:30:59 [error] 3218095#3218095: *92437189 access forbidden by rule, client: 47.128.56.44, server: carusoworld.ch, request: "GET /gallery/picture.php?%20%20%20%20/8408/categories/created-monthly-calendar-2011-6-26&%20%20%20%20metadata HTTP/2.0", host: "carusoworld.ch"
[Thu Aug 01 20:31:49.280137 2024] [proxy_fcgi:error] [pid 3218460] [client 17.241.219.206:0] AH01071: Got error 'Unable to open primary script: /home/ch122816/web/carusoworld.ch/public_html/gallery/main.php (No such file or directory)'
2024/08/01 20:36:24 [error] 3218032#3218032: *92447630 access forbidden by rule, client: 47.128.35.65, server: carusoworld.ch, request: "GET /gallery/picture.php?%20%20%20%20%20%20%20%20/12413/categories/created-monthly-list-2013-12-31&%20%20%20%20%20%20%20%20metadata HTTP/2.0", host: "carusoworld.ch"
2024/08/01 20:36:24 [error] 3218032#3218032: *92447630 access forbidden by rule, client: 47.128.35.65, server: carusoworld.ch, request: "GET /gallery/picture.php?%20%20%20%20%20%20%20%20/12413/categories/created-monthly-list-2013-12-31&%20%20%20%20%20%20%20%20metadata HTTP/2.0", host: "carusoworld.ch"
Somewhere in the middle of the file, those were from around the time when uninstalling and re-installing Piwigo:
[Thu Aug 01 18:48:16.619502 2024] [:error] [pid 3218408] [client 84.73.196.110:0] [client 84.73.196.110] ModSecurity: Access denied with code 403 (phase 2). Match of "eq 1" against "&SESSION:pwg" required. [file "/etc/modsecurity/02_comodo/30_Apps_OtherApps.conf"] [line "6284"] [id "241783"] [rev "2"] [msg "COMODO WAF: CSRF vulnerability in Piwigo before 2.6.2 (CVE-2014-4614)||carusoworld.ch|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "carusoworld.ch"] [uri "/gallery/ws.php"] [unique_id "Zqu8UF6msCuVWMj8Y8Y6jQAAAC8"], referer: https://carusoworld.ch/gallery/admin.php?page=albums
[Thu Aug 01 18:48:17.598412 2024] [:error] [pid 3218542] [client 84.73.196.110:0] [client 84.73.196.110] ModSecurity: Access denied with code 403 (phase 2). Match of "eq 1" against "&SESSION:pwg" required. [file "/etc/modsecurity/02_comodo/30_Apps_OtherApps.conf"] [line "6284"] [id "241783"] [rev "2"] [msg "COMODO WAF: CSRF vulnerability in Piwigo before 2.6.2 (CVE-2014-4614)||carusoworld.ch|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "carusoworld.ch"] [uri "/gallery/ws.php"] [unique_id "Zqu8Uacmcm-TSaBSRCL09wAAAGU"], referer: https://carusoworld.ch/gallery/admin.php?page=albums
[Thu Aug 01 18:48:17.811883 2024] [:error] [pid 3217461] [client 84.73.196.110:0] [client 84.73.196.110] ModSecurity: Access denied with code 403 (phase 2). Match of "eq 1" against "&SESSION:pwg" required. [file "/etc/modsecurity/02_comodo/30_Apps_OtherApps.conf"] [line "6284"] [id "241783"] [rev "2"] [msg "COMODO WAF: CSRF vulnerability in Piwigo before 2.6.2 (CVE-2014-4614)||carusoworld.ch|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "carusoworld.ch"] [uri "/gallery/ws.php"] [unique_id "Zqu8UebcjpfvKzmfiDQ1vQAAAHE"], referer: https://carusoworld.ch/gallery/admin.php?page=albums
2024/08/01 18:43:30 [error] 3218074#3218074: *92239703 access forbidden by rule, client: 156.59.198.135, server: carusoworld.ch, request: "GET /gallery/_data/i/galleries/Urlaub/Toscana2011/Toscana2011_182-me.jpg HTTP/2.0", host: "carusoworld.ch"
2024/08/01 18:43:30 [error] 3218074#3218074: *92239703 access forbidden by rule, client: 156.59.198.135, server: carusoworld.ch, request: "GET /gallery/_data/i/galleries/Urlaub/Toscana2011/Toscana2011_182-me.jpg HTTP/2.0", host: "carusoworld.ch"
This is from last night:
2024/08/01 00:30:19 [error] 368085#368085: *90059288 access forbidden by rule, client: 47.128.18.111, server: carusoworld.ch, request: "GET /gallery/index.php?/categories/created-monthly-list-2019-any-10&lang=zh_CN HTTP/2.0", host: "www.carusoworld.ch"
2024/08/01 00:30:19 [error] 368085#368085: *90059288 access forbidden by rule, client: 47.128.18.111, server: carusoworld.ch, request: "GET /gallery/index.php?/categories/created-monthly-list-2019-any-10&lang=zh_CN HTTP/2.0", host: "www.carusoworld.ch"
[Thu Aug 01 00:34:55.111485 2024] [:error] [pid 4181829] [client 216.244.66.202:0] [client 216.244.66.202] ModSecurity: Access denied with code 510 (phase 2). Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/etc/modsecurity/01_hs/bad-user-agents.conf"] [line "6"] [id "0999998"] [msg "BAD BOT - Detected and Blocked."] [severity "CRITICAL"] [hostname "www.carusoworld.ch"] [uri "/robots.txt"] [unique_id "Zqq8DjQ4PNfXd9g0uBO1LAAAALI"]
2024/08/01 00:35:20 [error] 368044#368044: *90065445 access forbidden by rule, client: 156.59.198.136, server: carusoworld.ch, request: "GET /gallery/_data/i/galleries/Urlaub/Toscana2011/Toscana2011_005-me.jpg HTTP/2.0", host: "www.carusoworld.ch"
2024/08/01 00:35:20 [error] 368044#368044: *90065445 access forbidden by rule, client: 156.59.198.136, server: carusoworld.ch, request: "GET /gallery/_data/i/galleries/Urlaub/Toscana2011/Toscana2011_005-me.jpg HTTP/2.0", host: "www.carusoworld.ch"
[Thu Aug 01 00:35:38.064412 2024] [:error] [pid 4181572] [client 31.10.148.81:0] [client 31.10.148.81] ModSecurity: Access denied with code 403 (phase 2). Match of "eq 1" against "&SESSION:pwg" required. [file "/etc/modsecurity/02_comodo/30_Apps_OtherApps.conf"] [line "6284"] [id "241783"] [rev "2"] [msg "COMODO WAF: CSRF vulnerability in Piwigo before 2.6.2 (CVE-2014-4614)||carusoworld.ch|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "carusoworld.ch"] [uri "/gallery/ws.php"] [unique_id "Zqq8Oi@1JM0GuldzHR0GRAAAACs"], referer: https://carusoworld.ch/gallery/index.php?/category/327
[Thu Aug 01 00:35:41.203640 2024] [:error] [pid 4181566] [client 31.10.148.81:0] [client 31.10.148.81] ModSecurity: Access denied with code 403 (phase 2). Match of "eq 1" against "&SESSION:pwg" required. [file "/etc/modsecurity/02_comodo/30_Apps_OtherApps.conf"] [line "6284"] [id "241783"] [rev "2"] [msg "COMODO WAF: CSRF vulnerability in Piwigo before 2.6.2 (CVE-2014-4614)||carusoworld.ch|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "carusoworld.ch"] [uri "/gallery/ws.php"] [unique_id "Zqq8PfPyfeYxbeYJqLJvDAAAACQ"], referer: https://carusoworld.ch/gallery/index.php?/category/327
[Thu Aug 01 00:35:44.459457 2024] [:error] [pid 4181687] [client 31.10.148.81:0] [client 31.10.148.81] ModSecurity: Access denied with code 403 (phase 2). Match of "eq 1" against "&SESSION:pwg" required. [file "/etc/modsecurity/02_comodo/30_Apps_OtherApps.conf"] [line "6284"] [id "241783"] [rev "2"] [msg "COMODO WAF: CSRF vulnerability in Piwigo before 2.6.2 (CVE-2014-4614)||carusoworld.ch|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "carusoworld.ch"] [uri "/gallery/ws.php"] [unique_id "Zqq8QFlKchLyeLUgT6Z8PgAAAFE"], referer: https://carusoworld.ch/gallery/index.php?/category/327
[Thu Aug 01 00:35:46.057466 2024] [:error] [pid 4181662] [client 31.10.148.81:0] [client 31.10.148.81] ModSecurity: Access denied with code 403 (phase 2). Match of "eq 1" against "&SESSION:pwg" required. [file "/etc/modsecurity/02_comodo/30_Apps_OtherApps.conf"] [line "6284"] [id "241783"] [rev "2"] [msg "COMODO WAF: CSRF vulnerability in Piwigo before 2.6.2 (CVE-2014-4614)||carusoworld.ch|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "carusoworld.ch"] [uri "/gallery/ws.php"] [unique_id "Zqq8Qn53KjiCYI8a8NHCcgAAAEQ"], referer: https://carusoworld.ch/gallery/index.php?/category/327
2024/08/01 00:35:46 [error] 368029#368029: *90066019 access forbidden by rule, client: 47.128.58.203, server: carusoworld.ch, request: "GET /gallery/picture.php?/10147/categories/created-weekly-list-2015-23 HTTP/2.0", host: "www.carusoworld.ch"
2024/08/01 00:35:46 [error] 368029#368029: *90066019 access forbidden by rule, client: 47.128.58.203, server: carusoworld.ch, request: "GET /gallery/picture.php?/10147/categories/created-weekly-list-2015-23 HTTP/2.0", host: "www.carusoworld.ch"
Here are two lines concerning the album with the white page, but they don't look much different to the other error lines:
2024/08/01 02:24:38 [error] 368064#368064: *90220436 access forbidden by rule, client: 114.119.154.237, server: carusoworld.ch, request: "GET /gallery/index.php?/category/221/created-monthly-list-any HTTP/1.1", host: "www.carusoworld.ch", referrer: "https://www.carusoworld.ch/gallery/index.php?%2Fcategory%2F221%2Fcreated-monthly-list-any%2Fstart-15"
2024/08/01 02:24:38 [error] 368064#368064: *90220436 access forbidden by rule, client: 114.119.154.237, server: carusoworld.ch, request: "GET /gallery/index.php?/category/221/created-monthly-list-any HTTP/1.1", host: "www.carusoworld.ch", referrer: "https://www.carusoworld.ch/gallery/index.php?%2Fcategory%2F221%2Fcreated-monthly-list-any%2Fstart-15"
Does this help?
Offline
Lots of 403 from your security restrictions. Nothing stands out for the blank page to me.
Normally you should `tail -f *.log` while hitting the page that is causing the problem.
Offline
Thank you for looking through the error log.
Do you mean that when trying to access the album with white page, it should show up in the error log? I would have expected so and just tried again - but nothing.
What had the expected time stamp, was a server error that there is no index.html or similar on my server - which is correct due to problems with my provider. I'm going to fix this now and maybe this resolves all the 403 errors.
Offline
Seeing all that ModSecurity fubar that might as well be the cause of trouble. It says
"COMODO WAF: CSRF vulnerability in Piwigo before 2.6.2 (CVE-2014-4614)"
so if you are indeed still using a version <2.6.2 then do yourself a favour and manually upgrade. If you are running a later version then talk to your hoster and tell them that's a false positive and they should loosen that rule.
See also [Forum, post 164282 by cally6008 in topic 26634] Can't upload any images after update to 2.8.1, gets stuck uploading and following.
Offline
erAck wrote:
Seeing all that ModSecurity fubar that might as well be the cause of trouble. It says
"COMODO WAF: CSRF vulnerability in Piwigo before 2.6.2 (CVE-2014-4614)"
so if you are indeed still using a version <2.6.2 then do yourself a favour and manually upgrade. If you are running a later version then talk to your hoster and tell them that's a false positive and they should loosen that rule.
Thank you. I'm running Piwigo 14.5.0. I wrote to my hoster and asked about this. I only got one response, but none to my second message. I asked again today.
erAck wrote:
See also [Forum, post 164282 by cally6008 in topic 26634] Can't upload any images after update to 2.8.1, gets stuck uploading and following.
Thank you. I turned off ModSecurity for a few seconds and turned it on again. Nothing changed. I asked my hoster about the security rules (they mentioned it in their answer), but this domain only has one rule that has some numbers as name, while my other domain has the same rule plus one other. I hope I will get an answer from my hoster.
I uploaded new photographs to Piwigo today and tried some other ideas. This is what I found out (helpful or not):
- This is the album that shows a blank page: gallery/index.php?/category/221. The admin page for this album also shows a blank page (when logged in as admin) gallery/admin.php?page=batch_manager&filter=album-221.
- From the admin panel, I can access the subalbums and their photographs. I can edit subalbums, images and upload new images. So it's only this album on the highest level that shows a blank page.
- All other albums on the highest level are shown correctly. I was able to create a new album on highest level and add images.
- I can edit the title of album-221 or the description, the album still shows a blank page.
- I uploaded an image directly to that album-221, it is shown in the admin panel ("1 image and x albums"), but I can't see it because of the blank page.
- The album-221 was not closed, but I found that - whyever - all subalbums were set to "closed". I changed all subalbums, but the album itself still shows the blank page.
- I don't know why, but I'm able to edit the albums through the edit button on the album page (not in the admin panel). I got an error message for about a year now, only "fast edit" worked since then. I still got that error message last week after re-installing Piwigo, but it works today :D
I will report as soon as I hear back from my hoster.
Offline
my problem is resolved. Eventually it was caused by the error 'Fatal error: Allowed memory size of 134217728 bytes exhausted' I just followed a old post https://piwigo.org/forum/viewtopic.php?id=27887 increased default memory, then all problem is all gone! Thanks for forums!
Offline
Note you can set a topic to resolved by clicking the cog wheel on your first post of a topic and then Set this topic as resolved. I just did that here for you.
Offline