Demo Discussion
Forum Config Examples Contributions Vulnerabilities
  Discussion forum about ELOG, Page 375 of 808  Not logged in ELOG logo
    icon2.gif   Re: Permission on reply, posted by Stefan Ritt on Fri Jan 30 09:30:35 2015 
You can use the switches

Alloe reply = <user list>

Deny reply = <user list>
    icon2.gif   Re: Permission on reply, posted by Banata Wachid Ridwan on Wed Feb 4 09:48:32 2015 
so let say I just want to add certain members for replying logbook, so I just need to add parameter Allow reply = <user list>

and automatically all members not listed will be forbidden, am I correct?

I dont need to specify members for "Deny Reply" right ?
    icon2.gif   Re: Permission on reply, posted by David Pilgram on Wed Feb 4 10:33:16 2015 
Hi Banata,

If you only have a few people who can reply, then use

Allow reply = <user list>
    icon2.gif   Re: Periodic backup doesn't work .., posted by Roland Gsell on Tue Jun 12 10:38:34 2012 
The synchronize feature is totally worthless to me.
First of all the automatic backup doesn't work - and nobody seems to know why - and pressing the synchronize button by hand from time to time also
doesn't work if the entry is too big: 
    icon2.gif   Re: Path disclosure on unfound file, posted by Stefan Ritt on Wed Jun 10 09:12:06 2015 Screen_Shot_2015-06-10_at_9.11.38_.png
What URL did you use? If I try here on this forum I get:



which looks fine to me.
    icon2.gif   Re: Path disclosure on unfound file, posted by Travis Unkel on Fri Aug 18 01:02:41 2017 
I am having the same issue. If you go to midas.psi.ch/elogs/12345.htm you get the path disclosure issue.

 




Stefan
    icon2.gif   Re: Path disclosure on unfound file, posted by prinnydood on Thu Dec 31 18:35:19 2020 no_extension.pngnonexistent_html.pngrandom_extension.pngvalid_html_file_with_html_extension.png
I can confirm this issue exists on version 3.1.3, which I have installed elog on Debian 10.

The issue also exists on version 3.14 (1.20190113git283534d97d5a.el7), which I tested on an AmazonLinux EC2 instance.

This is what I found:
    icon2.gif   Re: Path disclosure on unfound file, posted by Stefan Ritt on Fri Jan 8 13:47:14 2021 Screenshot_2021-01-08_at_13.46.02_.png
Ok, I fixed the code in the current commit (395e101add19f0fe8a11a25d0822e511f34d94d1). The path gets stripped, and we see a






prinnydood
ELOG V3.1.5-3fb85fa6