Demo Discussion
Forum Config Examples Contributions Vulnerabilities
  Discussion forum about ELOG, Page 752 of 806  Not logged in ELOG logo
    icon2.gif   Re: Change / List Change doen't work anymore?, posted by Harry Martin on Tue Dec 1 02:12:14 2020 
[quote="Stefan Ritt"][quote="Holger Mundhahs"]Hello @all,

I'm not sure if this is a bug, but after upgradeing from 2.7.0 to 2.7.7 the Change <attribute> and List Change <attribute> doesn't work anymore. In my
    icon2.gif   Re: Change / List Change doen't work anymore?, posted by Harry Martin on Tue Dec 1 02:39:45 2020 
[quote="Harry Martin"][quote="Stefan Ritt"][quote="Holger Mundhahs"]Hello @all,

I'm not sure if this is a bug, but after upgradeing from 2.7.0 to 2.7.7 the Change <attribute> and List Change <attribute> doesn't work anymore. In my
    icon2.gif   Re: Change / List Change doen't work anymore?, posted by Andreas Luedeke on Tue Dec 1 22:57:25 2020 
[quote="Harry Martin"][quote="Harry Martin"][quote="Stefan Ritt"][quote="Holger Mundhahs"]Hello @all,

I'm not sure if this is a bug, but after upgradeing from 2.7.0 to 2.7.7 the Change <attribute> and List Change <attribute> doesn't work anymore. In my
    icon2.gif   Re: Change / List Change doen't work anymore?, posted by Harry Martin on Wed Dec 2 00:43:31 2020 
[quote="Andreas Luedeke"][quote="Harry Martin"][quote="Harry Martin"][quote="Stefan Ritt"][quote="Holger Mundhahs"]Hello @all,

I'm not sure if this is a bug, but after upgradeing from 2.7.0 to 2.7.7 the Change <attribute> and List Change <attribute> doesn't work anymore. In my
    icon2.gif   Re: Change / List Change doen't work anymore?, posted by Stefan Ritt on Wed Dec 2 11:51:24 2020 
Yepp, the documentation was wrong. I fixed it.

Stefan
    icon2.gif   Re: Change / List Change doen't work anymore?, posted by Harry Martin on Thu Dec 3 01:53:59 2020 
[quote="Stefan Ritt"]Yepp, the documentation was wrong. I fixed it.

Stefan[/quote]
    icon2.gif   Re: Path disclosure on unfound file, posted by prinnydood on Thu Dec 31 18:35:19 2020 no_extension.pngnonexistent_html.pngrandom_extension.pngvalid_html_file_with_html_extension.png
I can confirm this issue exists on version 3.1.3, which I have installed elog on Debian 10.

The issue also exists on version 3.14 (1.20190113git283534d97d5a.el7), which I tested on an AmazonLinux EC2 instance.

This is what I found:
    icon2.gif   Re: Path disclosure on unfound file, posted by Stefan Ritt on Fri Jan 8 13:47:14 2021 Screenshot_2021-01-08_at_13.46.02_.png
Ok, I fixed the code in the current commit (395e101add19f0fe8a11a25d0822e511f34d94d1). The path gets stripped, and we see a






prinnydood
ELOG V3.1.5-3fb85fa6