events 1.3 beta security update

For all Non-Joomla! security issues. ie 3pd Components etc.

Moderator: General Support Moderators

Forum rules
Locked
User avatar
Geraint
Joomla! Guru
Joomla! Guru
Posts: 561
Joined: Fri Aug 19, 2005 5:23 pm
Location: Gogledd Cymru

events 1.3 beta security update

Post by Geraint » Wed Jul 26, 2006 8:30 pm

All users of Events 1.3 beta should upgrade to the latest beta available at : http://forge.joomla.org/sf/go/rel4213 or make the change highlighted in the news item on the project homepage at the forge.

User avatar
Hal
Joomla! Apprentice
Joomla! Apprentice
Posts: 30
Joined: Fri Aug 19, 2005 11:24 pm
Location: Duisburg / Germany
Contact:

Re: events 1.3 beta security update

Post by Hal » Thu Jul 27, 2006 12:21 am

Thank you for good work. Is there a potential security issue for the modules?

User avatar
Geraint
Joomla! Guru
Joomla! Guru
Posts: 561
Joined: Fri Aug 19, 2005 5:23 pm
Location: Gogledd Cymru

Re: events 1.3 beta security update

Post by Geraint » Thu Jul 27, 2006 6:46 am

None that we know of (and specifically not the direct access hole)

We will be releasing a full set of release candidate files in the next week or two with updated modules.

Geraint

tijs
Joomla! Enthusiast
Joomla! Enthusiast
Posts: 109
Joined: Mon Aug 29, 2005 7:59 pm

Re: events 1.3 beta security update

Post by tijs » Wed Aug 16, 2006 9:37 am

So just to be sure: if I manually add
defined( '_VALID_MOS' ) or die( 'Direct Access to this location is not allowed.' );
in administrator/components/com_events/admin.events.php I should be OK?

I've got three sites with the component and I'd rather just add this line than going through the hassle of uninstalling and installing again, especially because it seems I risk losing my events data while upgrading?

richm
Joomla! Intern
Joomla! Intern
Posts: 50
Joined: Sun Nov 20, 2005 9:05 pm

Re: events 1.3 beta security update

Post by richm » Fri Sep 01, 2006 4:47 am

I manually made the fix and it worked.  Before that, I tried uninstalling 1.3 and installing 1.3 beta2a, but it caused my Attend Events component to stop working.

User avatar
Geraint
Joomla! Guru
Joomla! Guru
Posts: 561
Joined: Fri Aug 19, 2005 5:23 pm
Location: Gogledd Cymru

Re: events 1.3 beta security update

Post by Geraint » Fri Sep 01, 2006 8:24 am

I'd not heard of "Attend Events" before - thanks for bringing it to our attention.

latristesse
Joomla! Explorer
Joomla! Explorer
Posts: 270
Joined: Mon Dec 12, 2005 9:59 pm

Re: events 1.3 beta security update

Post by latristesse » Fri Sep 01, 2006 3:32 pm

I'm still on Events 1.2 - is there any way to get up to this version without uninstalling, reinstalling, and therefore losing all one's data?  If not, what is the best way for me to migrate my data over?

User avatar
Geraint
Joomla! Guru
Joomla! Guru
Posts: 561
Joined: Fri Aug 19, 2005 5:23 pm
Location: Gogledd Cymru

Re: events 1.3 beta security update

Post by Geraint » Fri Sep 01, 2006 4:24 pm

Take a look at

http://forge.joomla.org/sf/projects/jevents

It explaions how to upgrade without lossing your existing data.  Remember to use the beta2 and follow the instructions carefully.

Geraint

stpbccom
Joomla! Fledgling
Joomla! Fledgling
Posts: 1
Joined: Tue Sep 12, 2006 8:30 pm

Re: events 1.3 beta security update

Post by stpbccom » Tue Sep 12, 2006 10:17 pm

I just downloaded 1.3b from 1.1. I am trying to get the frontend publishing to work. I have installed and it still does not allow adding of events from the frontend by administrators and/or publishers. Do you have any ideas?

stpbccom....

User avatar
kittymcooper
Joomla! Apprentice
Joomla! Apprentice
Posts: 31
Joined: Thu Aug 03, 2006 7:29 pm
Location: Fort Collins, CO, USA
Contact:

Re: events 1.3 beta security update

Post by kittymcooper » Fri Jun 29, 2007 11:26 pm

Where do I find this upgrade? All the URLs in this thread are broken and when I go to http://forge.joomla.org/ and try to look at projects I get this:

JoomlaCode Home »
Configuration error: Host name (forge.joomla.org) differs from system configuration (joomlacode.org)

User avatar
sc00zy
Joomla! Exemplar
Joomla! Exemplar
Posts: 9532
Joined: Thu Aug 18, 2005 9:07 am
Location: Assen, Netherlands
Contact:

Re: events 1.3 beta security update

Post by sc00zy » Thu Aug 23, 2007 9:42 am

kittymcooper wrote: Where do I find this upgrade? All the URLs in this thread are broken and when I go to http://forge.joomla.org/ and try to look at projects I get this:

JoomlaCode Home »
Configuration error: Host name (forge.joomla.org) differs from system configuration (joomlacode.org)
http://joomlacode.org/gf/project/jevents/
Arjan Menger
https://welldotcom.nl - Puntgaaf Internetbureau

User avatar
Geraint
Joomla! Guru
Joomla! Guru
Posts: 561
Joined: Fri Aug 19, 2005 5:23 pm
Location: Gogledd Cymru

Re: events 1.3 beta security update

Post by Geraint » Thu Aug 23, 2007 10:30 am

You should use JEvents 1.4.2 - see http://joomlacode.org/gf/project/jevents

karryberry
I've been banned!
Posts: 21
Joined: Wed Dec 19, 2007 10:36 pm

Re: events 1.3 beta security update

Post by karryberry » Thu Dec 20, 2007 4:52 pm

Hal wrote: Thank you for good work. Is there a potential security issue for the modules?
if the answer is no, then why the big hurry to update?
smile

chsajid11
Joomla! Apprentice
Joomla! Apprentice
Posts: 5
Joined: Wed May 28, 2008 4:08 pm
Contact:

Re: events 1.3 beta security update

Post by chsajid11 » Wed May 28, 2008 4:41 pm

same question as kerryberry asked... please update.


Locked

Return to “3rd Party/Non Joomla! Security Issues”