Quantcast
Channel: PKP Community Forum - Latest topics
Viewing all articles
Browse latest Browse all 27290

Hacked 'public' dir, not 'files' using tiny_mce

$
0
0

@ztajoli wrote:

Hi,
I find my server with same ‘hack’ uploaded using tyny_mce library.
Without login they can uploads files inside public/site/images/
They used those calls:
POST /lib/pkp/lib/tinymce/jscripts/tiny_mce/plugins/jbimages/ci/index.php/upload/%7B HTTP/1.1" 200
POST /lib/pkp/lib/tinymce/jscripts/tiny_mce/plugins/jbimages/ci/index.php/upload/english HTTP/1.1" 200

The dir public/site/images is write-able by www-data.

I use OJS 2.4.8

Is it possible to do something ?
Bye
Zeno Tajoli

Posts: 4

Participants: 2

Read full topic


Viewing all articles
Browse latest Browse all 27290

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>