Print Page | Close Window

Whats new in 7.91?

Printed From: Web Wiz Forums
Category: Web Wiz Web App Support Forums
Forum Name: Web Wiz Forums
Forum Description: Support forum for Web Wiz Forums application.
URL: https://forums.webwiz.net/forum_posts.asp?TID=15346
Printed Date: 13 April 2026 at 7:10am
Software Version: Web Wiz Forums 12.08 - https://www.webwizforums.com


Topic: Whats new in 7.91?
Posted By: chong67
Subject: Whats new in 7.91?
Date Posted: 02 June 2005 at 3:31pm
Whats new in 7.91?

Is it worth the upgrade from 7.9?
 



Replies:
Posted By: dj air
Date Posted: 02 June 2005 at 6:11pm
there was an XSS hack on the forum a couple days ago, but as i was online i managed to hide it from forum view, thats why not many know about it.

it just prevents another XSS hacking method. its only one file updated (functions_filters.asp).

just update that and your done.


Posted By: chong67
Date Posted: 02 June 2005 at 10:03pm
Oh boy.  I better do that tomorrow.
 
Thanks!


Posted By: felix.akinyemi
Date Posted: 03 June 2005 at 6:21am
There should be a zip file with just the file that need to be updated, saves people redownloadin the whole software again!!


Posted By: dj air
Date Posted: 03 June 2005 at 6:24am
it might be an idea, of course boRg's the one to decide that.




Posted By: Kostya
Date Posted: 03 June 2005 at 8:26am
Maybe you have the file
 
I fuld like to update too


-------------
Kostya Programmer


Posted By: dj air
Date Posted: 03 June 2005 at 9:55am
un the licence agreement we are not allowed to do so,

if you download the latest version all you have to do is update the functions/functions_filters.asp


Posted By: evilpeppard
Date Posted: 04 June 2005 at 1:50pm
Thanks for the info.  I updated the functions/functions_filters.asp file and presume I am good to go?

My version still shows 7.9, not 7.91.  Is that ok?


Posted By: dj air
Date Posted: 05 June 2005 at 7:03am
yes thats fine, the only way to change that is to upload the common.asp file.


Posted By: JohnKn
Date Posted: 05 June 2005 at 10:29am
Should the /admin/functions version of the file be replaced also? In the zip archive that version is still the old one from 2003.


Posted By: NeutralizeR
Date Posted: 06 June 2005 at 3:49pm
I've upgraded my v7.9 forum to v7.91... (actually, i've only uploaded the new functions_filter.asp)
 
And now... I've got this
 
<LINK href="includes/default_style.css" type=text/css rel=stylesheet>
 
in all new posts...
 
What's wrong ?


-------------

http://www.MsXLabs.com">


Posted By: NeutralizeR
Date Posted: 07 June 2005 at 10:09am

Anyone else who has the same problem here ?

I'm still waiting for an answer. Because i can't upgrade my forum to v7.91 and i don't feel good when there is a bug in my forum...Ouch


-------------

http://www.MsXLabs.com">


Posted By: NeutralizeR
Date Posted: 09 June 2005 at 8:36am
*******************RTE_textbox.asp file****************
<html>
<head>

     

<!--#include file="includes/skin_file.asp" -->
 
<%
If RTEenabled = "Gecko" Then
 
 Response.Write(vbCrLf & "<script language=""javascript"">" & _
 vbCrLf & " <!--" & _
 vbCrLf & " function enableDesignMode() {" & _
  vbCrLf & " document.designMode = ""on""" & _
 vbCrLf & " }" & _
 vbCrLf & "-->" & _
 vbCrLf & "</script>")
End If
%>
</head>

***************************************************
If i remove the red line in RTE_textbox.asp file, the problem goes away...
 
But the default_style.css isn't applied...
 
I can't add any html code between <head> and </head> in RTE_textbox.asp file...
 
What should i do ?
 
Borg Confused


-------------

http://www.MsXLabs.com">


Posted By: WebWiz-Bruce
Date Posted: 09 June 2005 at 9:43am
Sounds like you have a corrupted file somewhere, reupload all the original files from 7.91, just keep your original database.

-------------
https://www.webwiz.net/web-wiz-forums/forum-hosting.htm" rel="nofollow - Web Wiz Forums Hosting
https://www.webwiz.net/web-hosting/windows-web-hosting.htm" rel="nofollow - ASP.NET Web Hosting


Posted By: pjb007
Date Posted: 10 June 2005 at 9:25am
Originally posted by evilpeppard evilpeppard wrote:

Thanks for the info.  I updated the functions/functions_filters.asp file and presume I am good to go?

My version still shows 7.9, not 7.91.  Is that ok?
 
I have the same thing but.........
 
I downloaded the new software and uploaded all the files, the forum is now working, but I have 7.9 showing as the version and when I go into 'Check for Updates' it tells me to download 7.91 as I uploaded all the files not just the changed file does this mean that my update has not worked?


Posted By: NeutralizeR
Date Posted: 10 June 2005 at 1:13pm
I've fixed the error.
 
There was <body onmouseover="window.status='.:: [MsX©] Labs. HQ ~ http://www.MsXLabs.com - www.MsXLabs.com ::.'; return true;" onmouseout="window.status=''; return true;"> code in common.asp file.
 
I moved this code to header.asp and the problem is OK!
 
Thanks! Embarrassed


-------------

http://www.MsXLabs.com">


Posted By: WebWiz-Bruce
Date Posted: 10 June 2005 at 5:05pm
This site has nothing to do with the URL you have posted so I can't see how or why you would get that line unless you have modified the files.

-------------
https://www.webwiz.net/web-wiz-forums/forum-hosting.htm" rel="nofollow - Web Wiz Forums Hosting
https://www.webwiz.net/web-hosting/windows-web-hosting.htm" rel="nofollow - ASP.NET Web Hosting


Posted By: pjb007
Date Posted: 15 June 2005 at 11:54am
Sorry to post this again but I downloaded all of the software when I read about the update and uploaded everything, the forum is working but says version 9.7, when I click the 'Check for Updates' it tells me to download 9.71 as I uploaded all the files not just the changed file does this mean that my update has not worked?


Posted By: WebWiz-Bruce
Date Posted: 15 June 2005 at 12:14pm
No, sorry it looks like I forgot to update the version number in the file 'admin/common.asp'

-------------
https://www.webwiz.net/web-wiz-forums/forum-hosting.htm" rel="nofollow - Web Wiz Forums Hosting
https://www.webwiz.net/web-hosting/windows-web-hosting.htm" rel="nofollow - ASP.NET Web Hosting


Posted By: pjb007
Date Posted: 15 June 2005 at 12:19pm
Is it OK to change
 
'Intialise variables
Const strVersion = "7.9" to
 
'Intialise variables
Const strVersion = "7.91"
 
then


Posted By: NeutralizeR
Date Posted: 15 June 2005 at 3:22pm
Yes, it's enough...
 
Change them both in
 
admin\common.asp
 
&
 
common.asp files...


-------------

http://www.MsXLabs.com">


Posted By: theSCIENTIST
Date Posted: 18 June 2005 at 3:06am
So what have they done?
Injection with the style tag?

That's the only line I see added in new (functions_filters.asp).

If you prefer not to talk about it, I understand, sometimes it's better that way.

-------------
:: http://www.mylittlehost.com/ - www.mylittlehost.com


Posted By: WebWiz-Bruce
Date Posted: 18 June 2005 at 4:41am
Basically browsers allow you to place CSS styles within a page just using:-

<style> CSS here </style>

The problem with this is that the CSS is not actually within HTML tags eg < > so is hard to filter.

Anyway, some annoying idiot discovered that you can use this to change the back ground image using CSS. This wouldn't be so bad, but the person who discovered this linked to a background image that said 'This forum has been hacked!!'.

So it's not really a major security problem and it's quite simple to just delete the post, the problem was it took me the best part of a day to work out how to prevent it without removing legitimate 'Style' tags for things like font colours etc.


-------------
https://www.webwiz.net/web-wiz-forums/forum-hosting.htm" rel="nofollow - Web Wiz Forums Hosting
https://www.webwiz.net/web-hosting/windows-web-hosting.htm" rel="nofollow - ASP.NET Web Hosting



Print Page | Close Window

Forum Software by Web Wiz Forums® version 12.08 - https://www.webwizforums.com
Copyright ©2001-2026 Web Wiz Ltd. - https://www.webwiz.net