Print

Official files on SourceForge:
https://sourceforge.net/project/showfiles.php?group_id=64258&package_id=112134external link

Tiki 1.9.10.1 (a quickfix of never released 1.9.10) was released by Louis-Philippe Huberdeau and Marc Laporte on 2008-02-23.

Compared to 1.9.9, this release contains 78 code commits by franck, lphuberdeau, luciash, marclaporte, mose, nkoth and sylvieg from 2007-12-22 to 2008-02-23.

The main purposes of this release are:
  1. Fix bugs introduced in 1.9.9
  2. Deal with a Cross Site Scriptingexternal link (XSS) vulnerability reported by Fortify Softwareexternal link.
  3. Make TikiWiki more secure against future potential vulnerabilities (hardened TikiWiki)

Regression bugs introduced in 1.9.10.1 (which were ok in 1.9.9)


(07:01:41) peter__: Hello
(07:03:16) peter__: Just installed Tikiwiki and now have the problem that the registration code as image does not show up (tiki-random_number). Any suggestions?
(07:04:35) sylvieg: check you have imagick or gd installed
(07:05:32) peter__: gd is installed and for example pictures are shown in galleries.
(07:17:38) marclaporte: peter__: which version?
(07:17:55) marclaporte: I saw a bug fix to that file recently (dunno if related)
(07:29:47) lphuberdeau_: problem introduced in 1.9.10 or 1.9.10.1 with the additional checks
(07:30:06) lphuberdeau_: fix is in CVS, was waiting for more reports before making an other release
(07:32:51) lphuberdeau_: tiki-login_validate.php and tiki-random_num_img.php were modified since the release
(07:33:58) marclaporte: you can get them here: http://tikiwiki.cvs.sourceforge.net/tikiwiki/tiki/?pathrev=BRANCH-1-9
(08:29:06) peter__: lphuberdeau_: Thanks for the hint!
(08:39:48) peter__: Report: tiki-login_validate.php and tiki-random_num_img.php from CVS fixed the problem with the registration code image. Thanks.


This was a bug introduced while making Tiki more secure (a little too secure in this casesmile). Below are the tweaks needed to be done to 1.9.10.1:

http://tikiwiki.cvs.sourceforge.net/tikiwiki/tiki/tiki-login_validate.php?r1=1.9.2.10&r2=1.9.2.11&pathrev=BRANCH-1-9external link
http://tikiwiki.cvs.sourceforge.net/tikiwiki/tiki/tiki-random_num_img.php?r1=1.5.2.3&r2=1.5.2.4&pathrev=BRANCH-1-9external link


Security

  • Improving input sanitizer. Thank you to Fortify softwareexternal link for reporting a cross-site scripting (XSS) vulnerability in tiki-edit_article.php.
    Note: Until you upgrade, workaround is to not permit non-trusted users to add/edit articles, or to deactivate the articles feature altogether.
  • New pre-emptive securitycheck.php script. This check, which is now part of the release procedures, checks every single potentially dangerous file (.php, .sh, etc) to make sure it follows some basic checks (such as: a feature check, permission check, verify that it can't be called directly if it shouldn't, etc.). If you are not using feature X you will no longer potentially be affected in a security issue which is discovered in a feature using that file. If you are using that feature, you can turn it off until you upgrade.
  • Adding feature and permission checks to all files to comply with the securitycheck.php script described above.
  • Developer scripts now have extra protection to make sure they can't be run from the web (on a badly configured server).
  • Some useless files were deleted.

Fixes

  • Fix a username/password/registration bug issue which was introduced in 1.9.9.
  • Image Gallery: Fixed the next-prev glitch which was introduced recently.
  • Various fixes to Live Support feature.
  • Various fixes to InterTiki feature
  • Forums: Prevent forum pruning from removing comments as well, or from other forums.
  • Fixes to "thumbnail" plugin

Enhancements

  • Better handling of usernames with special characters
  • tiki-contact.php has anti-bot protection
  • Some administrative fixes and enhancements to the release, security and developer scripts.
  • New "superscript" plugin to make easy superscript in wiki page, without using html, like subscript plugin.


Full Changelog

For all changes, see: http://tikiwiki.org/changelogexternal link


Contributors to this page: marclaporte6182 points  and ricks991878 points  .
Page last modified on Thursday 28 February, 2008 15:56:12 CET by marclaporte6182 points .

Search Wiki PageName [toggle]

What theme do you use the most? [toggle]

To help determine the themes to include in the next Tiki release, please indicate what theme you now use (or use most). (Login necessary to vote.)

What theme do you use?
  • Bluegreen
  • Boreal
  • Codex
  • Damian
  • Dblue
  • Default
  • Elegant
  • Fmsc
  • Gemsi
  • Geo
  • Hec
  • Jalist
  • Lesjetesdelencre
  • Moreneat
  • Mose
  • Mozilla
  • Neat
  • Olive
  • Simple
  • Smartiki
  • Subsilver
  • Tceti
  • Tikigod
  • Tikineat
  • Tranquil
  • Trollparty
  • Whitebluegrey
  • (Other)
View Results
(Votes: 44)
Cookies must be allowed to vote

Menu [toggle]

Chatroom [toggle]

Click here to login to the TikiWiki IRC chatroom


Pop ups must be allowed by your browser.

Shoutbox [toggle]

Darkbee46 points : Apparently there was a power outage that caused some down-time.
Darkbee46 points : Has there been problems with the tikiwiki.org site? I haven't been able to get on all morning.
amateurathlete5 points : I have 1.9.10.1 now, should I bother upgrading to 1.9.11 before 2.0 is officially released?
Darkbee46 points : Have I missed an announcement about 1.10 becoming 2.0?
Frodoger2 points : twversion.class.php how to disable? Our tikiwiki don#t has internet access
CodyLoco23 points : @marclaporte: Is this a finished feature in 1.10? I'm running 1.10 on my site: www.clipsharewiki.com
marclaporte6182 points : CodyLoco: coming soon (1.10), yes
Oswaldo19651 points :
Oswaldo19651 points : I get this error, help The XML page cannot be displayed. Cannot view XML input using XSL style sheet. Please correct the error and then click the Refresh button, or try again later.
Oswaldo19651 points : i get this error, 2nd part. Only one top level element is allowed in an XML document. Error processing resource '[Link] Undefined variable: categories in /data/16/1/35/106/1524595/
Powered by Tikiwiki Powered by PHP Powered by Smarty Powered by ADOdb Made with CSS Powered by RDF powered by The PHP Layers Menu System
RSS feed Wiki RSS feed Blogs RSS feed Articles RSS feed File Galleries RSS feed Forums RSS feed Directories