PHP Web Host - Quality Web Hosting For All PHP Applications Clan Themes! We make clans look good!!
  Login or Register
 • Home • Downloads • Your Account • Forums • 

View next topic
View previous topic


Google
 
Web RavenPHPScripts (This Site)
This forum is locked: you cannot post, reply to, or edit topics.   This topic is locked: you cannot edit posts or make replies.
Author Message
LostGhost
New Member
New Member


Joined: Mar 29, 2004
Posts: 5

PostPosted: Mon Mar 29, 2004 2:05 pm Reply with quote Back to top

Every time someone uses an apostrophe when posting a news story / review / etc, nuke appears to be inserting a \.

So (for example) if they were to submit the word don't, it would be changed to don\'t


Please help as this is driving me mad.

As this is happening everywhere that someone can submit to the site I assume this is being caused by one of the core pages.
View user's profile Send private message
Raven
Site Admin/Owner


Joined: Aug 27, 2002
Posts: 16987
Location: Kansas

PostPosted: Mon Mar 29, 2004 2:25 pm Reply with quote Back to top

That is a security precaution. addslashes() is the function and prevents XSS attacks. The data should be stored in the database but the stripped out with stripslashes() before being displayed. Are you saying that it is actually displaying the \' in your news article? If so, this is not the behavior of the native News module. have you applied any code changes to your News module?
View user's profile Send private message Visit poster's website AIM Address Yahoo Messenger
LostGhost
New Member
New Member


Joined: Mar 29, 2004
Posts: 5

PostPosted: Mon Mar 29, 2004 2:45 pm Reply with quote Back to top

Thats exactly what I'm saying, and I haven't made any changes to the native News module (though I have edited some of the others).

However, this problem isn't confined to News.

It happens in every module people can submit (i.e. reviews, comments in Coppermine, etc.).

Thats why I presumed there was something missing from one of the core files. Does the stripslash appear in something like mainfile.php ?


Last edited by LostGhost on Mon Mar 29, 2004 3:07 pm; edited 1 time in total
View user's profile Send private message
Raven
Site Admin/Owner


Joined: Aug 27, 2002
Posts: 16987
Location: Kansas

PostPosted: Mon Mar 29, 2004 2:54 pm Reply with quote Back to top

Just for curiosity, run phpinfo() and check this setting:
magic_quotes_gpc
Is it set to On or Off?
View user's profile Send private message Visit poster's website AIM Address Yahoo Messenger
LostGhost
New Member
New Member


Joined: Mar 29, 2004
Posts: 5

PostPosted: Mon Mar 29, 2004 3:08 pm Reply with quote Back to top

magic_quotes_gpc On

magic_quotes_runtime Off

magic_quotes_sybase Off
View user's profile Send private message
Raven
Site Admin/Owner


Joined: Aug 27, 2002
Posts: 16987
Location: Kansas

PostPosted: Mon Mar 29, 2004 3:12 pm Reply with quote Back to top

If you have not made any changes at all, then I would suggest reuploading all files, as a first step. What version of nuke and MySQL are you using?
View user's profile Send private message Visit poster's website AIM Address Yahoo Messenger
LostGhost
New Member
New Member


Joined: Mar 29, 2004
Posts: 5

PostPosted: Mon Mar 29, 2004 3:23 pm Reply with quote Back to top

As per title, it is Nuke 7.0

I downloaded it from the club when it first became available, although I only started noticing the / problem after installing Coppermine (but it could have been there before).

I have been applying security patches and fixes as they became available, so I am rather loath to over-write everything by uploading the files. Would I be better off upgrading to 7.1 or 7.2?

It is running on MySQL 4.0.18-standard
View user's profile Send private message
Raven
Site Admin/Owner


Joined: Aug 27, 2002
Posts: 16987
Location: Kansas

PostPosted: Mon Mar 29, 2004 3:26 pm Reply with quote Back to top

7.2 for sure. Coppermine is wrecking some havoc right now on many sites so I would be suspicious ....
View user's profile Send private message Visit poster's website AIM Address Yahoo Messenger
LostGhost
New Member
New Member


Joined: Mar 29, 2004
Posts: 5

PostPosted: Mon Mar 29, 2004 4:05 pm Reply with quote Back to top

OK I'll get 7.2 Final and try updating to that.

I'll let you know how I get on.

Thanks for your help.
View user's profile Send private message
Display posts from previous:       
This forum is locked: you cannot post, reply to, or edit topics.   This topic is locked: you cannot edit posts or make replies.

View next topic
View previous topic
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
Forums ©
 

All logos and trademarks in this site are property of their respective owner.
The comments are property of their posters, all the rest © 2002-2011 by Raven

You can syndicate our news using the file xml

CSE HTML Validator Helped Clean up This Page! [Valid RSS] valid RSS 2.0 Valid robots.txt Stop Spam Harvesters, Join Project Honey Pot

Website engines core code is © copyright by PHP-Nuke but has been heavily patched and modified by myself and others.
PHP-Nuke is a free software released under the GNU/GPL.


:: fisubice phpbb2 style by Daz :: PHP-Nuke theme by www.nukemods.com ::
:: fisubice Theme Modified by the RavenNuke™ Team ::

:: W3C CSS Compliance Validation :: W3C HTML 4.01 Transitional Compliance Validation ::

zerosum