eXtplorer - PHP-based File Manager: Issueshttps://extplorer.net/https://extplorer.net/favicon.ico?16960560042024-01-11T13:42:12ZeXtplorer - a PHP-based File Manager
Redmine Fehler #390 (Neu): XSS Hack is' nun veröffentlichthttps://extplorer.net/issues/3902024-01-11T13:42:12ZRalf Römling
<p>Moin Sören, der Hack, der auf Github seit 05.2023 gärt hat nu' eine CVE<br /><a class="external" href="https://vuldb.com/?id.248026">https://vuldb.com/?id.248026</a></p> Fehler #361 (Neu): Watchful Malware Scanner Errorshttps://extplorer.net/issues/3612019-12-26T15:41:05ZJeff Borellidomains@cpointcc.com
<p>I am using Watchful.net site scanner tool. All my sites with eXtplorer have these same errors in the malware scanner.</p>
<p>/administrator/components/com_extplorer/index.php header( 'HTTP/1.0 404 Not Found'); header( 'Locat Possible PHP injection (redirect)<br />/administrator/components/com_extplorer/libraries/Text/Diff/ThreeWay.php assert( assert()<br />/administrator/components/com_extplorer/libraries/Text/Diff/Mapped.php assert( assert()<br />/administrator/components/com_extplorer/libraries/Text/Diff/Engine/shell.php assert( assert()<br />/administrator/components/com_extplorer/libraries/Text/Diff/Engine/native.php assert( assert()<br />/administrator/components/com_extplorer/libraries/Text/Diff.php assert( assert()<br />/administrator/components/com_extplorer/libraries/HTTP/WebDAV/Server/Filesystem.php popen("file -i '$fspath' 2>/dev/null", "r"); $rep Possible PHP Injection (Unix command)</p> Fehler #333 (Gelöst): webdav display UPPER/CASE/FULL/PATH with some webdav clienthttps://extplorer.net/issues/3332016-11-10T13:38:33ZDaniel Roche
<p>Hello,</p>
<p>when accessing to extplorer by webdav the files and directory are displayed in upper case and with the full path.</p>
<p>it happen only with some linux client : <br /> - nemo ( cinnamon desktop )<br /> - thunar ( xfce desktop )</p>
<p>it does not happen with cadaver CLI tools, nor with windows explorer<br />( i haven't tested unity/ubuntu nor gnome/nautilus )</p>
<p>i guess this behavior shows because theses tools are displaying the displayname property <br />instead of the path .</p>
<p>however, it seems quite easy to fix :</p>
<pre><code>in libraries/HTTP/WebDAV/Server/Filesystem.php<br /> replace ( line 215 )</code></pre>
<pre><code>$info["props"][] = $this->mkprop("displayname", strtoupper($path));</code></pre>
<pre><code>by </code></pre>
<pre><code>$info["props"][] = $this->mkprop("displayname", basename($path));</code></pre>
<p>and folders and files are properly displayed.<br />i have tested ok with : <br />- windows explorer<br />- thunar<br />- nemo<br />- cadaver<br />- macOS finder</p>
<p>Best regards</p> Fehler #206 (Neu): View only - Not downloadhttps://extplorer.net/issues/2062016-08-01T21:23:04ZLe Bon Yvan
<p>Ability to view only but not to download</p> Unterstützung #192 (Neu): Watchful.li - Malware Scan Returning Error On 2 eXtplorer fileshttps://extplorer.net/issues/1922015-09-06T19:10:15ZYaani-Mai Gaddyyaanimai@gmail.com
<p>Hi I am using Watchful.li to monotor several Joomla 1.5, 2.5 & 3.4 websites.</p>
<p>It has a Malware scan where (described as "detects malware signatures, deep level scan that detects malware signatures in the file system of the website")</p>
<p>After teh Malware scan it returns 2 "Files to check" with the following info</p>
<p>Path: /administrator/components/com_extplorer/index.php <br />Pattern: header( 'Location: <a class="external" href="http://'.$_SERVER['HTTP_HOST']">http://'.$_SERVER['HTTP_HOST']</a>)<br />Reason: Possible PHP injection (redirect)</p>
<p>Path: /administrator/components/com_extplorer/libraries/HTTP/WebDAV/Server/Filesystem.php<br />Pattern: popen("file -i '$fspath' 2>/dev/null", "r")<br />Reason: Possible PHP Injection (Unix command)</p>
<p>Can you please let me know if code in these files are secure & the Watchful.li Malware Scan is just being over cautious.</p>
<p>I am using extplorer version 2.1.7</p>
<p>Thank you for taking a look at this!</p> Fehler #179 (Neu): Users Home directory - security issue.https://extplorer.net/issues/1792015-01-09T16:32:05ZJulianno Nogueirajulianno@netvolt.com.br
<p>Good Afternoon,</p>
<p>I have installed eXtplorer version <strong>2.1.6</strong> and I found an issue that I need your help in order to fix this security hole.</p>
<p><strong>When the issue happen:</strong><br />1 - Using an admin account, create a subfolder in the root folder (any name);<br />2 - Create a new user, and select his "Home directory" as the new created above;<br />3 - Now, delete de new created folder that was set to the new user (using admin account still)<br />4 - Login with the new user and get access to the entire public_html folder!</p>
<p>Are you able to help me to identify where can I insert a folder lookup for each user, and if that folder does not exist, set the User Home directory to some "custom" folder?</p>
<p>Thank you in advance.</p> Fehler #166 (Neu): What version do we need for Joomla 3?https://extplorer.net/issues/1662014-07-17T21:34:12ZMike Pricemike@optimized-computer-services.com
<p>We currently have a Joomla 2.5 website using 2.1.0</p>
<p>What version do we need for Joomla 3?</p>
<p>Thanks,</p>
<p>Mike</p> Fehler #143 (Neu): The Rename functionality needs cleaned up.https://extplorer.net/issues/1432013-09-08T02:33:38ZMichael Franekmike.franek@gmail.com
<p>Simply setup a "user" that only has view only permissions. Login as this user and navigate to a file.</p>
<p>Rename that file. A dialog box will say:<br />"You are not allowed to use this function." which is expected, however the name of the file remains "changed" at least until the screen is refreshed in some fashion.</p>
<p>This give the impression that the file truly was renamed, when it wasn't.</p> Fehler #50 (Neu): Symlinks issuehttps://extplorer.net/issues/502011-11-28T02:59:41Zkorun kenercagecicigec@fastmail.fm
<p>Hi</p>
<p>Thanks for this great software. It seems to work fine except using with symlinks on Linux. Basically if a folder is based on a symlink there is no way to see the contents of the folder. Although it expands the folders in the tree view(no visible files). Basically double clicking on the folder name that is a symlink yields to no visible result in the browsing area(just expands in the treeview), which is not usable for browsing or looking at files.</p>
<p>thanks</p> Feature #44 (Neu): toolbarhttps://extplorer.net/issues/442011-10-21T14:43:14Zajowan lechienajowan@live.com
<p>hi,</p>
<p>how to disable certain functionalities in the toolbar ?</p>
<p>thx,</p> Fehler #41 (Neu): UTF-8 encoding d'nt work.https://extplorer.net/issues/412011-10-07T07:32:21ZWladyslaw Polinskijwp_hedgehog@bk.ru
<p>Hi!</p>
<p>For a long time I'm looking for normal File Manager to my D-Link DNS-323.</p>
<p>All tested is uncorrectly work with russian (Cyrillic) file names.</p>
<p>As a result I found next - some application on some device (or platform) cannot correctly autodetect actual internal code page.</p>
<pre><code>Midnight Commander (for example) must be recompile with follow manuall correction in lib before build:</code></pre>
<p>1. in file /lib/strutil/strutil.c<br /> string <br /><code>return (nl_langinfo (CODESET));</code><br /> must be replaced on<br /><code>return "UTF8";</code></p>
<p>2. in file /lib/tty/tty-slang.c (S-Lang lib reqired)<br /> in string<br /><code>SLutf8_enable (-1);</code><br /> remove "minus" <br /><code>SLutf8_enable (1);</code></p>
<p>I'm test all release of eXtplorer (2.1.0 RC3/RC4/RC5) and in all cases I have received follow:</p> Fehler #32 (Neu): umask in SSH sessions is hard codedhttps://extplorer.net/issues/322011-09-02T21:24:43ZShahar Ormightyiampresence@gmail.com
<p>Using the SSH login method files are created in umask 0022. This, in my case, is not the logged in user's umask.</p>
<p>Setting a umask would be an essential feature in eXtplorer - especially in non-SSH logins. I think that until then it should use the user's default umask in SSH logins.</p>
<p>Or is the umask in SSH sessions determined by somewhere else in the stack, like PHP?</p> Fehler #22 (Neu): Unlink and Permissions problemhttps://extplorer.net/issues/222011-07-08T22:14:55ZGuillermo Marcoguillermo.marco@gmail.com
<p>I'm getting this error after install.. it seems like a permission isue. Currently running Debian Squeeze.</p>
<p>Warning: unlink(/var/www/acceso_ftp/scripts.tar.gz) [function.unlink]: Permission denied in /var/www/acceso_ftp/libraries/standalone.php on line 388</p> Fehler #14 (Neu): UT8 encoding don't workhttps://extplorer.net/issues/142011-05-28T17:18:18ZMartin C.changer4@hotmail.com
<p>Hi,</p>
<p>i like extplorer with the usability and how it looks like. But i can't use it :(<br />Some folders with special chars like ü, ö, ä aren't displayed correctly.</p>
<p>I tried to remove utf8 encoding like suggested in this forum:<br /><a class="external" href="http://www.synology-forum.de/showthread.html?3785-3rd-Party-eXtplorer-Umlaute&p=24067#post24067">http://www.synology-forum.de/showthread.html?3785-3rd-Party-eXtplorer-Umlaute&p=24067#post24067</a><br />(<- Note: Use translator to get in english)</p>
<p>'Bücher' is displayed to 'B?'<br />and<br />'Urlaub - Ausflüge - Besuch' => 'Urlaub - Ausflg00650020002d0020Besuch'</p>
<p>Hope this information helps to fix the problem.<br />Let me know, if problem is solved, so i can start using this great tool.</p> Fehler #6 (Neu): Uploads don't work in IE8https://extplorer.net/issues/62011-03-28T15:19:38ZKlaus Ederhax@gmx.at
<p>The Upload Window in IE 8 doesn't show.</p>
<p>Looks like this: <a class="external" href="http://jing.hax.at/2011-03-28_1719.png">http://jing.hax.at/2011-03-28_1719.png</a></p>
<p>Error: <a class="external" href="http://jing.hax.at/2011-03-28_1708.png">http://jing.hax.at/2011-03-28_1708.png</a></p>