LxCenter HyperVM & Kloxo Support

Forum



Members   Search      Help    Register    Login    Home
Home » Archive » Kloxo Bug Report » File system access bug?(Unprotected file system access?)
File system access bug? [message #76653] Sat, 04 September 2010 16:24 Go to next message
frogstarr78 is currently offline frogstarr78  United States
Messages: 25
Registered: June 2010
Member
In helping a customer who was attempting to access a file outside of the admin home directory, I was initially unable to get access to the directory using Kloxo's File Manager. However, the customer, unaware of how they got it to work initially, provided me with this working favorited url (I've changed the vm name):

https://example.com:7777/display.php?frm_action=show&frm _o_o [0][class]=pserver&frm_o_o[0][nname]=localhost&frm_o _o[1][class]=ffile&frm_o_o[1][nname]=/opt/railo/tomcat/c onf/

Should this work?
Re: File system access bug? [message #76717 is a reply to message #76653] Tue, 07 September 2010 22:27 Go to previous message
Walter  Brazil
Messages: 866
Registered: February 2009
Location: Florianopolis / BR
Senior Master
Forum Moderator
LxCenter Project Manager

I'm not sure if it's a bug or a feature. Wink

This is only possible when the user is logged in as "admin" (equivalent to root).

Log in as a normal customer/client/reseller and try to access data outside their home directory in the same manner.

If you manage to do that, please fill a bug report at http://project.lxcenter.org with a high priority.

Previous Topic:Cant login to RoundCube and Horde
Next Topic:I can't access kloxo
Goto Forum:
  


Current Time: Wed Jun 19 12:12:26 EDT 2013

Total time taken to generate the page: 0.01029 seconds
.:: Contact :: Home :: Privacy ::.

Click here to lend your support to: LxCenter and make a donation at www.pledgie.com !

Powered by: FUDforum 3.0.2.
Copyright ©2001-2010 FUDforum Bulletin Board Software