Announcement

Collapse
No announcement yet.

.PHP uploaded to "signaturepics" directory

Collapse
X
 
  • Filter
  • Time
  • Show
Clear All
new posts

  • ElForro
    replied
    But if i move the directories below my public_html, I would need to make an alias or something like that in order to access the images, right?

    So, they would still be able to upload a PHP file to that directory? Is this a bug in VBulletin?

    Leave a comment:


  • peterska2
    replied
    You can change them if you so wish. The locations of the directories are changed at the discretion of the administrator.

    Leave a comment:


  • ElForro
    replied
    Thanks... Should I change also the other directories? I mean: "customavatars" and "customprofilepics"? I want to be sure they can't upload a PHP anymore to any folder...

    Leave a comment:


  • peterska2
    replied
    Move the signaturepics directory to below your public_html directory. Then go to

    AdminCP > Avatars > User Picture Storage Type

    Update the path for signtuare pictures to point to the new directory location and the relative URL to the new location.

    Leave a comment:


  • ElForro
    started a topic .PHP uploaded to "signaturepics" directory

    .PHP uploaded to "signaturepics" directory

    Somehow, someone managed to upload a .PHP file to the "signaturepics" directory in my VB 3.6.9 installation.

    With that, he also could change my index.php

    I would like to know how can I protect against this type of things, and if it's a bug, it has been solved in the new versions of VB? (I'm using 3.6.9)

    Thanks

Related Topics

Collapse

Working...
X