Archives

You are currently browsing the Programming category.
Subscribe (RSS).

Rounded corners with jquery

Everybody loves rounded corners in a web page but it’s a hassle to accomplish, multiple divs and different images aligned in the corret way. I’ gonna show you how to do it with just a couple lines of javascript using the jquery framework. (more…)

Security issues in WP Forum fixed

All security issues in this report is fixed.

New version is 1.7.6

Excerpt from the report

Description:
Some vulnerabilities have been discovered in the WP-Forum plugin for WordPress, which can be exploited by malicious users to conduct script insertion attacks, and by malicious people to conduct cross-site scripting and SQL injection attacks.

1) Input passed to the “user” parameter in the WordPress installation’s index.php script (when “forumaction” is set to “showprofile” and “page_id” to a page with the “” tag) is not properly sanitised before being used in SQL queries. This can be exploited to manipulate SQL queries by injecting arbitrary SQL code.

Successful exploitation of this vulnerability allows e.g. retrieving usernames, password hashes, and e-mail addresses for all users and administrators, but requires knowledge of the database table prefix.

2) Input passed to the “forum_query” parameter in the WordPress installation’s index.php script (when “forumaction” is set to “search”) is not properly sanitised before being returned to the user. This can be exploited to execute arbitrary HTML and script code in a user’s browser session in context of an affected site.

Successful exploitation of this vulnerability requires that the target user has valid user credentials.

3) Input passed to the “forumtext” parameter in the WordPress installation’s index.php script (when “forumaction” is set to “post”) is not properly sanitised before being stored. This can be exploited to insert arbitrary HTML and script code, which is executed in a user’s browser session in context of an affected site when the malicious data is viewed.

Successful exploitation of this vulnerability requires that the attacker has valid user credentials.

The vulnerabilities are confirmed in version 1.7.4. Other versions may also be affected.

Solution:
Edit the source code to ensure that input is properly sanitised.

Provided and/or discovered by:
1) websec Team
2, 3) FeDeReR and sinner_01

Ajax tutorial

This tutorial is intended to give the reader some initial understanding of the power of using Ajax as a tool on a web page. The web pages are growing larger and larger due to more and more bandwidth around the globe.

This is nice since the web is getting more readable and more visual appealing. But if your web host have a traffic limit per day the size of the total files requested by each visitor becomes critical, at least if you have many visitors.
(more…)

WordPress image gallery fGallery released

My new WordPress plug in announced in the previous article is now released and the corresponding page with download can be found here.

WordPress image gallery plugin on the way

iI’m about to finish a new image gallery plugin with a lot of features such as:

  • Direct upload from WordPress admin.
  • Language selection.
  • Images ordered by albums and with the ability to exclude images from an album without deleting it.
  • Easy managment of images and albums from the WordPress admin interface.
  • Edit CSS in the WordPress admin, resetting CSS if something went wrong.
  • Support for gettext, which means that you can generate your own language files with gettext.
  • Swedish and english languages included.

Update 1: Russian translation.

Update 2: I have set up is a small demo of the galleries, you can watch it here.

Next Page »

car insurance quotes. рулетка и оазис покер