« archives

January 2007
S M T W T F S
« Dec   Feb »
 123456
78910111213
14151617181920
21222324252627
28293031  

recently

news from around the web

» view all

Important Zenphoto 1.0.7 Release

January 27th 2007

Zenphoto 1.0.7 has been released tonight with one small change — an important security fix for a problem with upwards directory traversal using “..” as the album name. I’ve simply filtered it out (in two places) and it shouldn’t be a problem again. Thanks to nicosomb for reporting this on the forums.

Everyone using any previous version should upgrade as soon as possible, though no need to worry — there’s not much risk from this bug, only the possibility of seeing folder names (and nothing else) in your web site’s directories that are accessible to your user. No files can be opened, nor any applications exploited. But upgrade anyway ;-)

More on zenphoto to come.


This entry was posted on Saturday, January 27th, 2007 at 12:08 am and is filed under zenphoto. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.


4 Responses to “Important Zenphoto 1.0.7 Release”



  1. Randy Commented at 4:44 pm on February 14th 2007

    Just to let you know, I’ve taken the text below from my blog.

    “The last couple of days I’ve been real busy with collecting and categorising new photos that will come online when the new Photogallery does. I’ve already searched the Internet for some good photogallery scripts and it’s almost for sure that I’ll go with ZenPhoto because this one looks very nice and clean and is very simple to use. I’m only waiting till they get out of beta testing so that some popular awaited features (like subalbums and spam protection on the comments) are added and the chance on errors will be smaller. I hope they will be done with this soon so that I can start using it and finally can get rid of the cluttered Coppermine Photogallery.”

    Any word yet on the “out-of-beta” version of Zenphoto? :)

    Keep up the good work! I love this little piece of software.

  2. Wouter Commented at 2:54 am on February 24th 2007

    I Just Love Zenphoto and U keeping it alive!

    Keep up the fine work mate!

  3. amin Commented at 10:57 pm on September 9th 2007

    I have a problem with i.php. Because my php GD library version is 1.6. So the thumbnail generaot is fail for generate the thnumbnail. Could you advise what to do? At least I want to subtitute it with an icon

  4. Tristan Commented at 10:59 pm on September 9th 2007

    amin - please use the support forums available at http://www.zenphoto.org/support for questions, you’ll get more help there.

    All I can say is Zenphoto requires GD version 2 and a recent version of PHP to function properly.

    Even if you fix the thumbnails, the rest of the images will not work. Please contact your host and ask them to upgrade to more modern software.

Leave a Reply

Some XHTML allowed.