• twitter image
  • facebook image
  • youtube image
  • linkedin image
Language: CMS Made Simple Czech CMS Made Simple France CMS Made Simple Spain CMS Made Simple Hungary CMS Made Simple Russia CMS Made Simple Netherlands

All times are UTC




Post new topic Reply to topic  [ 7 posts ] 
Author Message
 Post subject: Awesome customized website for non - profit organization
PostPosted: Thu Sep 22, 2011 4:58 am 
Offline
Forum Members
Forum Members

Joined: Mon Nov 01, 2010 7:04 pm
Posts: 48
http://www.gmhi.org/

All of the content is easily editable through cmsms. Most tags of each type have been styled to make adding content in a manner that looks consistent a breeze. The gallery also using the gallery template allows for adding a new image to the slider along with new text a breeze.

Let me know what you guys think.

By the way, I encourage all of you readers to donate. They are doing really good things for those in need.

These are the modules in use.

CGSimpleSmarty
1.4.8

Gallery
1.4.4

CGExtensions
1.26.3

FormBuilder
0.7

CGBlog
1.7.5


Top
 Profile  
 
 Post subject: Re: Awesome customized website for non - profit organization
PostPosted: Sun Oct 02, 2011 3:47 pm 
Offline
Forum Members
Forum Members

Joined: Mon Nov 01, 2010 7:04 pm
Posts: 48
I added a bit more polish to it.

Let me know what you guys think


Top
 Profile  
 
 Post subject: Re: Awesome customized website for non - profit organization
PostPosted: Wed Oct 12, 2011 6:11 am 
Offline
Forum Members
Forum Members

Joined: Mon Aug 13, 2007 11:15 am
Posts: 39
Location: Israel
nyandres,
FormBuilder is vulnerable to XSS attacks.

You must fix this problem in FormBuilder's templates or not use FormBuilder at all, because the default settings are highly unsafe.

A nice little demo on request.

Best regards,
David


Top
 Profile  
 
 Post subject: Re: Awesome customized website for non - profit organization
PostPosted: Wed Oct 12, 2011 11:08 am 
Offline
Power Poster
Power Poster
User avatar

Joined: Sat Nov 14, 2009 4:54 pm
Posts: 703
Location: the Netherlands
dwave wrote:
the default settings are highly unsafe.

Care to explain?

_________________
Make your community a better place!


Top
 Profile  
 
 Post subject: Re: Awesome customized website for non - profit organization
PostPosted: Wed Oct 12, 2011 11:50 am 
Offline
Forum Members
Forum Members

Joined: Mon Aug 13, 2007 11:15 am
Posts: 39
Location: Israel
Sure.

Almost every variable in the Submission template of the default template set is unsafe and susceptible to Cross Site Scripting attacks.

The fix would be not to echo any user variables at all or to sanitize them first with PHP's strip_tags. And don't use Smarty's strip_tags, it's broken and also unsafe.

POC:
Code:
http://[domain].[tld]/index.php?mact=FormBuilder,cntnt01,default,0&cntnt01returnid=68&cntnt01fbrp_callcount=1&cntnt01form_id=5&cntnt01fbrp_continue=2&cntnt01fbrp_done=1&cntnt01fbrp__39=&lt;h1&gt;&lt;xss3&cntnt01fbrp__40=2&cntnt01fbrp__41=nil&cntnt01fbrp__42=nil&cntnt01fbrp__43=your@email.com&cntnt01fbrp__44=00000&cntnt01fbrp__47=<body+onload=alert(document.cookie);cntnt01fbrp_submit=Sent


You'll have to adjust your variable names accordingly. You understand that I cannot post a working proof of concept here, but you get the idea.


Top
 Profile  
 
 Post subject: Re: Awesome customized website for non - profit organization
PostPosted: Thu Apr 19, 2012 9:57 am 
Offline
Dev Team Member
Dev Team Member
User avatar

Joined: Fri Nov 30, 2007 9:15 am
Posts: 329
Hi Dwave,

So using "pretty URL's" would be secure?

pretty URL ex:
"http://www.domain.com/contact-us/"
After submitting the form the URL stays the same

ps: don't think this matters but no information the user submitted is being shown on the form result page.

Greetings,
Manuel


Top
 Profile  
 
 Post subject: Re: Awesome customized website for non - profit organization
PostPosted: Thu Apr 19, 2012 12:26 pm 
Offline
Forum Members
Forum Members

Joined: Wed Aug 06, 2008 10:48 pm
Posts: 66
Hi,
Nice site, but I can't use the Contact link in the main menu in the index page, it is in a second line behind the slider. I can use it in the ohter pages even though still appears in a second line .

I use a resolution of 1280x800 and FF.

All the best.
A.


Attachments:
noContact.png
noContact.png [ 186.87 KiB | Viewed 925 times ]
Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 7 posts ] 

All times are UTC


Who is online

Users browsing this forum: No registered users


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
A2 Hosting