2 patrick Jan 06, 2005 22:14

I'm still using 0.8.7, and don't have that section in _class_itemlist.php - am I ok?
I *think* 0.8.7 did not have ant $title handling, so you *might* be okay. But there is no way I can guarantee anything about old releases like 0.8.7 .
Ok, thanks Francoise. I added the title handling myself, so I'll take the risk.
Greets - I just checked the relevant file for this bug and found it to exist. I am currently running v9.10.0.
Note that this is not the most recent exploit. I'd patched this a while back, but was recently exploited - see [url=http://www.greenman.co.za/b2evolution/blogs/index.php?p=130&more=1&c=1&tb=1&pb=1]my blog post about the exploit[/url].
providing your logs to francois would be the thing to do.. BUT, fyi, the screenshot you have of the b2evolution website having "lost its skin" .. I see that ALOT here because the server seems to slow down, and the stylesheet doesnt get rendered ... not seeing a particular style isnt an accurate indication of an exploit.
Like I said, sending an email to francois with your apache logs and as much other info as you can provide (times etc..) would certainly go further than one post here as francois will probably see his email before he comes here.
I wont even ask why you posted on your blog about this 3 days before your post here .. Ill just assume you have already contacted francois and leave well enough alone. Cant fix it if they dont know its broke :(
Hi whoo
I have been in contact with Francois, and he's sure there was no exploit of the actual b2evolution site, so it must just have been a style sheet issue, as you mention.
yeap greenman, I read his reply on your blog regarding this domain. Im still not sure about what happened to your own blog, but thats not for me to wonder, I reckon.
Hello all. In my conditions [url=http://sugarcult-ticket.monforum.com/index.php]:([/url] I have to use 0.8.7 release. What can i do in this case except b2evolution updating? Sorry if my question looks like quesion of stupid man. But I have to
This file is in b2evocore folder ;)