vBulletin Search Engine Optimization
This is a discussion on Security issue with filevbseo_getsitemap.php within the Bug Reporting forums, part of the vBSEO Google/Yahoo Sitemap category; Hi, When the filevbseo_getsitemap.php is called without arguments it supplies a list of files in the directory where it's installed. ...
| |||||||
Enhancing 80 million pages. | Register | FAQ | Members List | Social Groups | Calendar | Search | Today's Posts | Mark Forums Read |
|
#1
| |||
| |||
| Security issue with filevbseo_getsitemap.php
Hi, When the filevbseo_getsitemap.php is called without arguments it supplies a list of files in the directory where it's installed. This is a security risk. Please fix this ASAP. I am a bit concerned: why haven't you already tested this obvious test-case ? At present, I don't have a complete understanding of VBSEO sitemaps and this is why I am asking you: why do you need this file in the first place ? You could generate the files in some folder then just instruct the user to put a line in "robots.txt", a line that will tell all robots where is the file located: Sitemap: http://www.test.eu/some-folder/sitemap_index.xml.gz What is wrong with this approach ? This second option looks like a better incarnation of the KISS principle. Regards, Razvan Last edited by mihai11; 11-05-2008 at 11:57 AM. Reason: typo |
|
#2
| ||||
| ||||
|
Hello, vbseo_getsitemap.php never provides a directory listing, you can check it here: http://www.vbseo.com/vbseo_sitemap/vbseo_getsitemap.php Quote:
__________________ Oleg Ignatiuk / Crawlability Inc. Support Team Launches New DeskPro Powered Tool Enhanced Support at Your Service vBSEO 3.2.0 Launched - Maximum Overdrive for Your Web Traffic! Over 100 Instant SEO Optimizations 6X Traffic - $1400 in One Day with vBSEO! Imagine What the vBSEO Patent Pending Technology Can Do For You. |
|
#3
| |||
| |||
| Quote:
Note: I am using the latest version of sitemaps. I will open a support ticket and I will provide all the relevant details there. |
|
#4
| ||||
| ||||
|
It might be related to the server settings, let's see in the ticket.
__________________ Oleg Ignatiuk / Crawlability Inc. Support Team Launches New DeskPro Powered Tool Enhanced Support at Your Service vBSEO 3.2.0 Launched - Maximum Overdrive for Your Web Traffic! Over 100 Instant SEO Optimizations 6X Traffic - $1400 in One Day with vBSEO! Imagine What the vBSEO Patent Pending Technology Can Do For You. |
| Thread Tools | |
| |
Similar Threads | ||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| security? | sde | General Discussion | 8 | 07-18-2006 11:44 PM |