Sign In  |  Register
 
 DotNetNuke Powered!
DotNetNuke Support Forums

Warning! Allowing portal admins to do Skin Upload can be a security risk

Rate this topic:

Please Register to post a reply.
Another benefit of registration is the ability to subscribe to and recieve notifications of new posts.

AuthorMessages
John Mitchell
Posts:3085



03/07/2007 3:51 PM  

Warning!  Please be advised of what you are doing when giving permission for portal administrators to upload skins. Warning! 

This ability allows any of your administrators to upload server-side code, and there is no security checking of the uploaded skins.

If you do not explicitly trust the people with administrator privledges to have the same rights as a Host / SuperUser then you should not enable portals to upload skins.

If you are the only one running the site and all the portals then you should log in as Host / SuperUser and you will then be able to upload skins.

This is not new and has been around with DNN since skinning was introduced, but I often see posts like this one:
http://www.dotnetnuke.com/Community/ForumsDotNetNuke/tabid/795/mid/2108/threadid/113340/scope/posts/Default.aspx#113585
Where users are just told to turn on this feature, without any warning.

Here's another related thread:
http://forums.asp.net/thread/879684.aspx

 

Please Register to post a reply.
Another benefit of registration is the ability to subscribe to and recieve notifications of new posts.

Forums >DotNetNuke Support >Tips-And-Tricks > Warning! Allowing portal admins to do Skin Upload can be a security risk



ActiveForums 3.7
Visit our Store for great DotNetNuke Modules and Skins
DNNMasters Sitemap/Google Sitemap 3.0

Item codeSM3-01
Price$29.00
Product Information 
DotNetNuke CSS NavMenu 3.3 (Developers)

Item codeCSSNM33DEV
Base Price$149.00
Product Information 
Snapsis PageBlaster 3.3.2 for DotNetNuke - Professional Edition

AuthorJohn Mitchell
Base Price$79.00
Product Information