HTTP 500 error

Phoca Guestbook - creating guestbooks in Joomla! CMS
nl1bzw
Phoca Member
Phoca Member
Posts: 31
Joined: 31 Jan 2008, 20:09

Can you tell me what

Post by nl1bzw »

Can you tell me what changed between version 1.2.0 and 1.2.1?

Thanks already
User avatar
Jan
Phoca Hero
Phoca Hero
Posts: 49138
Joined: 10 Nov 2007, 18:23
Location: Czech Republic
Contact:

There was a security

Post by Jan »

There was a security fix. Protection against XSS (there is a library called html purifier) which cleans 'dangerous scripts' from strings...

There is some error on your site in this library ...

Jan
If you find Phoca extensions useful, please support the project
nl1bzw
Phoca Member
Phoca Member
Posts: 31
Joined: 31 Jan 2008, 20:09

Re: HTTP 500 error

Post by nl1bzw »

Hi Jan,

I tried it even with the new version, but i still get the same error. So i will send you my FTP info and joomla info in a PM. Hope you can find the problem.

Thanks already.
User avatar
Jan
Phoca Hero
Phoca Hero
Posts: 49138
Joined: 10 Nov 2007, 18:23
Location: Czech Republic
Contact:

Re: HTTP 500 error

Post by Jan »

Hi, in your administrator area, there is all right with guestbook, in frontend too, I left an message in guestbook, everything works ok ...
If you find Phoca extensions useful, please support the project
nl1bzw
Phoca Member
Phoca Member
Posts: 31
Joined: 31 Jan 2008, 20:09

Re: HTTP 500 error

Post by nl1bzw »

That's because i'm still running version 1.2.0 Beta. If i upgrade to any version above version 1.2.0 it doesn't work anymore.

Try for yourself and install the latest phoca guestbook :) Then i get the HTTP 500 error.
User avatar
Jan
Phoca Hero
Phoca Hero
Posts: 49138
Joined: 10 Nov 2007, 18:23
Location: Czech Republic
Contact:

Re: HTTP 500 error

Post by Jan »

so please install the 1.3.1 and let me know login, password into the pm

Jan
If you find Phoca extensions useful, please support the project
nl1bzw
Phoca Member
Phoca Member
Posts: 31
Joined: 31 Jan 2008, 20:09

Re: HTTP 500 error

Post by nl1bzw »

Done, and thanks already.
User avatar
Jan
Phoca Hero
Phoca Hero
Posts: 49138
Joined: 10 Nov 2007, 18:23
Location: Czech Republic
Contact:

Re: HTTP 500 error

Post by Jan »

The problem is here:

Fatal error: Call to undefined function ctype_lower() in ...components/com_phocaguestbook/assets/library/HTMLPurifier/Token.php on line 70

:( The HTML purifier is an external library which check the strings against XSS attacks becasue there is still some problem in Joomla! with clean method :-(

I cannot say what can be the problem because it is an external script :-(

I think your php server doesn't have inmplemented the Ctype functions :-(

http://cz.php.net/manual/en/ref.ctype.php

Jan
If you find Phoca extensions useful, please support the project
nl1bzw
Phoca Member
Phoca Member
Posts: 31
Joined: 31 Jan 2008, 20:09

Re: HTTP 500 error

Post by nl1bzw »

On the website it's written:

In PHP versions before 4.4.1, ctype functions have a bug handling very large integers.
http://bugs.php.net/bug.php?id=34645

But my ISP is using 5.2.4-pl2-gentoo.

Shouldn't it be solved in this PHP version?
nl1bzw
Phoca Member
Phoca Member
Posts: 31
Joined: 31 Jan 2008, 20:09

Re: HTTP 500 error

Post by nl1bzw »

I found something:

'./configure' '--prefix=/usr/lib/php5' '--host=i686-pc-linux-gnu' '--mandir=/usr/lib/php5/man' '--infodir=/usr/lib/php5/info' '--sysconfdir=/etc' '--cache-file=./config.cache' '--enable-maintainer-zts' '--disable-cli' '--with-apxs2=/usr/sbin/apxs2' '--with-config-file-path=/etc/php/apache2-php5' '--with-config-file-scan-dir=/etc/php/apache2-php5/ext-active' '--without-pear' '--disable-bcmath' '--without-bz2' '--disable-calendar' '--disable-ctype' '--with-curl' '--without-curlwrappers' '--disable-dbase' '--disable-exif' '--without-fbsql' '--without-fdftk' '--disable-filter' '--disable-ftp' '--with-gettext' '--without-gmp' '--disable-hash' '--disable-json' '--without-kerberos' '--enable-mbstring' '--with-mcrypt' '--without-mhash' '--without-msql' '--without-mssql' '--with-ncurses' '--with-openssl' '--with-openssl-dir=/usr' '--disable-pcntl' '--disable-pdo' '--without-pgsql' '--without-pspell' '--without-recode' '--disable-simplexml' '--disable-shmop' '--with-snmp' '--disable-soap' '--disable-sockets' '--without-sybase' '--without-sybase-ct' '--disable-sysvmsg' '--disable-sysvsem' '--disable-sysvshm' '--without-tidy' '--disable-tokenizer' '--disable-wddx' '--disable-xmlreader' '--disable-xmlwriter' '--without-xmlrpc' '--without-xsl' '--disable-zip' '--with-zlib' '--disable-debug' '--enable-dba' '--without-cdb' '--with-db4' '--without-flatfile' '--with-gdbm' '--without-inifile' '--without-qdbm' '--without-freetype-dir' '--without-t1lib' '--disable-gd-jis-conv' '--with-jpeg-dir=/usr' '--with-png-dir=/usr' '--without-xpm-dir' '--with-gd' '--with-imap' '--with-imap-ssl' '--with-ldap' '--without-ldap-sasl' '--with-mysql=/usr' '--with-mysql-sock=/var/run/mysqld/mysqld.sock' '--without-mysqli' '--with-readline' '--without-libedit' '--without-mm' '--without-sqlite'

It's written disabled ctype. So that's the problem i guess?
Post Reply