vanilla-restore: category=modified-benign (79 fájl)

vhost: www.archlinexp.eu
rel_path: components/com_users/controller.php
result: quarantined
evidence_sha256: 2d0e5a25333180fc0976159ba409b32506d458b3239daa930474d8140a95bb92
timestamp: 20260718T160204Z
finding_ref: 7252

vhost: www.archlinexp.eu
rel_path: components/com_users/controllers/profile.json.php
result: quarantined
evidence_sha256: 14089aed5d01c80be03a7ff13f0b8f5b6a5fb5c37b7f8e72bf9ab98e5bbb976b
timestamp: 20260718T160204Z
finding_ref: 7257

vhost: www.archlinexp.eu
rel_path: components/com_users/controllers/profile.php
result: quarantined
evidence_sha256: 0cef6b3e5fc0304afdb0005711b02d9a39d01fee0ce14903d4312f31a2fa540b
timestamp: 20260718T160204Z
finding_ref: 7258

vhost: www.archlinexp.eu
rel_path: components/com_users/controllers/profile_base_json.php
result: quarantined
evidence_sha256: 11ec9184dddb0f201b18ec05c6a279f1d4b387813b80ed01dfe5040e00c93d4a
timestamp: 20260718T160204Z
finding_ref: 7259

vhost: www.archlinexp.eu
rel_path: components/com_users/controllers/remind.php
result: quarantined
evidence_sha256: a6ef6d7b60043fa180e39c8efce1dcff804c8c2bbfa11d4e5e4d2ca36601972d
timestamp: 20260718T160204Z
finding_ref: 7255

vhost: www.archlinexp.eu
rel_path: components/com_users/controllers/reset.php
result: quarantined
evidence_sha256: 224404ff37d78b3baf18f77b89e51e7599304b44b51fe6e4bf1ff9abf354ac0c
timestamp: 20260718T160204Z
finding_ref: 7256

vhost: www.archlinexp.eu
rel_path: components/com_users/controllers/user.php
result: quarantined
evidence_sha256: d7472a9cb222592b7799229831d00ed6e728d082fd5ed5be616404edb8ad275c
timestamp: 20260718T160204Z
finding_ref: 7254

vhost: www.archlinexp.eu
rel_path: components/com_users/helpers/html/users.php
result: quarantined
evidence_sha256: cb229ad16ba915a20aa22c49f2b5863cb4079cb5ce5fb3975b07b5caa161e786
timestamp: 20260718T160204Z
finding_ref: 7283

vhost: www.archlinexp.eu
rel_path: components/com_users/helpers/legacyrouter.php
result: quarantined
evidence_sha256: e25f6683f53657c5f1f0f03e80126eb3acbc3b270dd26f3bcd8e16fc72f72343
timestamp: 20260718T160204Z
finding_ref: 7281

vhost: www.archlinexp.eu
rel_path: components/com_users/helpers/route.php
result: quarantined
evidence_sha256: 2f2d92b287b854fc6ad31c8168badc5938e39bec1f8b6202d4df348cd23a23f0
timestamp: 20260718T160204Z
finding_ref: 7282

vhost: www.archlinexp.eu
rel_path: components/com_users/layouts/joomla/form/renderfield.php
result: quarantined
evidence_sha256: 767cc86103a71d15914e028fc231d5b48ffb5cdc5bf6ab8ecc3e22bb73d9190b
timestamp: 20260718T160204Z
finding_ref: 7284

vhost: www.archlinexp.eu
rel_path: components/com_users/models/forms/profile.xml
result: quarantined
evidence_sha256: 6f217de7628ab4c162bef301a62851bd90557bc43062783410df850901f536ba
timestamp: 20260718T160204Z
finding_ref: 7278

vhost: www.archlinexp.eu
rel_path: components/com_users/models/forms/registration.xml
result: quarantined
evidence_sha256: d8d90d9badd444b08bd7243d3621f6af3feaee137523c212b5b883883f805b7e
timestamp: 20260718T160204Z
finding_ref: 7277

vhost: www.archlinexp.eu
rel_path: components/com_users/models/login.php
result: quarantined
evidence_sha256: 1bd545c9d69235efbd0ca01aa8e3fee5c0416f9d7e57647314f029d01c7bcb75
timestamp: 20260718T160204Z
finding_ref: 7272

vhost: www.archlinexp.eu
rel_path: components/com_users/models/profile.php
result: quarantined
evidence_sha256: 9120583bc9b1fc6d5c5b7a81fdd14c2d18250715cc89c672b743038cd62f7682
timestamp: 20260718T160204Z
finding_ref: 7276

vhost: www.archlinexp.eu
rel_path: components/com_users/models/registration.php
result: quarantined
evidence_sha256: 36f98683f5d734fd65acabfd638da4bff54196ce0f4fc2574c23ab9ef9b66ba6
timestamp: 20260718T160204Z
finding_ref: 7275

vhost: www.archlinexp.eu
rel_path: components/com_users/models/remind.php
result: quarantined
evidence_sha256: 25d8b3522b7b6fc0456dda7a2cc346c94e9b3889f4180d32f3e3101998791f1a
timestamp: 20260718T160204Z
finding_ref: 7273

vhost: www.archlinexp.eu
rel_path: components/com_users/models/reset.php
result: quarantined
evidence_sha256: f948b6a494c8fe051b43bff9f12801d462e4d22f37607da2c5b3b6a7886dcd72
timestamp: 20260718T160204Z
finding_ref: 7274

vhost: www.archlinexp.eu
rel_path: components/com_users/models/rules/loginuniquefield.php
result: quarantined
evidence_sha256: 70dfe2a0662c32f12e612c1d5785006673319ec19766651ab15aefb880a2c5f2
timestamp: 20260718T160204Z
finding_ref: 7279

vhost: www.archlinexp.eu
rel_path: components/com_users/models/rules/logoutuniquefield.php
result: quarantined
evidence_sha256: 9bc602cb398ce792eafb70d3cba2fa732d6bffeb2bf88afc05de9e507334c095
timestamp: 20260718T160204Z
finding_ref: 7280

vhost: www.archlinexp.eu
rel_path: components/com_users/router.php
result: quarantined
evidence_sha256: 2b9acf14b84908cd85f8ffface816d5c7124f3226088696dccec501054773253
timestamp: 20260718T160204Z
finding_ref: 7253

vhost: www.archlinexp.eu
rel_path: components/com_users/users.php
result: quarantined
evidence_sha256: 6ed1fd07fc85fc4f09fd85926ce729ad711577f7cc3ceaf551c748b07dd2ae5c
timestamp: 20260718T160204Z
finding_ref: 7251

vhost: www.archlinexp.eu
rel_path: components/com_users/views/login/tmpl/default.php
result: quarantined
evidence_sha256: 8dac9ace51133f1eea7a524ca6dd8de9fc5effedd7c5bb2b5f5562ccd2257efc
timestamp: 20260718T160204Z
finding_ref: 7269

vhost: www.archlinexp.eu
rel_path: components/com_users/views/login/tmpl/default.xml
result: quarantined
evidence_sha256: 1e40888b8d147a0130bca03085edf7f94e97da2ed09e2aa4b6dfe41282162ecc
timestamp: 20260718T160204Z
finding_ref: 7270

vhost: www.archlinexp.eu
rel_path: components/com_users/views/login/tmpl/default_login.php
result: quarantined
evidence_sha256: f619bd9d8abc8c0b2766659057d744280be80ff87f1705b5c23c9e74a8f6d6ed
timestamp: 20260718T160204Z
finding_ref: 7271

vhost: www.archlinexp.eu
rel_path: components/com_users/views/login/tmpl/default_logout.php
result: quarantined
evidence_sha256: 17b5b52ed420d182ca4d96cdc494e204f3dfe024955ae4d91eaf68537daf1f52
timestamp: 20260718T160204Z
finding_ref: 7268

vhost: www.archlinexp.eu
rel_path: components/com_users/views/login/view.html.php
result: quarantined
evidence_sha256: 81388b133b1d59d485333ab97724d1a1d3616606f055d863da72bc0a9f0fbea3
timestamp: 20260718T160204Z
finding_ref: 7267

vhost: www.archlinexp.eu
rel_path: components/com_users/views/profile/tmpl/default.php
result: quarantined
evidence_sha256: d4133100827716d2da1eb9c60343fb744f2183367c917139a1767681ac200b17
timestamp: 20260718T160204Z
finding_ref: 7260

vhost: www.archlinexp.eu
rel_path: components/com_users/views/profile/tmpl/default_core.php
result: quarantined
evidence_sha256: dc8e27c5cf90263c3221ac79542f92ac1e7571cedaa42e6d2a9ad8d99f288765
timestamp: 20260718T160204Z
finding_ref: 7263

vhost: www.archlinexp.eu
rel_path: components/com_users/views/profile/tmpl/default_custom.php
result: quarantined
evidence_sha256: 9f2af47de5012a4c1fd0b79ff93f806b85c9c96ba7ea7132f1fb0004a1cf751f
timestamp: 20260718T160204Z
finding_ref: 7261

vhost: www.archlinexp.eu
rel_path: components/com_users/views/profile/tmpl/default_params.php
result: quarantined
evidence_sha256: b206251975c81b9896dabbdbd16f56225ed1fb582d1ae8053ce397dcbd3381f3
timestamp: 20260718T160204Z
finding_ref: 7264

vhost: www.archlinexp.eu
rel_path: components/com_users/views/registration/tmpl/default.php
result: quarantined
evidence_sha256: c362b87f0b31a19b551012f06fcde8b00d0eacda164c95a95b87f3f467426b6f
timestamp: 20260718T160204Z
finding_ref: 7265

vhost: www.archlinexp.eu
rel_path: libraries/cms/html/behavior.php
result: quarantined
evidence_sha256: b7e3e5f1cba9c986a3624ff1bd80216bc8ae36c853cbe5c2f443499db4502951
timestamp: 20260718T160204Z
finding_ref: 7201

vhost: www.archlinexp.eu
rel_path: modules/mod_al_newsletter/helper.php
result: quarantined
evidence_sha256: b7956607a80914f9937904e84970f2e1e67774f4aba36604c4be02572ed61818
timestamp: 20260718T160204Z
finding_ref: 7240

vhost: www.archlinexp.eu
rel_path: modules/mod_al_newsletter/index.html
result: quarantined
evidence_sha256: 647cde511844340d9fac1c8247d2ddbcb03c29471da015a4eaf34224a623815d
timestamp: 20260718T160204Z
finding_ref: 7238

vhost: www.archlinexp.eu
rel_path: modules/mod_al_newsletter/language/de-DE/de-DE.mod_al_newsletter.ini
result: quarantined
evidence_sha256: b4c34415a7fef19b193d8f8cde917e276ca585c5fc43b0157c5428059a8a9796
timestamp: 20260718T160204Z
finding_ref: 7245

vhost: www.archlinexp.eu
rel_path: modules/mod_al_newsletter/language/de-DE/de-DE.mod_al_newsletter.sys.ini
result: quarantined
evidence_sha256: 6aa67b1e7671a2e12d9eceea4dd8a01c9b053208d565b20ba961e0bb8a4d8793
timestamp: 20260718T160204Z
finding_ref: 7244

vhost: www.archlinexp.eu
rel_path: modules/mod_al_newsletter/language/en-GB/en-GB.mod_al_newsletter.ini
result: quarantined
evidence_sha256: 112d4cbd2f2bcc865926f7348639e346cb3d0fb8a5c3e4f005912ffa95c581d4
timestamp: 20260718T160204Z
finding_ref: 7247

vhost: www.archlinexp.eu
rel_path: modules/mod_al_newsletter/language/en-GB/en-GB.mod_al_newsletter.sys.ini
result: quarantined
evidence_sha256: 6aa67b1e7671a2e12d9eceea4dd8a01c9b053208d565b20ba961e0bb8a4d8793
timestamp: 20260718T160204Z
finding_ref: 7246

vhost: www.archlinexp.eu
rel_path: modules/mod_al_newsletter/language/hu-HU/hu-HU.mod_al_newsletter.ini
result: quarantined
evidence_sha256: 1ee232c97d9600124baa334bd87c71b5103131e6ef29bf9aa145b28aeabb6e97
timestamp: 20260718T160204Z
finding_ref: 7242

vhost: www.archlinexp.eu
rel_path: modules/mod_al_newsletter/language/hu-HU/hu-HU.mod_al_newsletter.sys.ini
result: quarantined
evidence_sha256: fe3e8aca75ff56194b30ab42b861b09a22a2ca313624d1ae62e18b10cfefd368
timestamp: 20260718T160204Z
finding_ref: 7243

vhost: www.archlinexp.eu
rel_path: modules/mod_al_newsletter/mod_al_newsletter.php
result: quarantined
evidence_sha256: 9eaa9a68edd1e4498587bcb45e83748e0644206df67207146c15db9762edd19e
timestamp: 20260718T160204Z
finding_ref: 7241

vhost: www.archlinexp.eu
rel_path: modules/mod_al_newsletter/mod_al_newsletter.xml
result: quarantined
evidence_sha256: 63093cd4600619b21a0b611c46f598ec3074df45ec183860c0ff6119897ea0ce
timestamp: 20260718T160204Z
finding_ref: 7239

vhost: www.archlinexp.eu
rel_path: modules/mod_al_newsletter/tmpl/default.php
result: quarantined
evidence_sha256: 647148d53fa91736b4f4e5afa5e5f90987320636c0e8dbf132e02af872714b6e
timestamp: 20260718T160204Z
finding_ref: 7249

vhost: www.archlinexp.eu
rel_path: modules/mod_al_newsletter/tmpl/index.html
result: quarantined
evidence_sha256: 647cde511844340d9fac1c8247d2ddbcb03c29471da015a4eaf34224a623815d
timestamp: 20260718T160204Z
finding_ref: 7248

vhost: www.archlinexp.eu
rel_path: modules/mod_al_vote/helper.php
result: quarantined
evidence_sha256: 0b5c924a705ef20a151755d51cc1ec0f6a14259dc95fe8275999c9fd5ccef384
timestamp: 20260718T160204Z
finding_ref: 7218

vhost: www.archlinexp.eu
rel_path: modules/mod_al_vote/index.html
result: quarantined
evidence_sha256: 647cde511844340d9fac1c8247d2ddbcb03c29471da015a4eaf34224a623815d
timestamp: 20260718T160204Z
finding_ref: 7216

vhost: www.archlinexp.eu
rel_path: modules/mod_al_vote/language/de-DE/de-DE.mod_al_vote.ini
result: quarantined
evidence_sha256: b14f757d445fe29447b213ad3834a6485924704e56e103c95a0ddcf6a5d86b9b
timestamp: 20260718T160204Z
finding_ref: 7223

vhost: www.archlinexp.eu
rel_path: modules/mod_al_vote/language/de-DE/de-DE.mod_al_vote.sys.ini
result: quarantined
evidence_sha256: 6aa67b1e7671a2e12d9eceea4dd8a01c9b053208d565b20ba961e0bb8a4d8793
timestamp: 20260718T160204Z
finding_ref: 7222

vhost: www.archlinexp.eu
rel_path: modules/mod_al_vote/language/en-GB/en-GB.mod_al_vote.ini
result: quarantined
evidence_sha256: b14f757d445fe29447b213ad3834a6485924704e56e103c95a0ddcf6a5d86b9b
timestamp: 20260718T160204Z
finding_ref: 7225

vhost: www.archlinexp.eu
rel_path: modules/mod_al_vote/language/en-GB/en-GB.mod_al_vote.sys.ini
result: quarantined
evidence_sha256: 6aa67b1e7671a2e12d9eceea4dd8a01c9b053208d565b20ba961e0bb8a4d8793
timestamp: 20260718T160204Z
finding_ref: 7224

vhost: www.archlinexp.eu
rel_path: modules/mod_al_vote/language/hu-HU/hu-HU.mod_al_vote.ini
result: quarantined
evidence_sha256: 5d8093e15f311eb8a3e44cd1710baaa1d347c423b5e2c9ff07fb0ea1876cd0de
timestamp: 20260718T160204Z
finding_ref: 7221

vhost: www.archlinexp.eu
rel_path: modules/mod_al_vote/language/hu-HU/hu-HU.mod_al_vote.sys.ini
result: quarantined
evidence_sha256: fe3e8aca75ff56194b30ab42b861b09a22a2ca313624d1ae62e18b10cfefd368
timestamp: 20260718T160204Z
finding_ref: 7220

vhost: www.archlinexp.eu
rel_path: modules/mod_al_vote/mod_al_vote.php
result: quarantined
evidence_sha256: 176fd1c778009daba61f1e1289363e5b657a9ac6f558f21f9bc3723c14659135
timestamp: 20260718T160204Z
finding_ref: 7219

vhost: www.archlinexp.eu
rel_path: modules/mod_al_vote/mod_al_vote.xml
result: quarantined
evidence_sha256: 1ed8c27095489f0a0011b846d9a5434f5d1900b1e445dd3af1e1ae84d67ee5b5
timestamp: 20260718T160204Z
finding_ref: 7217

vhost: www.archlinexp.eu
rel_path: modules/mod_al_vote/tmpl/default.php
result: quarantined
evidence_sha256: 5bff3f42b1a1627e018b8c2ca635a83435f8504e9ff43e995bbbccbc401b548e
timestamp: 20260718T160204Z
finding_ref: 7227

vhost: www.archlinexp.eu
rel_path: modules/mod_al_vote/tmpl/index.html
result: quarantined
evidence_sha256: 647cde511844340d9fac1c8247d2ddbcb03c29471da015a4eaf34224a623815d
timestamp: 20260718T160204Z
finding_ref: 7226

vhost: www.archlinexp.eu
rel_path: modules/mod_alusers/assets/css/images/index.html
result: quarantined
evidence_sha256: 647cde511844340d9fac1c8247d2ddbcb03c29471da015a4eaf34224a623815d
timestamp: 20260718T160204Z
finding_ref: 7214

vhost: www.archlinexp.eu
rel_path: modules/mod_alusers/assets/css/index.html
result: quarantined
evidence_sha256: 647cde511844340d9fac1c8247d2ddbcb03c29471da015a4eaf34224a623815d
timestamp: 20260718T160204Z
finding_ref: 7211

vhost: www.archlinexp.eu
rel_path: modules/mod_alusers/assets/css/newstyle.css
result: quarantined
evidence_sha256: d70abf50ed939eb2e298de25d32af4f33a54815c9b90c4d0118c20ba498ffa32
timestamp: 20260718T160204Z
finding_ref: 7212

vhost: www.archlinexp.eu
rel_path: modules/mod_alusers/assets/css/style.css
result: quarantined
evidence_sha256: 34722adf5908c18835675b48bf1f7108c208216ce2ae7056455c1e160a86e887
timestamp: 20260718T160204Z
finding_ref: 7213

vhost: www.archlinexp.eu
rel_path: modules/mod_alusers/assets/index.html
result: quarantined
evidence_sha256: 647cde511844340d9fac1c8247d2ddbcb03c29471da015a4eaf34224a623815d
timestamp: 20260718T160204Z
finding_ref: 7210

vhost: www.archlinexp.eu
rel_path: modules/mod_alusers/assets/js/index.html
result: quarantined
evidence_sha256: 647cde511844340d9fac1c8247d2ddbcb03c29471da015a4eaf34224a623815d
timestamp: 20260718T160204Z
finding_ref: 7215

vhost: www.archlinexp.eu
rel_path: modules/mod_alusers/helper.php
result: quarantined
evidence_sha256: f32a272853a5e3b28097863308241216bf9ca011cf6dafe4ac4ccb63aeb8d7ae
timestamp: 20260718T160204Z
finding_ref: 7206

vhost: www.archlinexp.eu
rel_path: modules/mod_alusers/index.html
result: quarantined
evidence_sha256: 647cde511844340d9fac1c8247d2ddbcb03c29471da015a4eaf34224a623815d
timestamp: 20260718T160204Z
finding_ref: 7204

vhost: www.archlinexp.eu
rel_path: modules/mod_alusers/mod_alusers.php
result: quarantined
evidence_sha256: b3a03c1a602038b8d04ed872392111f716c34c5d602a192d4960aa9830ed95b5
timestamp: 20260718T160204Z
finding_ref: 7207

vhost: www.archlinexp.eu
rel_path: modules/mod_alusers/mod_alusers.xml
result: quarantined
evidence_sha256: 6c84ae2988438c5b40555e8862b72fce0d349b203dfcf54a58f3f9ba1ebf289e
timestamp: 20260718T160204Z
finding_ref: 7205

vhost: www.archlinexp.eu
rel_path: modules/mod_alusers/tmpl/default.php
result: quarantined
evidence_sha256: 1fa3716d8853febb7a6630ffa262cd2dd2e3c9cdbf04b7fa107b4fafe7afa990
timestamp: 20260718T160204Z
finding_ref: 7209

vhost: www.archlinexp.eu
rel_path: modules/mod_alusers/tmpl/index.html
result: quarantined
evidence_sha256: 647cde511844340d9fac1c8247d2ddbcb03c29471da015a4eaf34224a623815d
timestamp: 20260718T160204Z
finding_ref: 7208

vhost: www.archlinexp.eu
rel_path: modules/mod_course_list/helper.php
result: quarantined
evidence_sha256: 7b74a823c28f5516bbc785b36d16beafb6d01d229db1af93561488d67911fd27
timestamp: 20260718T160204Z
finding_ref: 7230

vhost: www.archlinexp.eu
rel_path: modules/mod_course_list/index.html
result: quarantined
evidence_sha256: 647cde511844340d9fac1c8247d2ddbcb03c29471da015a4eaf34224a623815d
timestamp: 20260718T160204Z
finding_ref: 7228

vhost: www.archlinexp.eu
rel_path: modules/mod_course_list/language/en-GB/en-GB.mod_course_list.ini
result: quarantined
evidence_sha256: 4289718b100745f12113baff97d577817d0ad7fca3ed8a7d37360bd06b95d0ed
timestamp: 20260718T160204Z
finding_ref: 7235

vhost: www.archlinexp.eu
rel_path: modules/mod_course_list/language/en-GB/en-GB.mod_course_list.sys.ini
result: quarantined
evidence_sha256: 4289718b100745f12113baff97d577817d0ad7fca3ed8a7d37360bd06b95d0ed
timestamp: 20260718T160204Z
finding_ref: 7234

vhost: www.archlinexp.eu
rel_path: modules/mod_course_list/language/hu-HU/hu-HU.mod_course_list.ini
result: quarantined
evidence_sha256: 4289718b100745f12113baff97d577817d0ad7fca3ed8a7d37360bd06b95d0ed
timestamp: 20260718T160204Z
finding_ref: 7232

vhost: www.archlinexp.eu
rel_path: modules/mod_course_list/language/hu-HU/hu-HU.mod_course_list.sys.ini
result: quarantined
evidence_sha256: 4289718b100745f12113baff97d577817d0ad7fca3ed8a7d37360bd06b95d0ed
timestamp: 20260718T160204Z
finding_ref: 7233

vhost: www.archlinexp.eu
rel_path: modules/mod_course_list/mod_course_list.php
result: quarantined
evidence_sha256: 7ad520f80ac058de97c4942710890f49f62e7962bae0dc699694ddddc98961ac
timestamp: 20260718T160204Z
finding_ref: 7229

vhost: www.archlinexp.eu
rel_path: modules/mod_course_list/mod_course_list.xml
result: quarantined
evidence_sha256: 2de45f9fb95060b6131cfba8e5a46bbd3f6027cbd11a97026966fbf948c0c89a
timestamp: 20260718T160204Z
finding_ref: 7231

vhost: www.archlinexp.eu
rel_path: modules/mod_course_list/tmpl/default.php
result: quarantined
evidence_sha256: 7c7e3eec8538662acb59cbd9173f748aead4c052a1e10271c2216389983c83a2
timestamp: 20260718T160204Z
finding_ref: 7237

vhost: www.archlinexp.eu
rel_path: modules/mod_course_list/tmpl/index.html
result: quarantined
evidence_sha256: 647cde511844340d9fac1c8247d2ddbcb03c29471da015a4eaf34224a623815d
timestamp: 20260718T160204Z
finding_ref: 7236
This commit is contained in:
imrcli-remediator 2026-07-18 18:02:06 +02:00
parent 9ccb96f418
commit 0ea6861988
158 changed files with 9689 additions and 0 deletions

View File

@ -0,0 +1,136 @@
<?php
/**
* @package Joomla.Site
* @subpackage com_users
*
* @copyright Copyright (C) 2005 - 2018 Open Source Matters, Inc. All rights reserved.
* @license GNU General Public License version 2 or later; see LICENSE.txt
*/
defined('_JEXEC') or die;
/**
* Base controller class for Users.
*
* @since 1.5
*/
class UsersController extends JControllerLegacy
{
/**
* Method to display a view.
*
* @param boolean $cachable If true, the view output will be cached
* @param array $urlparams An array of safe URL parameters and their variable types, for valid values see {@link JFilterInput::clean()}.
*
* @return JController This object to support chaining.
*
* @since 1.5
*/
public function display($cachable = false, $urlparams = false)
{
// Get the document object.
$document = JFactory::getDocument();
// Set the default view name and format from the Request.
$vName = $this->input->getCmd('view', 'login');
$vFormat = $document->getType();
$lName = $this->input->getCmd('layout', 'default');
if ($view = $this->getView($vName, $vFormat))
{
// Do any specific processing by view.
switch ($vName)
{
case 'registration':
// If the user is already logged in, redirect to the profile page.
$user = JFactory::getUser();
if ($user->get('guest') != 1)
{
// Redirect to profile page.
$this->setRedirect(JRoute::_('index.php?option=com_users&view=profile', false));
return;
}
// Check if user registration is enabled
if (JComponentHelper::getParams('com_users')->get('allowUserRegistration') == 0)
{
// Registration is disabled - Redirect to login page.
$this->setRedirect(JRoute::_('index.php?option=com_users&view=login', false));
return;
}
// The user is a guest, load the registration model and show the registration page.
$model = $this->getModel('Registration');
break;
// Handle view specific models.
case 'profile':
// If the user is a guest, redirect to the login page.
$user = JFactory::getUser();
if ($user->get('guest') == 1)
{
// Redirect to login page.
$this->setRedirect(JRoute::_('index.php?option=com_users&view=login', false));
return;
}
$model = $this->getModel($vName);
break;
// Handle the default views.
case 'login':
$model = $this->getModel($vName);
break;
case 'reset':
// If the user is already logged in, redirect to the profile page.
$user = JFactory::getUser();
if ($user->get('guest') != 1)
{
// Redirect to profile page.
$this->setRedirect(JRoute::_('index.php?option=com_users&view=profile', false));
return;
}
$model = $this->getModel($vName);
break;
case 'remind':
// If the user is already logged in, redirect to the profile page.
$user = JFactory::getUser();
if ($user->get('guest') != 1)
{
// Redirect to profile page.
$this->setRedirect(JRoute::_('index.php?option=com_users&view=profile', false));
return;
}
$model = $this->getModel($vName);
break;
default:
$model = $this->getModel('Login');
break;
}
// Push the model into the view (as default).
$view->setModel($model, true);
$view->setLayout($lName);
// Push document object into the view.
$view->document = $document;
$view->display();
}
}
}

View File

@ -0,0 +1,15 @@
{
"finding_ref": "7252",
"log_excerpt": "[quarantine] www.archlinexp.eu:components/com_users/controller.php -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/components/com_users/controller.php)",
"original_sha256": "2d0e5a25333180fc0976159ba409b32506d458b3239daa930474d8140a95bb92",
"original_stat": {
"gid": 30037,
"mtime": 1552901205,
"size": 3467,
"uid": 12425
},
"rel_path": "components/com_users/controller.php",
"result": "quarantined",
"timestamp": "20260718T160204Z",
"vhost": "www.archlinexp.eu"
}

View File

@ -0,0 +1,21 @@
<?php
/**
* @package Joomla.Site
* @subpackage com_users
*
* @copyright Copyright (C) 2005 - 2018 Open Source Matters, Inc. All rights reserved.
* @license GNU General Public License version 2 or later; see LICENSE.txt
*/
defined('_JEXEC') or die;
JLoader::register('UsersControllerProfile_Base_Json', __DIR__ . '/profile_base_json.php');
/**
* Profile controller class for Users.
*
* @since 1.6
*/
class UsersControllerProfile extends UsersControllerProfile_Base_Json
{
}

View File

@ -0,0 +1,15 @@
{
"finding_ref": "7257",
"log_excerpt": "[quarantine] www.archlinexp.eu:components/com_users/controllers/profile.json.php -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/components/com_users/controllers/profile.json.php)",
"original_sha256": "14089aed5d01c80be03a7ff13f0b8f5b6a5fb5c37b7f8e72bf9ab98e5bbb976b",
"original_stat": {
"gid": 30037,
"mtime": 1533967367,
"size": 498,
"uid": 12425
},
"rel_path": "components/com_users/controllers/profile.json.php",
"result": "quarantined",
"timestamp": "20260718T160204Z",
"vhost": "www.archlinexp.eu"
}

View File

@ -0,0 +1,260 @@
<?php
/**
* @package Joomla.Site
* @subpackage com_users
*
* @copyright Copyright (C) 2005 - 2018 Open Source Matters, Inc. All rights reserved.
* @license GNU General Public License version 2 or later; see LICENSE.txt
*/
defined('_JEXEC') or die;
JLoader::register('UsersController', JPATH_COMPONENT . '/controller.php');
/**
* Profile controller class for Users.
*
* @since 1.6
*/
class UsersControllerProfile extends UsersController
{
/**
* Method to check out a user for editing and redirect to the edit form.
*
* @return boolean
*
* @since 1.6
*/
public function edit()
{
$app = JFactory::getApplication();
$user = JFactory::getUser();
$loginUserId = (int) $user->get('id');
// Get the previous user id (if any) and the current user id.
$previousId = (int) $app->getUserState('com_users.edit.profile.id');
$userId = $this->input->getInt('user_id');
// Check if the user is trying to edit another users profile.
if ($userId != $loginUserId)
{
$app->enqueueMessage(JText::_('JERROR_ALERTNOAUTHOR'), 'error');
$app->setHeader('status', 403, true);
return false;
}
$cookieLogin = $user->get('cookieLogin');
// Check if the user logged in with a cookie
if (!empty($cookieLogin))
{
// If so, the user must login to edit the password and other data.
$app->enqueueMessage(JText::_('JGLOBAL_REMEMBER_MUST_LOGIN'), 'message');
$this->setRedirect(JRoute::_('index.php?option=com_users&view=login', false));
return false;
}
// Set the user id for the user to edit in the session.
$app->setUserState('com_users.edit.profile.id', $userId);
// Get the model.
$model = $this->getModel('Profile', 'UsersModel');
// Check out the user.
if ($userId)
{
$model->checkout($userId);
}
// Check in the previous user.
if ($previousId)
{
$model->checkin($previousId);
}
// Redirect to the edit screen.
$this->setRedirect(JRoute::_('index.php?option=com_users&view=profile&layout=edit', false));
return true;
}
/**
* Method to save a user's profile data.
*
* @return void
*
* @since 1.6
*/
public function save()
{
// Check for request forgeries.
$this->checkToken();
$app = JFactory::getApplication();
$model = $this->getModel('Profile', 'UsersModel');
$user = JFactory::getUser();
$userId = (int) $user->get('id');
// Get the user data.
$requestData = $app->input->post->get('jform', array(), 'array');
// Force the ID to this user.
$requestData['id'] = $userId;
// Validate the posted data.
$form = $model->getForm();
if (!$form)
{
JError::raiseError(500, $model->getError());
return false;
}
// Send an object which can be modified through the plugin event
$objData = (object) $requestData;
$app->triggerEvent(
'onContentNormaliseRequestData',
array('com_users.user', $objData, $form)
);
$requestData = (array) $objData;
// Validate the posted data.
$data = $model->validate($form, $requestData);
// Check for errors.
if ($data === false)
{
// Get the validation messages.
$errors = $model->getErrors();
// Push up to three validation messages out to the user.
for ($i = 0, $n = count($errors); $i < $n && $i < 3; $i++)
{
if ($errors[$i] instanceof Exception)
{
$app->enqueueMessage($errors[$i]->getMessage(), 'warning');
}
else
{
$app->enqueueMessage($errors[$i], 'warning');
}
}
// Unset the passwords.
unset($requestData['password1'], $requestData['password2']);
// Save the data in the session.
$app->setUserState('com_users.edit.profile.data', $requestData);
// Redirect back to the edit screen.
$userId = (int) $app->getUserState('com_users.edit.profile.id');
$this->setRedirect(JRoute::_('index.php?option=com_users&view=profile&layout=edit&user_id=' . $userId, false));
return false;
}
// Attempt to save the data.
$return = $model->save($data);
// Check for errors.
if ($return === false)
{
// Save the data in the session.
$app->setUserState('com_users.edit.profile.data', $data);
// Redirect back to the edit screen.
$userId = (int) $app->getUserState('com_users.edit.profile.id');
$this->setMessage(JText::sprintf('COM_USERS_PROFILE_SAVE_FAILED', $model->getError()), 'warning');
$this->setRedirect(JRoute::_('index.php?option=com_users&view=profile&layout=edit&user_id=' . $userId, false));
return false;
}
// Redirect the user and adjust session state based on the chosen task.
switch ($this->getTask())
{
case 'apply':
// Check out the profile.
$app->setUserState('com_users.edit.profile.id', $return);
$model->checkout($return);
// Redirect back to the edit screen.
$this->setMessage(JText::_('COM_USERS_PROFILE_SAVE_SUCCESS'));
$redirect = $app->getUserState('com_users.edit.profile.redirect');
// Don't redirect to an external URL.
if (!JUri::isInternal($redirect))
{
$redirect = null;
}
if (!$redirect)
{
$redirect = 'index.php?option=com_users&view=profile&layout=edit&hidemainmenu=1';
}
$this->setRedirect(JRoute::_($redirect, false));
break;
default:
// Check in the profile.
$userId = (int) $app->getUserState('com_users.edit.profile.id');
if ($userId)
{
$model->checkin($userId);
}
// Clear the profile id from the session.
$app->setUserState('com_users.edit.profile.id', null);
$redirect = $app->getUserState('com_users.edit.profile.redirect');
// Don't redirect to an external URL.
if (!JUri::isInternal($redirect))
{
$redirect = null;
}
if (!$redirect)
{
$redirect = 'index.php?option=com_users&view=profile&user_id=' . $return;
}
// Redirect to the list screen.
$this->setMessage(JText::_('COM_USERS_PROFILE_SAVE_SUCCESS'));
$this->setRedirect(JRoute::_($redirect, false));
break;
}
// Flush the data from the session.
$app->setUserState('com_users.edit.profile.data', null);
}
/**
* Function that allows child controller access to model data after the data has been saved.
*
* @param JModelLegacy $model The data model object.
* @param array $validData The validated data.
*
* @return void
*
* @since 3.1
*/
protected function postSaveHook(JModelLegacy $model, $validData = array())
{
$item = $model->getData();
$tags = $validData['tags'];
if ($tags)
{
$item->tags = new JHelperTags;
$item->tags->getTagIds($item->id, 'com_users.user');
$item->metadata['tags'] = $item->tags;
}
}
}

View File

@ -0,0 +1,15 @@
{
"finding_ref": "7258",
"log_excerpt": "[quarantine] www.archlinexp.eu:components/com_users/controllers/profile.php -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/components/com_users/controllers/profile.php)",
"original_sha256": "0cef6b3e5fc0304afdb0005711b02d9a39d01fee0ce14903d4312f31a2fa540b",
"original_stat": {
"gid": 30037,
"mtime": 1533967367,
"size": 6630,
"uid": 12425
},
"rel_path": "components/com_users/controllers/profile.php",
"result": "quarantined",
"timestamp": "20260718T160204Z",
"vhost": "www.archlinexp.eu"
}

View File

@ -0,0 +1,53 @@
<?php
/**
* @package Joomla.Site
* @subpackage com_users
*
* @copyright Copyright (C) 2005 - 2018 Open Source Matters, Inc. All rights reserved.
* @license GNU General Public License version 2 or later; see LICENSE.txt
*/
defined('_JEXEC') or die;
/**
* Profile controller class for Users.
*
* @since 3.5
*/
class UsersControllerProfile_Base_Json extends JControllerLegacy
{
/**
* Returns the updated options for help site selector
*
* @return void
*
* @since 3.5
* @throws Exception
*/
public function gethelpsites()
{
jimport('joomla.filesystem.file');
// Set FTP credentials, if given
JClientHelper::setCredentialsFromRequest('ftp');
if (($data = file_get_contents('https://update.joomla.org/helpsites/helpsites.xml')) === false)
{
throw new Exception(JText::_('COM_CONFIG_ERROR_HELPREFRESH_FETCH'), 500);
}
elseif (!JFile::write(JPATH_ADMINISTRATOR . '/help/helpsites.xml', $data))
{
throw new Exception(JText::_('COM_CONFIG_ERROR_HELPREFRESH_ERROR_STORE'), 500);
}
$options = array_merge(
array(
JHtml::_('select.option', '', JText::_('JOPTION_USE_DEFAULT'))
),
JHelp::createSiteList(JPATH_ADMINISTRATOR . '/help/helpsites.xml')
);
echo json_encode($options);
JFactory::getApplication()->close();
}
}

View File

@ -0,0 +1,15 @@
{
"finding_ref": "7259",
"log_excerpt": "[quarantine] www.archlinexp.eu:components/com_users/controllers/profile_base_json.php -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/components/com_users/controllers/profile_base_json.php)",
"original_sha256": "11ec9184dddb0f201b18ec05c6a279f1d4b387813b80ed01dfe5040e00c93d4a",
"original_stat": {
"gid": 30037,
"mtime": 1533967367,
"size": 1301,
"uid": 12425
},
"rel_path": "components/com_users/controllers/profile_base_json.php",
"result": "quarantined",
"timestamp": "20260718T160204Z",
"vhost": "www.archlinexp.eu"
}

View File

@ -0,0 +1,59 @@
<?php
/**
* @package Joomla.Site
* @subpackage com_users
*
* @copyright Copyright (C) 2005 - 2018 Open Source Matters, Inc. All rights reserved.
* @license GNU General Public License version 2 or later; see LICENSE.txt
*/
defined('_JEXEC') or die;
JLoader::register('UsersController', JPATH_COMPONENT . '/controller.php');
/**
* Reset controller class for Users.
*
* @since 1.6
*/
class UsersControllerRemind extends UsersController
{
/**
* Method to request a username reminder.
*
* @return boolean
*
* @since 1.6
*/
public function remind()
{
// Check the request token.
$this->checkToken('post');
$model = $this->getModel('Remind', 'UsersModel');
$data = $this->input->post->get('jform', array(), 'array');
// Submit the password reset request.
$return = $model->processRemindRequest($data);
// Check for a hard error.
if ($return == false)
{
// The request failed.
// Go back to the request form.
$message = JText::sprintf('COM_USERS_REMIND_REQUEST_FAILED', $model->getError());
$this->setRedirect(JRoute::_('index.php?option=com_users&view=remind', false), $message, 'notice');
return false;
}
else
{
// The request succeeded.
// Proceed to step two.
$message = JText::_('COM_USERS_REMIND_REQUEST_SUCCESS');
$this->setRedirect(JRoute::_('index.php?option=com_users&view=login', false), $message);
return true;
}
}
}

View File

@ -0,0 +1,15 @@
{
"finding_ref": "7255",
"log_excerpt": "[quarantine] www.archlinexp.eu:components/com_users/controllers/remind.php -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/components/com_users/controllers/remind.php)",
"original_sha256": "a6ef6d7b60043fa180e39c8efce1dcff804c8c2bbfa11d4e5e4d2ca36601972d",
"original_stat": {
"gid": 30037,
"mtime": 1533967367,
"size": 1427,
"uid": 12425
},
"rel_path": "components/com_users/controllers/remind.php",
"result": "quarantined",
"timestamp": "20260718T160204Z",
"vhost": "www.archlinexp.eu"
}

View File

@ -0,0 +1,190 @@
<?php
/**
* @package Joomla.Site
* @subpackage com_users
*
* @copyright Copyright (C) 2005 - 2018 Open Source Matters, Inc. All rights reserved.
* @license GNU General Public License version 2 or later; see LICENSE.txt
*/
defined('_JEXEC') or die;
JLoader::register('UsersController', JPATH_COMPONENT . '/controller.php');
/**
* Reset controller class for Users.
*
* @since 1.6
*/
class UsersControllerReset extends UsersController
{
/**
* Method to request a password reset.
*
* @return boolean
*
* @since 1.6
*/
public function request()
{
// Check the request token.
$this->checkToken('post');
$app = JFactory::getApplication();
$model = $this->getModel('Reset', 'UsersModel');
$data = $this->input->post->get('jform', array(), 'array');
// Submit the password reset request.
$return = $model->processResetRequest($data);
// Check for a hard error.
if ($return instanceof Exception)
{
// Get the error message to display.
if ($app->get('error_reporting'))
{
$message = $return->getMessage();
}
else
{
$message = JText::_('COM_USERS_RESET_REQUEST_ERROR');
}
// Go back to the request form.
$this->setRedirect(JRoute::_('index.php?option=com_users&view=reset', false), $message, 'error');
return false;
}
elseif ($return === false)
{
// The request failed.
// Go back to the request form.
$message = JText::sprintf('COM_USERS_RESET_REQUEST_FAILED', $model->getError());
$this->setRedirect(JRoute::_('index.php?option=com_users&view=reset', false), $message, 'notice');
return false;
}
else
{
// The request succeeded.
// Proceed to step two.
$this->setRedirect(JRoute::_('index.php?option=com_users&view=reset&layout=confirm', false));
return true;
}
}
/**
* Method to confirm the password request.
*
* @return boolean
*
* @access public
* @since 1.6
*/
public function confirm()
{
// Check the request token.
$this->checkToken('request');
$app = JFactory::getApplication();
$model = $this->getModel('Reset', 'UsersModel');
$data = $this->input->get('jform', array(), 'array');
// Confirm the password reset request.
$return = $model->processResetConfirm($data);
// Check for a hard error.
if ($return instanceof Exception)
{
// Get the error message to display.
if ($app->get('error_reporting'))
{
$message = $return->getMessage();
}
else
{
$message = JText::_('COM_USERS_RESET_CONFIRM_ERROR');
}
// Go back to the confirm form.
$this->setRedirect(JRoute::_('index.php?option=com_users&view=reset&layout=confirm', false), $message, 'error');
return false;
}
elseif ($return === false)
{
// Confirm failed.
// Go back to the confirm form.
$message = JText::sprintf('COM_USERS_RESET_CONFIRM_FAILED', $model->getError());
$this->setRedirect(JRoute::_('index.php?option=com_users&view=reset&layout=confirm', false), $message, 'notice');
return false;
}
else
{
// Confirm succeeded.
// Proceed to step three.
$this->setRedirect(JRoute::_('index.php?option=com_users&view=reset&layout=complete', false));
return true;
}
}
/**
* Method to complete the password reset process.
*
* @return boolean
*
* @since 1.6
*/
public function complete()
{
// Check for request forgeries
$this->checkToken('post');
$app = JFactory::getApplication();
$model = $this->getModel('Reset', 'UsersModel');
$data = $this->input->post->get('jform', array(), 'array');
// Complete the password reset request.
$return = $model->processResetComplete($data);
// Check for a hard error.
if ($return instanceof Exception)
{
// Get the error message to display.
if ($app->get('error_reporting'))
{
$message = $return->getMessage();
}
else
{
$message = JText::_('COM_USERS_RESET_COMPLETE_ERROR');
}
// Go back to the complete form.
$this->setRedirect(JRoute::_('index.php?option=com_users&view=reset&layout=complete', false), $message, 'error');
return false;
}
elseif ($return === false)
{
// Complete failed.
// Go back to the complete form.
$message = JText::sprintf('COM_USERS_RESET_COMPLETE_FAILED', $model->getError());
$this->setRedirect(JRoute::_('index.php?option=com_users&view=reset&layout=complete', false), $message, 'notice');
return false;
}
else
{
// Complete succeeded.
// Proceed to the login form.
$message = JText::_('COM_USERS_RESET_COMPLETE_SUCCESS');
$this->setRedirect(JRoute::_('index.php?option=com_users&view=login', false), $message);
return true;
}
}
}

View File

@ -0,0 +1,15 @@
{
"finding_ref": "7256",
"log_excerpt": "[quarantine] www.archlinexp.eu:components/com_users/controllers/reset.php -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/components/com_users/controllers/reset.php)",
"original_sha256": "224404ff37d78b3baf18f77b89e51e7599304b44b51fe6e4bf1ff9abf354ac0c",
"original_stat": {
"gid": 30037,
"mtime": 1533967367,
"size": 4662,
"uid": 12425
},
"rel_path": "components/com_users/controllers/reset.php",
"result": "quarantined",
"timestamp": "20260718T160204Z",
"vhost": "www.archlinexp.eu"
}

View File

@ -0,0 +1,374 @@
<?php
/**
* @package Joomla.Site
* @subpackage com_users
*
* @copyright Copyright (C) 2005 - 2018 Open Source Matters, Inc. All rights reserved.
* @license GNU General Public License version 2 or later; see LICENSE.txt
*/
defined('_JEXEC') or die;
JLoader::register('UsersController', JPATH_COMPONENT . '/controller.php');
/**
* Registration controller class for Users.
*
* @since 1.6
*/
class UsersControllerUser extends UsersController
{
/**
* Method to log in a user.
*
* @return void
*
* @since 1.6
*/
public function login()
{
$this->checkToken('post');
$app = JFactory::getApplication();
$input = $app->input->getInputForRequestMethod();
// Populate the data array:
$data = array();
$data['return'] = base64_decode($input->get('return', '', 'BASE64'));
$data['username'] = $input->get('username', '', 'USERNAME');
$data['password'] = $input->get('password', '', 'RAW');
$data['secretkey'] = $input->get('secretkey', '', 'RAW');
// Check for a simple menu item id
if (is_numeric($data['return']))
{
if (JLanguageMultilang::isEnabled())
{
$db = JFactory::getDbo();
$query = $db->getQuery(true)
->select('language')
->from($db->quoteName('#__menu'))
->where('client_id = 0')
->where('id =' . $data['return']);
$db->setQuery($query);
try
{
$language = $db->loadResult();
}
catch (RuntimeException $e)
{
return;
}
if ($language !== '*')
{
$lang = '&lang=' . $language;
}
else
{
$lang = '';
}
}
else
{
$lang = '';
}
$data['return'] = 'index.php?Itemid=' . $data['return'] . $lang;
}
else
{
// Don't redirect to an external URL.
if (!JUri::isInternal($data['return']))
{
$data['return'] = '';
}
}
// Set the return URL if empty.
if (empty($data['return']))
{
$data['return'] = 'index.php?option=com_users&view=profile';
}
// Set the return URL in the user state to allow modification by plugins
$app->setUserState('users.login.form.return', $data['return']);
// Get the log in options.
$options = array();
$options['remember'] = $this->input->getBool('remember', false);
$options['return'] = $data['return'];
// Get the log in credentials.
$credentials = array();
$credentials['username'] = $data['username'];
$credentials['password'] = $data['password'];
$credentials['secretkey'] = $data['secretkey'];
// Perform the log in.
if (true !== $app->login($credentials, $options))
{
// Login failed !
// Clear user name, password and secret key before sending the login form back to the user.
$data['remember'] = (int) $options['remember'];
$data['username'] = '';
$data['password'] = '';
$data['secretkey'] = '';
$app->setUserState('users.login.form.data', $data);
$uri = JFactory::getURI();
$url = $uri->toString();
$app->redirect(JRoute::_($url, false));
//$app->redirect(JRoute::_('index.php?option=com_users&view=login', false)); //Eredeti
}
// Success
if ($options['remember'] == true)
{
$app->setUserState('rememberLogin', true);
}
$app->setUserState('users.login.form.data', array());
$app->redirect(JRoute::_($app->getUserState('users.login.form.return'), false));
}
/**
* Method to log out a user.
*
* @return void
*
* @since 1.6
*/
public function logout()
{
$this->checkToken('request');
$app = JFactory::getApplication();
// Prepare the logout options.
$options = array(
'clientid' => $app->get('shared_session', '0') ? null : 0,
);
// Perform the log out.
$error = $app->logout(null, $options);
$input = $app->input->getInputForRequestMethod();
// Check if the log out succeeded.
if ($error instanceof Exception)
{
$app->redirect(JRoute::_('index.php?option=com_users&view=login', false));
}
// Get the return URL from the request and validate that it is internal.
$return = $input->get('return', '', 'BASE64');
$return = base64_decode($return);
// Check for a simple menu item id
if (is_numeric($return))
{
if (JLanguageMultilang::isEnabled())
{
$db = JFactory::getDbo();
$query = $db->getQuery(true)
->select('language')
->from($db->quoteName('#__menu'))
->where('client_id = 0')
->where('id =' . $return);
$db->setQuery($query);
try
{
$language = $db->loadResult();
}
catch (RuntimeException $e)
{
return;
}
if ($language !== '*')
{
$lang = '&lang=' . $language;
}
else
{
$lang = '';
}
}
else
{
$lang = '';
}
$return = 'index.php?Itemid=' . $return . $lang;
}
else
{
// Don't redirect to an external URL.
if (!JUri::isInternal($return))
{
$return = '';
}
}
// In case redirect url is not set, redirect user to homepage
if (empty($return))
{
$return = JUri::root();
}
// Redirect the user.
$app->redirect(JRoute::_($return, false));
}
/**
* Method to logout directly and redirect to page.
*
* @return void
*
* @since 3.5
*/
public function menulogout()
{
// Get the ItemID of the page to redirect after logout
$app = JFactory::getApplication();
$itemid = $app->getMenu()->getActive()->params->get('logout');
// Get the language of the page when multilang is on
if (JLanguageMultilang::isEnabled())
{
if ($itemid)
{
$db = JFactory::getDbo();
$query = $db->getQuery(true)
->select('language')
->from($db->quoteName('#__menu'))
->where('client_id = 0')
->where('id =' . $itemid);
$db->setQuery($query);
try
{
$language = $db->loadResult();
}
catch (RuntimeException $e)
{
return;
}
if ($language !== '*')
{
$lang = '&lang=' . $language;
}
else
{
$lang = '';
}
// URL to redirect after logout
$url = 'index.php?Itemid=' . $itemid . $lang;
}
else
{
// Logout is set to default. Get the home page ItemID
$lang_code = $app->input->cookie->getString(JApplicationHelper::getHash('language'));
$item = $app->getMenu()->getDefault($lang_code);
$itemid = $item->id;
// Redirect to Home page after logout
$url = 'index.php?Itemid=' . $itemid;
}
}
else
{
// URL to redirect after logout, default page if no ItemID is set
$url = $itemid ? 'index.php?Itemid=' . $itemid : JUri::root();
}
// Logout and redirect
$this->setRedirect('index.php?option=com_users&task=user.logout&' . JSession::getFormToken() . '=1&return=' . base64_encode($url));
}
/**
* Method to request a username reminder.
*
* @return boolean
*
* @since 1.6
*/
public function remind()
{
// Check the request token.
$this->checkToken('post');
$app = JFactory::getApplication();
$model = $this->getModel('User', 'UsersModel');
$data = $this->input->post->get('jform', array(), 'array');
// Submit the username remind request.
$return = $model->processRemindRequest($data);
// Check for a hard error.
if ($return instanceof Exception)
{
// Get the error message to display.
$message = $app->get('error_reporting')
? $return->getMessage()
: JText::_('COM_USERS_REMIND_REQUEST_ERROR');
// Get the route to the next page.
$itemid = UsersHelperRoute::getRemindRoute();
$itemid = $itemid !== null ? '&Itemid=' . $itemid : '';
$route = 'index.php?option=com_users&view=remind' . $itemid;
// Go back to the complete form.
$this->setRedirect(JRoute::_($route, false), $message, 'error');
return false;
}
if ($return === false)
{
// Complete failed.
// Get the route to the next page.
$itemid = UsersHelperRoute::getRemindRoute();
$itemid = $itemid !== null ? '&Itemid=' . $itemid : '';
$route = 'index.php?option=com_users&view=remind' . $itemid;
// Go back to the complete form.
$message = JText::sprintf('COM_USERS_REMIND_REQUEST_FAILED', $model->getError());
$this->setRedirect(JRoute::_($route, false), $message, 'notice');
return false;
}
// Complete succeeded.
// Get the route to the next page.
$itemid = UsersHelperRoute::getLoginRoute();
$itemid = $itemid !== null ? '&Itemid=' . $itemid : '';
$route = 'index.php?option=com_users&view=login' . $itemid;
// Proceed to the login form.
$message = JText::_('COM_USERS_REMIND_REQUEST_SUCCESS');
$this->setRedirect(JRoute::_($route, false), $message);
return true;
}
/**
* Method to resend a user.
*
* @return void
*
* @since 1.6
*/
public function resend()
{
// Check for request forgeries
// $this->checkToken('post');
}
}

View File

@ -0,0 +1,15 @@
{
"finding_ref": "7254",
"log_excerpt": "[quarantine] www.archlinexp.eu:components/com_users/controllers/user.php -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/components/com_users/controllers/user.php)",
"original_sha256": "d7472a9cb222592b7799229831d00ed6e728d082fd5ed5be616404edb8ad275c",
"original_stat": {
"gid": 30037,
"mtime": 1557908559,
"size": 8730,
"uid": 12425
},
"rel_path": "components/com_users/controllers/user.php",
"result": "quarantined",
"timestamp": "20260718T160204Z",
"vhost": "www.archlinexp.eu"
}

View File

@ -0,0 +1,251 @@
<?php
/**
* @package Joomla.Site
* @subpackage com_users
*
* @copyright Copyright (C) 2005 - 2018 Open Source Matters, Inc. All rights reserved.
* @license GNU General Public License version 2 or later; see LICENSE.txt
*/
defined('_JEXEC') or die;
/**
* Users Html Helper
*
* @since 1.6
*/
abstract class JHtmlUsers
{
/**
* Get the sanitized value
*
* @param mixed $value Value of the field
*
* @return mixed String/void
*
* @since 1.6
*/
public static function value($value)
{
if (is_string($value))
{
$value = trim($value);
}
if (empty($value))
{
return JText::_('COM_USERS_PROFILE_VALUE_NOT_FOUND');
}
elseif (!is_array($value))
{
return htmlspecialchars($value, ENT_COMPAT, 'UTF-8');
}
}
/**
* Get the space symbol
*
* @param mixed $value Value of the field
*
* @return string
*
* @since 1.6
*/
public static function spacer($value)
{
return '';
}
/**
* Get the sanitized helpsite link
*
* @param mixed $value Value of the field
*
* @return mixed String/void
*
* @since 1.6
*/
public static function helpsite($value)
{
if (empty($value))
{
return static::value($value);
}
$text = $value;
if ($xml = simplexml_load_file(JPATH_ADMINISTRATOR . '/help/helpsites.xml'))
{
foreach ($xml->sites->site as $site)
{
if ((string) $site->attributes()->url == $value)
{
$text = (string) $site;
break;
}
}
}
$value = htmlspecialchars($value, ENT_COMPAT, 'UTF-8');
if (strpos($value, 'http') === 0)
{
return '<a href="' . $value . '">' . $text . '</a>';
}
return '<a href="http://' . $value . '">' . $text . '</a>';
}
/**
* Get the sanitized template style
*
* @param mixed $value Value of the field
*
* @return mixed String/void
*
* @since 1.6
*/
public static function templatestyle($value)
{
if (empty($value))
{
return static::value($value);
}
else
{
$db = JFactory::getDbo();
$query = $db->getQuery(true)
->select('title')
->from('#__template_styles')
->where('id = ' . $db->quote($value));
$db->setQuery($query);
$title = $db->loadResult();
if ($title)
{
return htmlspecialchars($title, ENT_COMPAT, 'UTF-8');
}
else
{
return static::value('');
}
}
}
/**
* Get the sanitized language
*
* @param mixed $value Value of the field
*
* @return mixed String/void
*
* @since 1.6
*/
public static function admin_language($value)
{
if (empty($value))
{
return static::value($value);
}
else
{
$file = JLanguageHelper::getLanguagePath(JPATH_ADMINISTRATOR, $value) . '/' . $value . '.xml';
$result = null;
if (is_file($file))
{
$result = JLanguageHelper::parseXMLLanguageFile($file);
}
if ($result)
{
return htmlspecialchars($result['name'], ENT_COMPAT, 'UTF-8');
}
else
{
return static::value('');
}
}
}
/**
* Get the sanitized language
*
* @param mixed $value Value of the field
*
* @return mixed String/void
*
* @since 1.6
*/
public static function language($value)
{
if (empty($value))
{
return static::value($value);
}
else
{
$file = JLanguageHelper::getLanguagePath(JPATH_SITE, $value) . '/' . $value . '.xml';
$result = null;
if (is_file($file))
{
$result = JLanguageHelper::parseXMLLanguageFile($file);
}
if ($result)
{
return htmlspecialchars($result['name'], ENT_COMPAT, 'UTF-8');
}
else
{
return static::value('');
}
}
}
/**
* Get the sanitized editor name
*
* @param mixed $value Value of the field
*
* @return mixed String/void
*
* @since 1.6
*/
public static function editor($value)
{
if (empty($value))
{
return static::value($value);
}
else
{
$db = JFactory::getDbo();
$lang = JFactory::getLanguage();
$query = $db->getQuery(true)
->select('name')
->from('#__extensions')
->where('element = ' . $db->quote($value))
->where('folder = ' . $db->quote('editors'));
$db->setQuery($query);
$title = $db->loadResult();
if ($title)
{
$lang->load("plg_editors_$value.sys", JPATH_ADMINISTRATOR, null, false, true)
|| $lang->load("plg_editors_$value.sys", JPATH_PLUGINS . '/editors/' . $value, null, false, true);
$lang->load($title . '.sys');
return JText::_($title);
}
else
{
return static::value('');
}
}
}
}

View File

@ -0,0 +1,15 @@
{
"finding_ref": "7283",
"log_excerpt": "[quarantine] www.archlinexp.eu:components/com_users/helpers/html/users.php -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/components/com_users/helpers/html/users.php)",
"original_sha256": "cb229ad16ba915a20aa22c49f2b5863cb4079cb5ce5fb3975b07b5caa161e786",
"original_stat": {
"gid": 30037,
"mtime": 1533967367,
"size": 4500,
"uid": 12425
},
"rel_path": "components/com_users/helpers/html/users.php",
"result": "quarantined",
"timestamp": "20260718T160204Z",
"vhost": "www.archlinexp.eu"
}

View File

@ -0,0 +1,309 @@
<?php
/**
* @package Joomla.Site
* @subpackage com_users
*
* @copyright Copyright (C) 2005 - 2018 Open Source Matters, Inc. All rights reserved.
* @license GNU General Public License version 2 or later; see LICENSE.txt
*/
defined('_JEXEC') or die;
/**
* Legacy routing rules class from com_users
*
* @since 3.6
* @deprecated 4.0
*/
class UsersRouterRulesLegacy implements JComponentRouterRulesInterface
{
/**
* Constructor for this legacy router
*
* @param JComponentRouterAdvanced $router The router this rule belongs to
*
* @since 3.6
* @deprecated 4.0
*/
public function __construct($router)
{
$this->router = $router;
}
/**
* Preprocess the route for the com_users component
*
* @param array &$query An array of URL arguments
*
* @return void
*
* @since 3.6
* @deprecated 4.0
*/
public function preprocess(&$query)
{
}
/**
* Build the route for the com_users component
*
* @param array &$query An array of URL arguments
* @param array &$segments The URL arguments to use to assemble the subsequent URL.
*
* @return void
*
* @since 3.6
* @deprecated 4.0
*/
public function build(&$query, &$segments)
{
// Declare static variables.
static $items;
static $default;
static $registration;
static $profile;
static $login;
static $remind;
static $resend;
static $reset;
// Get the relevant menu items if not loaded.
if (empty($items))
{
// Get all relevant menu items.
$items = $this->router->menu->getItems('component', 'com_users');
// Build an array of serialized query strings to menu item id mappings.
foreach ($items as $item)
{
if (empty($item->query['view']))
{
continue;
}
// Check to see if we have found the resend menu item.
if (empty($resend) && $item->query['view'] === 'resend')
{
$resend = $item->id;
continue;
}
// Check to see if we have found the reset menu item.
if (empty($reset) && $item->query['view'] === 'reset')
{
$reset = $item->id;
continue;
}
// Check to see if we have found the remind menu item.
if (empty($remind) && $item->query['view'] === 'remind')
{
$remind = $item->id;
continue;
}
// Check to see if we have found the login menu item.
if (empty($login) && $item->query['view'] === 'login')
{
$login = $item->id;
continue;
}
// Check to see if we have found the registration menu item.
if (empty($registration) && $item->query['view'] === 'registration')
{
$registration = $item->id;
continue;
}
// Check to see if we have found the profile menu item.
if (empty($profile) && $item->query['view'] === 'profile')
{
$profile = $item->id;
}
}
// Set the default menu item to use for com_users if possible.
if ($profile)
{
$default = $profile;
}
elseif ($registration)
{
$default = $registration;
}
elseif ($login)
{
$default = $login;
}
}
if (!empty($query['view']))
{
switch ($query['view'])
{
case 'reset':
if ($query['Itemid'] = $reset)
{
unset($query['view']);
}
else
{
$query['Itemid'] = $default;
}
break;
case 'resend':
if ($query['Itemid'] = $resend)
{
unset($query['view']);
}
else
{
$query['Itemid'] = $default;
}
break;
case 'remind':
if ($query['Itemid'] = $remind)
{
unset($query['view']);
}
else
{
$query['Itemid'] = $default;
}
break;
case 'login':
if ($query['Itemid'] = $login)
{
unset($query['view']);
}
else
{
$query['Itemid'] = $default;
}
break;
case 'registration':
if ($query['Itemid'] = $registration)
{
unset($query['view']);
}
else
{
$query['Itemid'] = $default;
}
break;
default:
case 'profile':
if (!empty($query['view']))
{
$segments[] = $query['view'];
}
unset($query['view']);
if ($query['Itemid'] = $profile)
{
unset($query['view']);
}
else
{
$query['Itemid'] = $default;
}
// Only append the user id if not "me".
$user = JFactory::getUser();
if (!empty($query['user_id']) && ($query['user_id'] != $user->id))
{
$segments[] = $query['user_id'];
}
unset($query['user_id']);
break;
}
}
$total = count($segments);
for ($i = 0; $i < $total; $i++)
{
$segments[$i] = str_replace(':', '-', $segments[$i]);
}
}
/**
* Parse the segments of a URL.
*
* @param array &$segments The segments of the URL to parse.
* @param array &$vars The URL attributes to be used by the application.
*
* @return void
*
* @since 3.6
* @deprecated 4.0
*/
public function parse(&$segments, &$vars)
{
$total = count($segments);
for ($i = 0; $i < $total; $i++)
{
$segments[$i] = preg_replace('/-/', ':', $segments[$i], 1);
}
// Only run routine if there are segments to parse.
if (count($segments) < 1)
{
return;
}
// Get the package from the route segments.
$userId = array_pop($segments);
if (!is_numeric($userId))
{
$vars['view'] = 'profile';
return;
}
if (is_numeric($userId))
{
$db = JFactory::getDbo();
$query = $db->getQuery(true)
->select($db->quoteName('id'))
->from($db->quoteName('#__users'))
->where($db->quoteName('id') . ' = ' . (int) $userId);
$db->setQuery($query);
$userId = $db->loadResult();
}
// Set the package id if present.
if ($userId)
{
// Set the package id.
$vars['user_id'] = (int) $userId;
// Set the view to package if not already set.
if (empty($vars['view']))
{
$vars['view'] = 'profile';
}
}
else
{
JError::raiseError(404, JText::_('JGLOBAL_RESOURCE_NOT_FOUND'));
}
}
}

View File

@ -0,0 +1,15 @@
{
"finding_ref": "7281",
"log_excerpt": "[quarantine] www.archlinexp.eu:components/com_users/helpers/legacyrouter.php -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/components/com_users/helpers/legacyrouter.php)",
"original_sha256": "e25f6683f53657c5f1f0f03e80126eb3acbc3b270dd26f3bcd8e16fc72f72343",
"original_stat": {
"gid": 30037,
"mtime": 1533967367,
"size": 6013,
"uid": 12425
},
"rel_path": "components/com_users/helpers/legacyrouter.php",
"result": "quarantined",
"timestamp": "20260718T160204Z",
"vhost": "www.archlinexp.eu"
}

View File

@ -0,0 +1,199 @@
<?php
/**
* @package Joomla.Site
* @subpackage com_users
*
* @copyright Copyright (C) 2005 - 2018 Open Source Matters, Inc. All rights reserved.
* @license GNU General Public License version 2 or later; see LICENSE.txt
*/
defined('_JEXEC') or die;
/**
* Users Route Helper
*
* @since 1.6
* @deprecated 4.0
*/
class UsersHelperRoute
{
/**
* Method to get the menu items for the component.
*
* @return array An array of menu items.
*
* @since 1.6
* @deprecated 4.0
*/
public static function &getItems()
{
static $items;
// Get the menu items for this component.
if (!isset($items))
{
$component = JComponentHelper::getComponent('com_users');
$items = JFactory::getApplication()->getMenu()->getItems('component_id', $component->id);
// If no items found, set to empty array.
if (!$items)
{
$items = array();
}
}
return $items;
}
/**
* Method to get a route configuration for the login view.
*
* @return mixed Integer menu id on success, null on failure.
*
* @since 1.6
* @deprecated 4.0
*/
public static function getLoginRoute()
{
// Get the items.
$items = self::getItems();
// Search for a suitable menu id.
foreach ($items as $item)
{
if (isset($item->query['view']) && $item->query['view'] === 'login')
{
return $item->id;
}
}
return null;
}
/**
* Method to get a route configuration for the profile view.
*
* @return mixed Integer menu id on success, null on failure.
*
* @since 1.6
* @deprecated 4.0
*/
public static function getProfileRoute()
{
// Get the items.
$items = self::getItems();
// Search for a suitable menu id.
// Menu link can only go to users own profile.
foreach ($items as $item)
{
if (isset($item->query['view']) && $item->query['view'] === 'profile')
{
return $item->id;
}
}
return null;
}
/**
* Method to get a route configuration for the registration view.
*
* @return mixed Integer menu id on success, null on failure.
*
* @since 1.6
* @deprecated 4.0
*/
public static function getRegistrationRoute()
{
// Get the items.
$items = self::getItems();
// Search for a suitable menu id.
foreach ($items as $item)
{
if (isset($item->query['view']) && $item->query['view'] === 'registration')
{
return $item->id;
}
}
return null;
}
/**
* Method to get a route configuration for the remind view.
*
* @return mixed Integer menu id on success, null on failure.
*
* @since 1.6
* @deprecated 4.0
*/
public static function getRemindRoute()
{
// Get the items.
$items = self::getItems();
// Search for a suitable menu id.
foreach ($items as $item)
{
if (isset($item->query['view']) && $item->query['view'] === 'remind')
{
return $item->id;
}
}
return null;
}
/**
* Method to get a route configuration for the resend view.
*
* @return mixed Integer menu id on success, null on failure.
*
* @since 1.6
* @deprecated 4.0
*/
public static function getResendRoute()
{
// Get the items.
$items = self::getItems();
// Search for a suitable menu id.
foreach ($items as $item)
{
if (isset($item->query['view']) && $item->query['view'] === 'resend')
{
return $item->id;
}
}
return null;
}
/**
* Method to get a route configuration for the reset view.
*
* @return mixed Integer menu id on success, null on failure.
*
* @since 1.6
* @deprecated 4.0
*/
public static function getResetRoute()
{
// Get the items.
$items = self::getItems();
// Search for a suitable menu id.
foreach ($items as $item)
{
if (isset($item->query['view']) && $item->query['view'] === 'reset')
{
return $item->id;
}
}
return null;
}
}

View File

@ -0,0 +1,15 @@
{
"finding_ref": "7282",
"log_excerpt": "[quarantine] www.archlinexp.eu:components/com_users/helpers/route.php -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/components/com_users/helpers/route.php)",
"original_sha256": "2f2d92b287b854fc6ad31c8168badc5938e39bec1f8b6202d4df348cd23a23f0",
"original_stat": {
"gid": 30037,
"mtime": 1533967367,
"size": 3867,
"uid": 12425
},
"rel_path": "components/com_users/helpers/route.php",
"result": "quarantined",
"timestamp": "20260718T160204Z",
"vhost": "www.archlinexp.eu"
}

View File

@ -0,0 +1,60 @@
<?php
/**
* @package Joomla.Site
* @subpackage Layout
*
* @copyright Copyright (C) 2005 - 2019 Open Source Matters, Inc. All rights reserved.
* @license GNU General Public License version 2 or later; see LICENSE.txt
*/
defined('JPATH_BASE') or die;
extract($displayData);
/**
* Layout variables
* ---------------------
* $options : (array) Optional parameters
* $label : (string) The html code for the label (not required if $options['hiddenLabel'] is true)
* $input : (string) The input field html code
*/
if (!empty($options['showonEnabled']))
{
JHtml::_('jquery.framework');
JHtml::_('script', 'jui/cms.js', array('version' => 'auto', 'relative' => true));
}
$class = empty($options['class']) ? '' : ' ' . $options['class'];
$rel = empty($options['rel']) ? '' : ' ' . $options['rel'];
/**
* @TODO:
*
* As mentioned in #8473 (https://github.com/joomla/joomla-cms/pull/8473), ...
* as long as we cannot access the field properties properly, this seems to
* be the way to go for now.
*
* On a side note: Parsing html is seldom a good idea.
* https://stackoverflow.com/questions/1732348/regex-match-open-tags-except-xhtml-self-contained-tags/1732454#1732454
*/
preg_match('/class=\"([^\"]+)\"/i', $input, $match);
$required = (strpos($input, 'aria-required="true"') !== false || (!empty($match[1]) && strpos($match[1], 'required') !== false));
$typeOfSpacer = (strpos($label, 'spacer-lbl') !== false);
?>
<div class="control-group<?php echo $class; ?>"<?php echo $rel; ?>>
<?php if (empty($options['hiddenLabel'])): ?>
<div class="control-label">
<?php echo $label; ?>
<?php if (!$required && !$typeOfSpacer) : ?>
<span class="optional"><?php echo JText::_('COM_USERS_OPTIONAL'); ?></span>
<?php endif; ?>
</div>
<?php endif; ?>
<div class="controls">
<?php echo $input; ?>
</div>
</div>

View File

@ -0,0 +1,15 @@
{
"finding_ref": "7284",
"log_excerpt": "[quarantine] www.archlinexp.eu:components/com_users/layouts/joomla/form/renderfield.php -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/components/com_users/layouts/joomla/form/renderfield.php)",
"original_sha256": "767cc86103a71d15914e028fc231d5b48ffb5cdc5bf6ab8ecc3e22bb73d9190b",
"original_stat": {
"gid": 30037,
"mtime": 1642534578,
"size": 1957,
"uid": 12425
},
"rel_path": "components/com_users/layouts/joomla/form/renderfield.php",
"result": "quarantined",
"timestamp": "20260718T160204Z",
"vhost": "www.archlinexp.eu"
}

View File

@ -0,0 +1,92 @@
<?xml version="1.0" encoding="utf-8"?>
<form>
<fieldset name="core" label="COM_USERS_PROFILE_DEFAULT_LABEL">
<field
name="id"
type="hidden"
filter="integer"
/>
<field
name="name"
type="text"
label="COM_USERS_PROFILE_NAME_LABEL"
description="COM_USERS_PROFILE_NAME_DESC"
filter="string"
required="true"
size="30"
/>
<field
name="username"
type="text"
label="COM_USERS_PROFILE_USERNAME_LABEL"
description="COM_USERS_DESIRED_USERNAME"
class="validate-username"
filter="username"
message="COM_USERS_PROFILE_USERNAME_MESSAGE"
required="true"
size="30"
validate="username"
/>
<field
name="password1"
type="password"
label="COM_USERS_PROFILE_PASSWORD1_LABEL"
description="COM_USERS_DESIRED_PASSWORD"
autocomplete="off"
class="validate-password"
filter="raw"
size="30"
validate="password"
/>
<field
name="password2"
type="password"
label="COM_USERS_PROFILE_PASSWORD2_LABEL"
description="COM_USERS_PROFILE_PASSWORD2_DESC"
autocomplete="off"
class="validate-password"
field="password1"
filter="raw"
message="COM_USERS_PROFILE_PASSWORD1_MESSAGE"
size="30"
validate="equals"
/>
<field
name="email1"
type="email"
label="COM_USERS_PROFILE_EMAIL1_LABEL"
description="COM_USERS_PROFILE_EMAIL1_DESC"
filter="string"
message="COM_USERS_PROFILE_EMAIL1_MESSAGE"
required="true"
size="30"
unique="true"
validate="email"
autocomplete="email"
/>
<field
name="email2"
type="email"
label="COM_USERS_PROFILE_EMAIL2_LABEL"
description="COM_USERS_PROFILE_EMAIL2_DESC"
field="email1"
filter="string"
message="COM_USERS_PROFILE_EMAIL2_MESSAGE"
required="true"
size="30"
validate="equals"
/>
</fieldset>
<!-- Used to get the two factor authentication configuration -->
<field
name="twofactor"
type="hidden"
/>
</form>

View File

@ -0,0 +1,15 @@
{
"finding_ref": "7278",
"log_excerpt": "[quarantine] www.archlinexp.eu:components/com_users/models/forms/profile.xml -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/components/com_users/models/forms/profile.xml)",
"original_sha256": "6f217de7628ab4c162bef301a62851bd90557bc43062783410df850901f536ba",
"original_stat": {
"gid": 30037,
"mtime": 1533967367,
"size": 1914,
"uid": 12425
},
"rel_path": "components/com_users/models/forms/profile.xml",
"result": "quarantined",
"timestamp": "20260718T160204Z",
"vhost": "www.archlinexp.eu"
}

View File

@ -0,0 +1,99 @@
<?xml version="1.0" encoding="utf-8"?>
<form>
<fieldset name="default" label="COM_USERS_REGISTRATION_DEFAULT_LABEL">
<field
name="spacer"
type="spacer"
label="COM_USERS_REGISTER_REQUIRED"
class="text"
/>
<field
name="name"
type="text"
label="COM_USERS_REGISTER_NAME_LABEL"
description="COM_USERS_REGISTER_NAME_DESC"
filter="string"
required="true"
size="30"
/>
<field
name="username"
type="text"
label="COM_USERS_REGISTER_USERNAME_LABEL"
description="COM_USERS_DESIRED_USERNAME"
class="validate-username"
filter="username"
message="COM_USERS_REGISTER_USERNAME_MESSAGE"
required="true"
size="30"
validate="username"
/>
<field
name="password1"
type="password"
label="COM_USERS_PROFILE_PASSWORD1_LABEL"
description="COM_USERS_DESIRED_PASSWORD"
autocomplete="off"
class="validate-password"
field="password1"
filter="raw"
size="30"
validate="password"
required="true"
/>
<field
name="password2"
type="password"
label="COM_USERS_PROFILE_PASSWORD2_LABEL"
description="COM_USERS_PROFILE_PASSWORD2_DESC"
autocomplete="off"
class="validate-password"
field="password1"
filter="raw"
message="COM_USERS_PROFILE_PASSWORD1_MESSAGE"
size="30"
validate="equals"
required="true"
/>
<field
name="email1"
type="email"
label="COM_USERS_REGISTER_EMAIL1_LABEL"
description="COM_USERS_REGISTER_EMAIL1_DESC"
field="id"
filter="string"
message="COM_USERS_REGISTER_EMAIL1_MESSAGE"
required="true"
size="30"
unique="true"
validate="email"
autocomplete="email"
/>
<field
name="email2"
type="email"
label="COM_USERS_REGISTER_EMAIL2_LABEL"
description="COM_USERS_REGISTER_EMAIL2_DESC"
field="email1"
filter="string"
message="COM_USERS_REGISTER_EMAIL2_MESSAGE"
required="true"
size="30"
validate="equals"
/>
<field
name="captcha"
type="captcha"
label="COM_USERS_CAPTCHA_LABEL"
description="COM_USERS_CAPTCHA_DESC"
validate="captcha"
/>
</fieldset>
</form>

View File

@ -0,0 +1,15 @@
{
"finding_ref": "7277",
"log_excerpt": "[quarantine] www.archlinexp.eu:components/com_users/models/forms/registration.xml -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/components/com_users/models/forms/registration.xml)",
"original_sha256": "d8d90d9badd444b08bd7243d3621f6af3feaee137523c212b5b883883f805b7e",
"original_stat": {
"gid": 30037,
"mtime": 1541586989,
"size": 2079,
"uid": 12425
},
"rel_path": "components/com_users/models/forms/registration.xml",
"result": "quarantined",
"timestamp": "20260718T160204Z",
"vhost": "www.archlinexp.eu"
}

View File

@ -0,0 +1,112 @@
<?php
/**
* @package Joomla.Site
* @subpackage com_users
*
* @copyright Copyright (C) 2005 - 2018 Open Source Matters, Inc. All rights reserved.
* @license GNU General Public License version 2 or later; see LICENSE.txt
*/
defined('_JEXEC') or die;
/**
* Rest model class for Users.
*
* @since 1.6
*/
class UsersModelLogin extends JModelForm
{
/**
* Method to get the login form.
*
* The base form is loaded from XML and then an event is fired
* for users plugins to extend the form with extra fields.
*
* @param array $data An optional array of data for the form to interogate.
* @param boolean $loadData True if the form is to load its own data (default case), false if not.
*
* @return JForm A JForm object on success, false on failure
*
* @since 1.6
*/
public function getForm($data = array(), $loadData = true)
{
// Get the form.
$form = $this->loadForm('com_users.login', 'login', array('load_data' => $loadData));
if (empty($form))
{
return false;
}
return $form;
}
/**
* Method to get the data that should be injected in the form.
*
* @return array The default data is an empty array.
*
* @since 1.6
*/
protected function loadFormData()
{
// Check the session for previously entered login form data.
$app = JFactory::getApplication();
$data = $app->getUserState('users.login.form.data', array());
$input = $app->input->getInputForRequestMethod();
// Check for return URL from the request first
if ($return = $input->get('return', '', 'BASE64'))
{
$data['return'] = base64_decode($return);
if (!JUri::isInternal($data['return']))
{
$data['return'] = '';
}
}
$app->setUserState('users.login.form.data', $data);
$this->preprocessData('com_users.login', $data);
return $data;
}
/**
* Method to auto-populate the model state.
*
* Calling getState in this method will result in recursion.
*
* @return void
*
* @since 1.6
*/
protected function populateState()
{
// Get the application object.
$params = JFactory::getApplication()->getParams('com_users');
// Load the parameters.
$this->setState('params', $params);
}
/**
* Override JModelAdmin::preprocessForm to ensure the correct plugin group is loaded.
*
* @param JForm $form A JForm object.
* @param mixed $data The data expected for the form.
* @param string $group The name of the plugin group to import (defaults to "content").
*
* @return void
*
* @since 1.6
* @throws Exception if there is an error in the form event.
*/
protected function preprocessForm(JForm $form, $data, $group = 'user')
{
parent::preprocessForm($form, $data, $group);
}
}

View File

@ -0,0 +1,15 @@
{
"finding_ref": "7272",
"log_excerpt": "[quarantine] www.archlinexp.eu:components/com_users/models/login.php -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/components/com_users/models/login.php)",
"original_sha256": "1bd545c9d69235efbd0ca01aa8e3fee5c0416f9d7e57647314f029d01c7bcb75",
"original_stat": {
"gid": 30037,
"mtime": 1533967367,
"size": 2737,
"uid": 12425
},
"rel_path": "components/com_users/models/login.php",
"result": "quarantined",
"timestamp": "20260718T160204Z",
"vhost": "www.archlinexp.eu"
}

View File

@ -0,0 +1,445 @@
<?php
/**
* @package Joomla.Site
* @subpackage com_users
*
* @copyright Copyright (C) 2005 - 2018 Open Source Matters, Inc. All rights reserved.
* @license GNU General Public License version 2 or later; see LICENSE.txt
*/
defined('_JEXEC') or die;
use Joomla\Registry\Registry;
/**
* Profile model class for Users.
*
* @since 1.6
*/
class UsersModelProfile extends JModelForm
{
/**
* @var object The user profile data.
* @since 1.6
*/
protected $data;
/**
* Constructor
*
* @param array $config An array of configuration options (name, state, dbo, table_path, ignore_request).
*
* @since 3.2
*
* @throws Exception
*/
public function __construct($config = array())
{
$config = array_merge(
array(
'events_map' => array('validate' => 'user')
), $config
);
parent::__construct($config);
// Load the helper and model used for two factor authentication
JLoader::register('UsersModelUser', JPATH_ADMINISTRATOR . '/components/com_users/models/user.php');
JLoader::register('UsersHelper', JPATH_ADMINISTRATOR . '/components/com_users/helpers/users.php');
}
/**
* Method to check in a user.
*
* @param integer $userId The id of the row to check out.
*
* @return boolean True on success, false on failure.
*
* @since 1.6
*/
public function checkin($userId = null)
{
// Get the user id.
$userId = (!empty($userId)) ? $userId : (int) $this->getState('user.id');
if ($userId)
{
// Initialise the table with JUser.
$table = JTable::getInstance('User');
// Attempt to check the row in.
if (!$table->checkin($userId))
{
$this->setError($table->getError());
return false;
}
}
return true;
}
/**
* Method to check out a user for editing.
*
* @param integer $userId The id of the row to check out.
*
* @return boolean True on success, false on failure.
*
* @since 1.6
*/
public function checkout($userId = null)
{
// Get the user id.
$userId = (!empty($userId)) ? $userId : (int) $this->getState('user.id');
if ($userId)
{
// Initialise the table with JUser.
$table = JTable::getInstance('User');
// Get the current user object.
$user = JFactory::getUser();
// Attempt to check the row out.
if (!$table->checkout($user->get('id'), $userId))
{
$this->setError($table->getError());
return false;
}
}
return true;
}
/**
* Method to get the profile form data.
*
* The base form data is loaded and then an event is fired
* for users plugins to extend the data.
*
* @return mixed Data object on success, false on failure.
*
* @since 1.6
*/
public function getData()
{
if ($this->data === null)
{
$userId = $this->getState('user.id');
// Initialise the table with JUser.
$this->data = new JUser($userId);
// Set the base user data.
$this->data->email1 = $this->data->get('email');
$this->data->email2 = $this->data->get('email');
// Override the base user data with any data in the session.
$temp = (array) JFactory::getApplication()->getUserState('com_users.edit.profile.data', array());
foreach ($temp as $k => $v)
{
$this->data->$k = $v;
}
// Unset the passwords.
unset($this->data->password1, $this->data->password2);
$registry = new Registry($this->data->params);
$this->data->params = $registry->toArray();
}
return $this->data;
}
/**
* Method to get the profile form.
*
* The base form is loaded from XML and then an event is fired
* for users plugins to extend the form with extra fields.
*
* @param array $data An optional array of data for the form to interogate.
* @param boolean $loadData True if the form is to load its own data (default case), false if not.
*
* @return JForm A JForm object on success, false on failure
*
* @since 1.6
*/
public function getForm($data = array(), $loadData = true)
{
// Get the form.
$form = $this->loadForm('com_users.profile', 'profile', array('control' => 'jform', 'load_data' => $loadData));
if (empty($form))
{
return false;
}
// Check for username compliance and parameter set
$isUsernameCompliant = true;
$username = $loadData ? $form->getValue('username') : $this->loadFormData()->username;
if ($username)
{
$isUsernameCompliant = !(preg_match('#[<>"\'%;()&\\\\]|\\.\\./#', $username) || strlen(utf8_decode($username)) < 2
|| trim($username) !== $username);
}
$this->setState('user.username.compliant', $isUsernameCompliant);
if ($isUsernameCompliant && !JComponentHelper::getParams('com_users')->get('change_login_name'))
{
$form->setFieldAttribute('username', 'class', '');
$form->setFieldAttribute('username', 'filter', '');
$form->setFieldAttribute('username', 'description', 'COM_USERS_PROFILE_NOCHANGE_USERNAME_DESC');
$form->setFieldAttribute('username', 'validate', '');
$form->setFieldAttribute('username', 'message', '');
$form->setFieldAttribute('username', 'readonly', 'true');
$form->setFieldAttribute('username', 'required', 'false');
}
// When multilanguage is set, a user's default site language should also be a Content Language
if (JLanguageMultilang::isEnabled())
{
$form->setFieldAttribute('language', 'type', 'frontend_language', 'params');
}
// If the user needs to change their password, mark the password fields as required
if (JFactory::getUser()->requireReset)
{
$form->setFieldAttribute('password1', 'required', 'true');
$form->setFieldAttribute('password2', 'required', 'true');
}
return $form;
}
/**
* Method to get the data that should be injected in the form.
*
* @return mixed The data for the form.
*
* @since 1.6
*/
protected function loadFormData()
{
$data = $this->getData();
$this->preprocessData('com_users.profile', $data, 'user');
return $data;
}
/**
* Override preprocessForm to load the user plugin group instead of content.
*
* @param JForm $form A JForm object.
* @param mixed $data The data expected for the form.
* @param string $group The name of the plugin group to import (defaults to "content").
*
* @return void
*
* @throws Exception if there is an error in the form event.
*
* @since 1.6
*/
protected function preprocessForm(JForm $form, $data, $group = 'user')
{
if (JComponentHelper::getParams('com_users')->get('frontend_userparams'))
{
$form->loadFile('frontend', false);
if (JFactory::getUser()->authorise('core.login.admin'))
{
$form->loadFile('frontend_admin', false);
}
}
parent::preprocessForm($form, $data, $group);
}
/**
* Method to auto-populate the model state.
*
* Note. Calling getState in this method will result in recursion.
*
* @return void
*
* @since 1.6
*/
protected function populateState()
{
// Get the application object.
$params = JFactory::getApplication()->getParams('com_users');
// Get the user id.
$userId = JFactory::getApplication()->getUserState('com_users.edit.profile.id');
$userId = !empty($userId) ? $userId : (int) JFactory::getUser()->get('id');
// Set the user id.
$this->setState('user.id', $userId);
// Load the parameters.
$this->setState('params', $params);
}
/**
* Method to save the form data.
*
* @param array $data The form data.
*
* @return mixed The user id on success, false on failure.
*
* @since 1.6
*/
public function save($data)
{
$userId = (!empty($data['id'])) ? $data['id'] : (int) $this->getState('user.id');
$user = new JUser($userId);
// Prepare the data for the user object.
$data['email'] = JStringPunycode::emailToPunycode($data['email1']);
$data['password'] = $data['password1'];
// Unset the username if it should not be overwritten
$isUsernameCompliant = $this->getState('user.username.compliant');
if ($isUsernameCompliant && !JComponentHelper::getParams('com_users')->get('change_login_name'))
{
unset($data['username']);
}
// Unset block and sendEmail so they do not get overwritten
unset($data['block'], $data['sendEmail']);
// Handle the two factor authentication setup
if (array_key_exists('twofactor', $data))
{
$model = new UsersModelUser;
$twoFactorMethod = $data['twofactor']['method'];
// Get the current One Time Password (two factor auth) configuration
$otpConfig = $model->getOtpConfig($userId);
if ($twoFactorMethod !== 'none')
{
// Run the plugins
FOFPlatform::getInstance()->importPlugin('twofactorauth');
$otpConfigReplies = FOFPlatform::getInstance()->runPlugins('onUserTwofactorApplyConfiguration', array($twoFactorMethod));
// Look for a valid reply
foreach ($otpConfigReplies as $reply)
{
if (!is_object($reply) || empty($reply->method) || ($reply->method != $twoFactorMethod))
{
continue;
}
$otpConfig->method = $reply->method;
$otpConfig->config = $reply->config;
break;
}
// Save OTP configuration.
$model->setOtpConfig($userId, $otpConfig);
// Generate one time emergency passwords if required (depleted or not set)
if (empty($otpConfig->otep))
{
$model->generateOteps($userId);
}
}
else
{
$otpConfig->method = 'none';
$otpConfig->config = array();
$model->setOtpConfig($userId, $otpConfig);
}
// Unset the raw data
unset($data['twofactor']);
// Reload the user record with the updated OTP configuration
$user->load($userId);
}
// Bind the data.
if (!$user->bind($data))
{
$this->setError(JText::sprintf('COM_USERS_PROFILE_BIND_FAILED', $user->getError()));
return false;
}
// Load the users plugin group.
JPluginHelper::importPlugin('user');
// Retrieve the user groups so they don't get overwritten
unset($user->groups);
$user->groups = JAccess::getGroupsByUser($user->id, false);
// Store the data.
if (!$user->save())
{
$this->setError($user->getError());
return false;
}
// Some contexts may not use tags data at all, so we allow callers to disable loading tag data
if ($this->getState('load_tags', true))
{
$user->tags = new JHelperTags;
$user->tags->getTagIds($user->id, 'com_users.user');
}
return $user->id;
}
/**
* Gets the configuration forms for all two-factor authentication methods
* in an array.
*
* @param integer $user_id The user ID to load the forms for (optional)
*
* @return array
*
* @since 3.2
*/
public function getTwofactorform($user_id = null)
{
$user_id = (!empty($user_id)) ? $user_id : (int) $this->getState('user.id');
$model = new UsersModelUser;
$otpConfig = $model->getOtpConfig($user_id);
FOFPlatform::getInstance()->importPlugin('twofactorauth');
return FOFPlatform::getInstance()->runPlugins('onUserTwofactorShowConfiguration', array($otpConfig, $user_id));
}
/**
* Returns the one time password (OTP) a.k.a. two factor authentication
* configuration for a particular user.
*
* @param integer $user_id The numeric ID of the user
*
* @return stdClass An object holding the OTP configuration for this user
*
* @since 3.2
*/
public function getOtpConfig($user_id = null)
{
$user_id = (!empty($user_id)) ? $user_id : (int) $this->getState('user.id');
$model = new UsersModelUser;
return $model->getOtpConfig($user_id);
}
}

View File

@ -0,0 +1,15 @@
{
"finding_ref": "7276",
"log_excerpt": "[quarantine] www.archlinexp.eu:components/com_users/models/profile.php -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/components/com_users/models/profile.php)",
"original_sha256": "9120583bc9b1fc6d5c5b7a81fdd14c2d18250715cc89c672b743038cd62f7682",
"original_stat": {
"gid": 30037,
"mtime": 1533967367,
"size": 11442,
"uid": 12425
},
"rel_path": "components/com_users/models/profile.php",
"result": "quarantined",
"timestamp": "20260718T160204Z",
"vhost": "www.archlinexp.eu"
}

View File

@ -0,0 +1,773 @@
<?php
/**
* @package Joomla.Site
* @subpackage com_users
*
* @copyright Copyright (C) 2005 - 2018 Open Source Matters, Inc. All rights reserved.
* @license GNU General Public License version 2 or later; see LICENSE.txt
*/
defined('_JEXEC') or die;
/**
* Registration model class for Users.
*
* @since 1.6
*/
class UsersModelRegistration extends JModelForm
{
/**
* @var object The user registration data.
* @since 1.6
*/
protected $data;
/**
* Constructor
*
* @param array $config An array of configuration options (name, state, dbo, table_path, ignore_request).
*
* @since 3.6
*
* @throws Exception
*/
public function __construct($config = array())
{
$config = array_merge(
array(
'events_map' => array('validate' => 'user')
),
$config
);
parent::__construct($config);
}
/**
* Method to activate a user account.
*
* @param string $token The activation token.
*
* @return mixed False on failure, user object on success.
*
* @since 1.6
*/
public function activate($token)
{
$config = JFactory::getConfig();
$userParams = JComponentHelper::getParams('com_users');
$db = $this->getDbo();
// Get the user id based on the token.
$query = $db->getQuery(true);
$query->select($db->quoteName('id'))
->from($db->quoteName('#__users'))
->where($db->quoteName('activation') . ' = ' . $db->quote($token))
->where($db->quoteName('block') . ' = ' . 1)
->where($db->quoteName('lastvisitDate') . ' = ' . $db->quote($db->getNullDate()));
$db->setQuery($query);
try {
$userId = (int) $db->loadResult();
} catch (RuntimeException $e) {
$this->setError(JText::sprintf('COM_USERS_DATABASE_ERROR', $e->getMessage()), 500);
return false;
}
// Check for a valid user id.
if (!$userId) {
$this->setError(JText::_('COM_USERS_ACTIVATION_TOKEN_NOT_FOUND'));
return false;
}
// Load the users plugin group.
JPluginHelper::importPlugin('user');
// Activate the user.
$user = JFactory::getUser($userId);
// Admin activation is on and user is verifying their email
if (($userParams->get('useractivation') == 2) && !$user->getParam('activate', 0)) {
$uri = JUri::getInstance();
// Compile the admin notification mail values.
$data = $user->getProperties();
$data['activation'] = JApplicationHelper::getHash(JUserHelper::genRandomPassword());
$user->set('activation', $data['activation']);
$data['siteurl'] = JUri::base();
$base = $uri->toString(array('scheme', 'user', 'pass', 'host', 'port'));
$data['activate'] = $base . JRoute::_('index.php?option=com_users&task=registration.activate&token=' . $data['activation'], false);
// Remove administrator/ from activate URL in case this method is called from admin
if (JFactory::getApplication()->isClient('administrator')) {
$adminPos = strrpos($data['activate'], 'administrator/');
$data['activate'] = substr_replace($data['activate'], '', $adminPos, 14);
}
$data['fromname'] = $config->get('fromname');
$data['mailfrom'] = $config->get('mailfrom');
$data['sitename'] = $config->get('sitename');
$user->setParam('activate', 1);
$emailSubject = JText::sprintf(
'COM_USERS_EMAIL_ACTIVATE_WITH_ADMIN_ACTIVATION_SUBJECT',
$data['name'],
$data['sitename']
);
$emailBody = JText::sprintf(
'COM_USERS_EMAIL_ACTIVATE_WITH_ADMIN_ACTIVATION_BODY',
$data['sitename'],
$data['name'],
$data['email'],
$data['username'],
$data['activate']
);
// Get all admin users
$query->clear()
->select($db->quoteName(array('name', 'email', 'sendEmail', 'id')))
->from($db->quoteName('#__users'))
->where($db->quoteName('sendEmail') . ' = 1')
->where($db->quoteName('block') . ' = 0');
$db->setQuery($query);
try {
$rows = $db->loadObjectList();
} catch (RuntimeException $e) {
$this->setError(JText::sprintf('COM_USERS_DATABASE_ERROR', $e->getMessage()), 500);
return false;
}
// Send mail to all users with users creating permissions and receiving system emails
foreach ($rows as $row) {
$usercreator = JFactory::getUser($row->id);
if ($usercreator->authorise('core.create', 'com_users')) {
$return = JFactory::getMailer()->sendMail($data['mailfrom'], $data['fromname'], $row->email, $emailSubject, $emailBody);
// Check for an error.
if ($return !== true) {
$this->setError(JText::_('COM_USERS_REGISTRATION_ACTIVATION_NOTIFY_SEND_MAIL_FAILED'));
return false;
}
}
}
}
// Admin activation is on and admin is activating the account
elseif (($userParams->get('useractivation') == 2) && $user->getParam('activate', 0)) {
$user->set('activation', '');
$user->set('block', '0');
// Compile the user activated notification mail values.
$data = $user->getProperties();
$user->setParam('activate', 0);
$data['fromname'] = $config->get('fromname');
$data['mailfrom'] = $config->get('mailfrom');
$data['sitename'] = $config->get('sitename');
$data['siteurl'] = JUri::base();
$emailSubject = JText::sprintf(
'COM_USERS_EMAIL_ACTIVATED_BY_ADMIN_ACTIVATION_SUBJECT',
$data['name'],
$data['sitename']
);
$emailBody = JText::sprintf(
'COM_USERS_EMAIL_ACTIVATED_BY_ADMIN_ACTIVATION_BODY',
$data['name'],
$data['siteurl'],
$data['username']
);
$return = JFactory::getMailer()->sendMail($data['mailfrom'], $data['fromname'], $data['email'], $emailSubject, $emailBody);
// Check for an error.
if ($return !== true) {
$this->setError(JText::_('COM_USERS_REGISTRATION_ACTIVATION_NOTIFY_SEND_MAIL_FAILED'));
return false;
}
} else {
$user->set('activation', '');
$user->set('block', '0');
}
// Store the user object.
if (!$user->save()) {
$this->setError(JText::sprintf('COM_USERS_REGISTRATION_ACTIVATION_SAVE_FAILED', $user->getError()));
return false;
}
return $user;
}
/**
* Method to get the registration form data.
*
* The base form data is loaded and then an event is fired
* for users plugins to extend the data.
*
* @return mixed Data object on success, false on failure.
*
* @since 1.6
*/
public function getData()
{
if ($this->data === null) {
$this->data = new stdClass;
$app = JFactory::getApplication();
$params = JComponentHelper::getParams('com_users');
// Override the base user data with any data in the session.
$temp = (array) $app->getUserState('com_users.registration.data', array());
// Don't load the data in this getForm call, or we'll call ourself
$form = $this->getForm(array(), false);
foreach ($temp as $k => $v) {
// Here we could have a grouped field, let's check it
if (is_array($v)) {
$this->data->$k = new stdClass;
foreach ($v as $key => $val) {
if ($form->getField($key, $k) !== false) {
$this->data->$k->$key = $val;
}
}
}
// Only merge the field if it exists in the form.
elseif ($form->getField($k) !== false) {
$this->data->$k = $v;
}
}
// Get the groups the user should be added to after registration.
$this->data->groups = array();
// Get the default new user group, Registered if not specified.
$system = $params->get('new_usertype', 2);
$this->data->groups[] = $system;
// Unset the passwords.
unset($this->data->password1, $this->data->password2);
// Get the dispatcher and load the users plugins.
$dispatcher = JEventDispatcher::getInstance();
JPluginHelper::importPlugin('user');
// Trigger the data preparation event.
$results = $dispatcher->trigger('onContentPrepareData', array('com_users.registration', $this->data));
// Check for errors encountered while preparing the data.
if (count($results) && in_array(false, $results, true)) {
$this->setError($dispatcher->getError());
$this->data = false;
}
}
return $this->data;
}
/**
* Method to get the registration form.
*
* The base form is loaded from XML and then an event is fired
* for users plugins to extend the form with extra fields.
*
* @param array $data An optional array of data for the form to interogate.
* @param boolean $loadData True if the form is to load its own data (default case), false if not.
*
* @return JForm A JForm object on success, false on failure
*
* @since 1.6
*/
public function getForm($data = array(), $loadData = true)
{
// Get the form.
$form = $this->loadForm('com_users.registration', 'registration', array('control' => 'jform', 'load_data' => $loadData));
if (empty($form)) {
return false;
}
// When multilanguage is set, a user's default site language should also be a Content Language
if (JLanguageMultilang::isEnabled()) {
$form->setFieldAttribute('language', 'type', 'frontend_language', 'params');
}
return $form;
}
/**
* Method to get the data that should be injected in the form.
*
* @return mixed The data for the form.
*
* @since 1.6
*/
protected function loadFormData()
{
$data = $this->getData();
if (JLanguageMultilang::isEnabled() && empty($data->language)) {
$data->language = JFactory::getLanguage()->getTag();
}
$this->preprocessData('com_users.registration', $data);
return $data;
}
/**
* Override preprocessForm to load the user plugin group instead of content.
*
* @param JForm $form A JForm object.
* @param mixed $data The data expected for the form.
* @param string $group The name of the plugin group to import (defaults to "content").
*
* @return void
*
* @since 1.6
* @throws Exception if there is an error in the form event.
*/
protected function preprocessForm(JForm $form, $data, $group = 'user')
{
$userParams = JComponentHelper::getParams('com_users');
// Add the choice for site language at registration time
if ($userParams->get('site_language') == 1 && $userParams->get('frontend_userparams') == 1) {
$form->loadFile('sitelang', false);
}
parent::preprocessForm($form, $data, $group);
}
/**
* Method to auto-populate the model state.
*
* Note. Calling getState in this method will result in recursion.
*
* @return void
*
* @since 1.6
*/
protected function populateState()
{
// Get the application object.
$app = JFactory::getApplication();
$params = $app->getParams('com_users');
// Load the parameters.
$this->setState('params', $params);
}
/**
* Method to save the form data.
*
* @param array $temp The form data.
*
* @return mixed The user id on success, false on failure.
*
* @since 1.6
*/
public function register($temp)
{
$params = JComponentHelper::getParams('com_users');
// Initialise the table with JUser.
$user = new JUser;
$data = (array) $this->getData();
// Merge in the registration data.
foreach ($temp as $k => $v) {
$data[$k] = $v;
}
// Prepare the data for the user object.
$data['email'] = JStringPunycode::emailToPunycode($data['email1']);
$data['name'] = $data['firstname']; // N.M. Az új registration form miatt kellett. Az emailben kiküldött név nem úgy jelent meg, ahogy kéne
$data['name'] .= ' ';
$data['name'] .= $data['lastname'];
$data['password'] = $data['password1'];
$useractivation = $params->get('useractivation');
$sendpassword = $params->get('sendpassword', 1);
// Check if the user needs to activate their account.
if (($useractivation == 1) || ($useractivation == 2)) {
$data['activation'] = JApplicationHelper::getHash(JUserHelper::genRandomPassword());
$data['block'] = 1;
}
// Bind the data.
if (!$user->bind($data)) {
$this->setError(JText::sprintf('COM_USERS_REGISTRATION_BIND_FAILED', $user->getError()));
return false;
}
// Load the users plugin group.
JPluginHelper::importPlugin('user');
// Store the data.
if (!$user->save()) {
$this->setError(JText::sprintf('COM_USERS_REGISTRATION_SAVE_FAILED', $user->getError()));
return false;
}
$config = JFactory::getConfig();
$db = $this->getDbo();
$query = $db->getQuery(true);
// Compile the notification mail values.
$data = $user->getProperties();
$data['fromname'] = $config->get('fromname');
$data['mailfrom'] = $config->get('mailfrom');
$data['sitename'] = $config->get('sitename');
$data['siteurl'] = JUri::root();
// Handle account activation/confirmation emails.
if ($useractivation == 2) {
// Set the link to confirm the user email.
$uri = JUri::getInstance();
$base = $uri->toString(array('scheme', 'user', 'pass', 'host', 'port'));
$data['activate'] = $base . JRoute::_('index.php?option=com_users&task=registration.activate&token=' . $data['activation'], false);
// Remove administrator/ from activate URL in case this method is called from admin
if (JFactory::getApplication()->isClient('administrator')) {
$adminPos = strrpos($data['activate'], 'administrator/');
$data['activate'] = substr_replace($data['activate'], '', $adminPos, 14);
}
$emailSubject = JText::sprintf(
'COM_USERS_EMAIL_ACCOUNT_DETAILS',
$data['name'],
$data['sitename']
);
if ($sendpassword) {
$emailBody = JText::sprintf(
'COM_USERS_EMAIL_REGISTERED_WITH_ADMIN_ACTIVATION_BODY',
$data['name'],
$data['sitename'],
$data['activate'],
$data['siteurl'],
$data['username'],
$data['password_clear']
);
} else {
$emailBody = JText::sprintf(
'COM_USERS_EMAIL_REGISTERED_WITH_ADMIN_ACTIVATION_BODY_NOPW',
$data['name'],
$data['sitename'],
$data['activate'],
$data['siteurl'],
$data['username']
);
}
} elseif ($useractivation == 1) {
// Set the link to activate the user account.
$uri = JUri::getInstance();
$base = $uri->toString(array('scheme', 'user', 'pass', 'host', 'port'));
$data['activate'] = $base . JRoute::_('index.php?option=com_users&task=registration.activate&token=' . $data['activation'], false);
// Remove administrator/ from activate URL in case this method is called from admin
if (JFactory::getApplication()->isClient('administrator')) {
$adminPos = strrpos($data['activate'], 'administrator/');
$data['activate'] = substr_replace($data['activate'], '', $adminPos, 14);
}
$emailSubject = JText::sprintf(
'COM_USERS_EMAIL_ACCOUNT_DETAILS',
$data['name'],
$data['sitename']
);
if ($sendpassword) {
$emailBody = JText::sprintf(
'COM_USERS_EMAIL_REGISTERED_WITH_ACTIVATION_BODY',
$data['name'],
$data['sitename'],
$data['activate'],
$data['siteurl'],
$data['username'],
$data['password_clear']
);
} else {
$emailBody = JText::sprintf(
'COM_USERS_EMAIL_REGISTERED_WITH_ACTIVATION_BODY_NOPW',
$data['name'],
$data['sitename'],
$data['activate'],
$data['siteurl'],
$data['username']
);
}
} else {
$emailSubject = JText::sprintf(
'COM_USERS_EMAIL_ACCOUNT_DETAILS',
$data['name'],
$data['sitename']
);
if ($sendpassword) {
$emailBody = JText::sprintf(
'COM_USERS_EMAIL_REGISTERED_BODY',
$data['name'],
$data['sitename'],
$data['siteurl'],
$data['username'],
$data['password_clear']
);
} else {
$emailBody = JText::sprintf(
'COM_USERS_EMAIL_REGISTERED_BODY_NOPW',
$data['name'],
$data['sitename'],
$data['siteurl']
);
}
}
// Send the registration email.
$return = JFactory::getMailer()->sendMail($data['mailfrom'], $data['fromname'], $data['email'], $emailSubject, $emailBody);
// Send Notification mail to administrators
if (($params->get('useractivation') < 2) && ($params->get('mail_to_admin') == 1)) {
$emailSubject = JText::sprintf(
'COM_USERS_EMAIL_ACCOUNT_DETAILS',
$data['name'],
$data['sitename']
);
$emailBodyAdmin = JText::sprintf(
'COM_USERS_EMAIL_REGISTERED_NOTIFICATION_TO_ADMIN_BODY',
$data['name'],
$data['username'],
$data['siteurl']
);
// Get all admin users
$query->clear()
->select($db->quoteName(array('name', 'email', 'sendEmail')))
->from($db->quoteName('#__users'))
->where($db->quoteName('sendEmail') . ' = 1')
->where($db->quoteName('block') . ' = 0');
$db->setQuery($query);
try {
$rows = $db->loadObjectList();
} catch (RuntimeException $e) {
$this->setError(JText::sprintf('COM_USERS_DATABASE_ERROR', $e->getMessage()), 500);
return false;
}
// Send mail to all superadministrators id
foreach ($rows as $row) {
$return = JFactory::getMailer()->sendMail($data['mailfrom'], $data['fromname'], $row->email, $emailSubject, $emailBodyAdmin);
// Check for an error.
if ($return !== true) {
$this->setError(JText::_('COM_USERS_REGISTRATION_ACTIVATION_NOTIFY_SEND_MAIL_FAILED'));
return false;
}
}
}
// Check for an error.
if ($return !== true) {
$this->setError(JText::_('COM_USERS_REGISTRATION_SEND_MAIL_FAILED'));
// Send a system message to administrators receiving system mails
$db = $this->getDbo();
$query->clear()
->select($db->quoteName('id'))
->from($db->quoteName('#__users'))
->where($db->quoteName('block') . ' = ' . (int) 0)
->where($db->quoteName('sendEmail') . ' = ' . (int) 1);
$db->setQuery($query);
try {
$userids = $db->loadColumn();
} catch (RuntimeException $e) {
$this->setError(JText::sprintf('COM_USERS_DATABASE_ERROR', $e->getMessage()), 500);
return false;
}
if (count($userids) > 0) {
$jdate = new JDate;
// Build the query to add the messages
foreach ($userids as $userid) {
$values = array(
$db->quote($userid),
$db->quote($userid),
$db->quote($jdate->toSql()),
$db->quote(JText::_('COM_USERS_MAIL_SEND_FAILURE_SUBJECT')),
$db->quote(JText::sprintf('COM_USERS_MAIL_SEND_FAILURE_BODY', $return, $data['username']))
);
$query->clear()
->insert($db->quoteName('#__messages'))
->columns($db->quoteName(array('user_id_from', 'user_id_to', 'date_time', 'subject', 'message')))
->values(implode(',', $values));
$db->setQuery($query);
try {
$db->execute();
} catch (RuntimeException $e) {
$this->setError(JText::sprintf('COM_USERS_DATABASE_ERROR', $e->getMessage()), 500);
return false;
}
}
}
return false;
}
if ($useractivation == 1) {
return 'useractivate';
} elseif ($useractivation == 2) {
return 'adminactivate';
} else {
return $user->id;
}
}
private function checkCaptcha($response)
{
$secret = '';
if ($_SERVER['SERVER_NAME'] == 'www.archline.hu')
$secret = '6Lc8nh8TAAAAALeRGLDbjsr7Rh1qpQJkYXYO-P50';
else
$secret = '6LeqnB8TAAAAAJTatP1dt8npqwDfJLz4_i9-rbNg';
$post_data = http_build_query(
array(
'secret' => $secret,
'response' => $response,
'remoteip' => $_SERVER['REMOTE_ADDR']
)
);
$opts = array(
'http' =>
array(
'method' => 'POST',
'header' => 'Content-type: application/x-www-form-urlencoded',
'content' => $post_data
)
);
$context = stream_context_create($opts);
$response = file_get_contents('https://www.google.com/recaptcha/api/siteverify', false, $context);
$result = json_decode($response);
return $result->success;
}
private function phoneCorrect(&$phone)
{
$phone = str_replace('-', '', $phone);
$phone = str_replace(' ', '', $phone);
$phone = str_replace('+', '', $phone);
$phone = str_replace('/', '', $phone);
$phone = str_replace('.', '', $phone);
$phone = str_replace(' ', '', $phone);
return $phone;
}
public function registerWithARCHLine($temp, &$message)
{
if (!class_exists('crm_hardlock')) require_once(JPATH_BASE . "/common_cadline_libraries/crm_hardlock.class.php");
$resource = new Resource($temp['country']);
$captchaResult = $this->checkCaptcha($temp['captcha']);
if (!$captchaResult) {
$message = $resource->getDlgString('10947');
return false;
}
$query = "SELECT * FROM www_archline_hu.jml_users WHERE username = ? OR email = ?";
Database::getInstance()->query($query, array('ss', $temp['email'], $temp['email']));
$res = Database::getInstance()->fetchNext();
if (!empty($res)) {
$message = $resource->getDlgString('10789');
return false;
}
if ($temp['password'] != $temp['password2']) {
$message = $resource->getDlgString('10792');
return false;
}
// Initialise the table with JUser.
$user = new JUser;
$data = (array) $this->getData();
// Merge in the registration data.
foreach ($temp as $k => $v) {
$data[$k] = $v;
}
$user->bind($data);
if (!$user->save()) {
$message = JText::sprintf('COM_USERS_REGISTRATION_SAVE_FAILED', $user->getError());
return false;
}
$profile_phone = array(
'user_id' => $user->id,
'profile_key' => 'profile.phone',
'profile_value' => $temp['phone'],
'ordering' => 7
);
$profile_country = array(
'user_id' => $user->id,
'profile_key' => 'profile.country',
'profile_value' => $temp['country'],
'ordering' => 5
);
Database::getInstance()->insert('www_archline_hu.jml_user_profiles', $profile_phone, 'issi');
Database::getInstance()->insert('www_archline_hu.jml_user_profiles', $profile_country, 'issi');
$this->phoneCorrect($temp['phone']);
$query = "SELECT * FROM www_archline_hu.jml_users WHERE id = ?";
Database::getInstance()->query($query, array('i', $user->id));
$jmlUser = Database::getInstance()->fetchNext();
Database::getInstance()->update(
'cl_hlusers.users',
array(
'strTel' => $temp['phone'],
'nCtrID' => $temp['country']
),
array('nUserID' => $jmlUser['nUserID']),
'sii'
);
$message = $resource->getDlgString('10793');
return $user->id;
}
}

View File

@ -0,0 +1,15 @@
{
"finding_ref": "7275",
"log_excerpt": "[quarantine] www.archlinexp.eu:components/com_users/models/registration.php -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/components/com_users/models/registration.php)",
"original_sha256": "36f98683f5d734fd65acabfd638da4bff54196ce0f4fc2574c23ab9ef9b66ba6",
"original_stat": {
"gid": 30037,
"mtime": 1658220713,
"size": 22646,
"uid": 12425
},
"rel_path": "components/com_users/models/registration.php",
"result": "quarantined",
"timestamp": "20260718T160204Z",
"vhost": "www.archlinexp.eu"
}

View File

@ -0,0 +1,198 @@
<?php
/**
* @package Joomla.Site
* @subpackage com_users
*
* @copyright Copyright (C) 2005 - 2018 Open Source Matters, Inc. All rights reserved.
* @license GNU General Public License version 2 or later; see LICENSE.txt
*/
defined('_JEXEC') or die;
use Joomla\Utilities\ArrayHelper;
/**
* Remind model class for Users.
*
* @since 1.5
*/
class UsersModelRemind extends JModelForm
{
/**
* Method to get the username remind request form.
*
* @param array $data An optional array of data for the form to interogate.
* @param boolean $loadData True if the form is to load its own data (default case), false if not.
*
* @return JFor A JForm object on success, false on failure
*
* @since 1.6
*/
public function getForm($data = array(), $loadData = true)
{
// Get the form.
$form = $this->loadForm('com_users.remind', 'remind', array('control' => 'jform', 'load_data' => $loadData));
if (empty($form))
{
return false;
}
return $form;
}
/**
* Override preprocessForm to load the user plugin group instead of content.
*
* @param JForm $form A JForm object.
* @param mixed $data The data expected for the form.
* @param string $group The name of the plugin group to import (defaults to "content").
*
* @return void
*
* @throws Exception if there is an error in the form event.
*
* @since 1.6
*/
protected function preprocessForm(JForm $form, $data, $group = 'user')
{
parent::preprocessForm($form, $data, 'user');
}
/**
* Method to auto-populate the model state.
*
* Note. Calling getState in this method will result in recursion.
*
* @return void
*
* @since 1.6
*/
protected function populateState()
{
// Get the application object.
$app = JFactory::getApplication();
$params = $app->getParams('com_users');
// Load the parameters.
$this->setState('params', $params);
}
/**
* Send the remind username email
*
* @param array $data Array with the data received from the form
*
* @return boolean
*
* @since 1.6
*/
public function processRemindRequest($data)
{
// Get the form.
$form = $this->getForm();
$data['email'] = JStringPunycode::emailToPunycode($data['email']);
// Check for an error.
if (empty($form))
{
return false;
}
// Validate the data.
$data = $this->validate($form, $data);
// Check for an error.
if ($data instanceof Exception)
{
return false;
}
// Check the validation results.
if ($data === false)
{
// Get the validation messages from the form.
foreach ($form->getErrors() as $formError)
{
$this->setError($formError->getMessage());
}
return false;
}
// Find the user id for the given email address.
$db = $this->getDbo();
$query = $db->getQuery(true)
->select('*')
->from($db->quoteName('#__users'))
->where($db->quoteName('email') . ' = ' . $db->quote($data['email']));
// Get the user id.
$db->setQuery($query);
try
{
$user = $db->loadObject();
}
catch (RuntimeException $e)
{
$this->setError(JText::sprintf('COM_USERS_DATABASE_ERROR', $e->getMessage()), 500);
return false;
}
// Check for a user.
if (empty($user))
{
$this->setError(JText::_('COM_USERS_USER_NOT_FOUND'));
return false;
}
// Make sure the user isn't blocked.
if ($user->block)
{
$this->setError(JText::_('COM_USERS_USER_BLOCKED'));
return false;
}
$config = JFactory::getConfig();
// Assemble the login link.
$link = 'index.php?option=com_users&view=login';
$mode = $config->get('force_ssl', 0) == 2 ? 1 : (-1);
// Put together the email template data.
$data = ArrayHelper::fromObject($user);
$data['fromname'] = $config->get('fromname');
$data['mailfrom'] = $config->get('mailfrom');
$data['sitename'] = $config->get('sitename');
$data['link_text'] = JRoute::_($link, false, $mode);
$data['link_html'] = JRoute::_($link, true, $mode);
$subject = JText::sprintf(
'COM_USERS_EMAIL_USERNAME_REMINDER_SUBJECT',
$data['sitename']
);
$body = JText::sprintf(
'COM_USERS_EMAIL_USERNAME_REMINDER_BODY',
$data['sitename'],
$data['username'],
$data['link_text']
);
// Send the password reset request email.
$return = JFactory::getMailer()->sendMail($data['mailfrom'], $data['fromname'], $user->email, $subject, $body);
// Check for an error.
if ($return !== true)
{
$this->setError(JText::_('COM_USERS_MAIL_FAILED'), 500);
return false;
}
return true;
}
}

View File

@ -0,0 +1,15 @@
{
"finding_ref": "7273",
"log_excerpt": "[quarantine] www.archlinexp.eu:components/com_users/models/remind.php -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/components/com_users/models/remind.php)",
"original_sha256": "25d8b3522b7b6fc0456dda7a2cc346c94e9b3889f4180d32f3e3101998791f1a",
"original_stat": {
"gid": 30037,
"mtime": 1533967367,
"size": 4537,
"uid": 12425
},
"rel_path": "components/com_users/models/remind.php",
"result": "quarantined",
"timestamp": "20260718T160204Z",
"vhost": "www.archlinexp.eu"
}

View File

@ -0,0 +1,523 @@
<?php
/**
* @package Joomla.Site
* @subpackage com_users
*
* @copyright Copyright (C) 2005 - 2018 Open Source Matters, Inc. All rights reserved.
* @license GNU General Public License version 2 or later; see LICENSE.txt
*/
defined('_JEXEC') or die;
/**
* Rest model class for Users.
*
* @since 1.5
*/
class UsersModelReset extends JModelForm
{
/**
* Method to get the password reset request form.
*
* The base form is loaded from XML and then an event is fired
* for users plugins to extend the form with extra fields.
*
* @param array $data An optional array of data for the form to interogate.
* @param boolean $loadData True if the form is to load its own data (default case), false if not.
*
* @return JForm A JForm object on success, false on failure
*
* @since 1.6
*/
public function getForm($data = array(), $loadData = true)
{
// Get the form.
$form = $this->loadForm('com_users.reset_request', 'reset_request', array('control' => 'jform', 'load_data' => $loadData));
if (empty($form))
{
return false;
}
return $form;
}
/**
* Method to get the password reset complete form.
*
* @param array $data Data for the form.
* @param boolean $loadData True if the form is to load its own data (default case), false if not.
*
* @return JForm A JForm object on success, false on failure
*
* @since 1.6
*/
public function getResetCompleteForm($data = array(), $loadData = true)
{
// Get the form.
$form = $this->loadForm('com_users.reset_complete', 'reset_complete', $options = array('control' => 'jform'));
if (empty($form))
{
return false;
}
return $form;
}
/**
* Method to get the password reset confirm form.
*
* @param array $data Data for the form.
* @param boolean $loadData True if the form is to load its own data (default case), false if not.
*
* @return JForm A JForm object on success, false on failure
*
* @since 1.6
*/
public function getResetConfirmForm($data = array(), $loadData = true)
{
// Get the form.
$form = $this->loadForm('com_users.reset_confirm', 'reset_confirm', $options = array('control' => 'jform'));
if (empty($form))
{
return false;
}
else
{
$form->setValue('token', '', JFactory::getApplication()->input->get('token'));
}
return $form;
}
/**
* Override preprocessForm to load the user plugin group instead of content.
*
* @param JForm $form A JForm object.
* @param mixed $data The data expected for the form.
* @param string $group The name of the plugin group to import (defaults to "content").
*
* @return void
*
* @throws Exception if there is an error in the form event.
*
* @since 1.6
*/
protected function preprocessForm(JForm $form, $data, $group = 'user')
{
parent::preprocessForm($form, $data, $group);
}
/**
* Method to auto-populate the model state.
*
* Note. Calling getState in this method will result in recursion.
*
* @return void
*
* @since 1.6
*/
protected function populateState()
{
// Get the application object.
$params = JFactory::getApplication()->getParams('com_users');
// Load the parameters.
$this->setState('params', $params);
}
/**
* Save the new password after reset is done
*
* @param array $data The data expected for the form.
*
* @return mixed Exception | JException | boolean
*
* @since 1.6
*/
public function processResetComplete($data)
{
// Get the form.
$form = $this->getResetCompleteForm();
$data['email'] = JStringPunycode::emailToPunycode($data['email']);
// Check for an error.
if ($form instanceof Exception)
{
return $form;
}
// Filter and validate the form data.
$data = $form->filter($data);
$return = $form->validate($data);
// Check for an error.
if ($return instanceof Exception)
{
return $return;
}
// Check the validation results.
if ($return === false)
{
// Get the validation messages from the form.
foreach ($form->getErrors() as $formError)
{
$this->setError($formError->getMessage());
}
return false;
}
// Get the token and user id from the confirmation process.
$app = JFactory::getApplication();
$token = $app->getUserState('com_users.reset.token', null);
$userId = $app->getUserState('com_users.reset.user', null);
// Check the token and user id.
if (empty($token) || empty($userId))
{
return new JException(JText::_('COM_USERS_RESET_COMPLETE_TOKENS_MISSING'), 403);
}
// Get the user object.
$user = JUser::getInstance($userId);
// Check for a user and that the tokens match.
if (empty($user) || $user->activation !== $token)
{
$this->setError(JText::_('COM_USERS_USER_NOT_FOUND'));
return false;
}
// Make sure the user isn't blocked.
if ($user->block)
{
$this->setError(JText::_('COM_USERS_USER_BLOCKED'));
return false;
}
// Check if the user is reusing the current password if required to reset their password
if ($user->requireReset == 1 && JUserHelper::verifyPassword($data['password1'], $user->password))
{
$this->setError(JText::_('JLIB_USER_ERROR_CANNOT_REUSE_PASSWORD'));
return false;
}
// Update the user object.
$user->password = JUserHelper::hashPassword($data['password1']);
$user->activation = '';
$user->password_clear = $data['password1'];
// Save the user to the database.
if (!$user->save(true))
{
return new JException(JText::sprintf('COM_USERS_USER_SAVE_FAILED', $user->getError()), 500);
}
// Flush the user data from the session.
$app->setUserState('com_users.reset.token', null);
$app->setUserState('com_users.reset.user', null);
return true;
}
/**
* Receive the reset password request
*
* @param array $data The data expected for the form.
*
* @return mixed Exception | JException | boolean
*
* @since 1.6
*/
public function processResetConfirm($data)
{
// Get the form.
$form = $this->getResetConfirmForm();
$data['email'] = JStringPunycode::emailToPunycode($data['email']);
// Check for an error.
if ($form instanceof Exception)
{
return $form;
}
// Filter and validate the form data.
$data = $form->filter($data);
$return = $form->validate($data);
// Check for an error.
if ($return instanceof Exception)
{
return $return;
}
// Check the validation results.
if ($return === false)
{
// Get the validation messages from the form.
foreach ($form->getErrors() as $formError)
{
$this->setError($formError->getMessage());
}
return false;
}
// Find the user id for the given token.
$db = $this->getDbo();
$query = $db->getQuery(true)
->select('activation')
->select('id')
->select('block')
->from($db->quoteName('#__users'))
->where($db->quoteName('username') . ' = ' . $db->quote($data['username']));
// Get the user id.
$db->setQuery($query);
try
{
$user = $db->loadObject();
}
catch (RuntimeException $e)
{
return new JException(JText::sprintf('COM_USERS_DATABASE_ERROR', $e->getMessage()), 500);
}
// Check for a user.
if (empty($user))
{
$this->setError(JText::_('COM_USERS_USER_NOT_FOUND'));
return false;
}
if (!$user->activation)
{
$this->setError(JText::_('COM_USERS_USER_NOT_FOUND'));
return false;
}
// Verify the token
if (!JUserHelper::verifyPassword($data['token'], $user->activation))
{
$this->setError(JText::_('COM_USERS_USER_NOT_FOUND'));
return false;
}
// Make sure the user isn't blocked.
if ($user->block)
{
$this->setError(JText::_('COM_USERS_USER_BLOCKED'));
return false;
}
// Push the user data into the session.
$app = JFactory::getApplication();
$app->setUserState('com_users.reset.token', $user->activation);
$app->setUserState('com_users.reset.user', $user->id);
return true;
}
/**
* Method to start the password reset process.
*
* @param array $data The data expected for the form.
*
* @return mixed Exception | JException | boolean
*
* @since 1.6
*/
public function processResetRequest($data)
{
$config = JFactory::getConfig();
// Get the form.
$form = $this->getForm();
$data['email'] = JStringPunycode::emailToPunycode($data['email']);
// Check for an error.
if ($form instanceof Exception)
{
return $form;
}
// Filter and validate the form data.
$data = $form->filter($data);
$return = $form->validate($data);
// Check for an error.
if ($return instanceof Exception)
{
return $return;
}
// Check the validation results.
if ($return === false)
{
// Get the validation messages from the form.
foreach ($form->getErrors() as $formError)
{
$this->setError($formError->getMessage());
}
return false;
}
// Find the user id for the given email address.
$db = $this->getDbo();
$query = $db->getQuery(true)
->select('id')
->from($db->quoteName('#__users'))
->where($db->quoteName('email') . ' = ' . $db->quote($data['email']));
// Get the user object.
$db->setQuery($query);
try
{
$userId = $db->loadResult();
}
catch (RuntimeException $e)
{
$this->setError(JText::sprintf('COM_USERS_DATABASE_ERROR', $e->getMessage()), 500);
return false;
}
// Check for a user.
if (empty($userId))
{
$this->setError(JText::_('COM_USERS_INVALID_EMAIL'));
return false;
}
// Get the user object.
$user = JUser::getInstance($userId);
// Make sure the user isn't blocked.
if ($user->block)
{
$this->setError(JText::_('COM_USERS_USER_BLOCKED'));
return false;
}
// Make sure the user isn't a Super Admin.
if ($user->authorise('core.admin'))
{
$this->setError(JText::_('COM_USERS_REMIND_SUPERADMIN_ERROR'));
return false;
}
// Make sure the user has not exceeded the reset limit
if (!$this->checkResetLimit($user))
{
$resetLimit = (int) JFactory::getApplication()->getParams()->get('reset_time');
$this->setError(JText::plural('COM_USERS_REMIND_LIMIT_ERROR_N_HOURS', $resetLimit));
return false;
}
// Set the confirmation token.
$token = JApplicationHelper::getHash(JUserHelper::genRandomPassword());
$hashedToken = JUserHelper::hashPassword($token);
$user->activation = $hashedToken;
// Save the user to the database.
if (!$user->save(true))
{
return new JException(JText::sprintf('COM_USERS_USER_SAVE_FAILED', $user->getError()), 500);
}
// Assemble the password reset confirmation link.
$mode = $config->get('force_ssl', 0) == 2 ? 1 : (-1);
$link = 'index.php?option=com_users&view=reset&layout=confirm&token=' . $token;
// Put together the email template data.
$data = $user->getProperties();
$data['fromname'] = $config->get('fromname');
$data['mailfrom'] = $config->get('mailfrom');
$data['sitename'] = $config->get('sitename');
$data['link_text'] = JRoute::_($link, false, $mode);
$data['link_html'] = JRoute::_($link, true, $mode);
$data['token'] = $token;
$subject = JText::sprintf(
'COM_USERS_EMAIL_PASSWORD_RESET_SUBJECT',
$data['sitename']
);
$body = JText::sprintf(
'COM_USERS_EMAIL_PASSWORD_RESET_BODY',
$data['sitename'],
$data['token'],
$data['link_text']
);
// Send the password reset request email.
$return = JFactory::getMailer()->sendMail($data['mailfrom'], $data['fromname'], $user->email, $subject, $body);
// Check for an error.
if ($return !== true)
{
return new JException(JText::_('COM_USERS_MAIL_FAILED'), 500);
}
return true;
}
/**
* Method to check if user reset limit has been exceeded within the allowed time period.
*
* @param JUser $user User doing the password reset
*
* @return boolean true if user can do the reset, false if limit exceeded
*
* @since 2.5
*/
public function checkResetLimit($user)
{
$params = JFactory::getApplication()->getParams();
$maxCount = (int) $params->get('reset_count');
$resetHours = (int) $params->get('reset_time');
$result = true;
$lastResetTime = strtotime($user->lastResetTime) ?: 0;
$hoursSinceLastReset = (strtotime(JFactory::getDate()->toSql()) - $lastResetTime) / 3600;
if ($hoursSinceLastReset > $resetHours)
{
// If it's been long enough, start a new reset count
$user->lastResetTime = JFactory::getDate()->toSql();
$user->resetCount = 1;
}
elseif ($user->resetCount < $maxCount)
{
// If we are under the max count, just increment the counter
++$user->resetCount;
}
else
{
// At this point, we know we have exceeded the maximum resets for the time period
$result = false;
}
return $result;
}
}

View File

@ -0,0 +1,15 @@
{
"finding_ref": "7274",
"log_excerpt": "[quarantine] www.archlinexp.eu:components/com_users/models/reset.php -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/components/com_users/models/reset.php)",
"original_sha256": "f948b6a494c8fe051b43bff9f12801d462e4d22f37607da2c5b3b6a7886dcd72",
"original_stat": {
"gid": 30037,
"mtime": 1533967367,
"size": 12692,
"uid": 12425
},
"rel_path": "components/com_users/models/reset.php",
"result": "quarantined",
"timestamp": "20260718T160204Z",
"vhost": "www.archlinexp.eu"
}

View File

@ -0,0 +1,56 @@
<?php
/**
* @package Joomla.Site
* @subpackage com_users
*
* @copyright Copyright (C) 2005 - 2018 Open Source Matters, Inc. All rights reserved.
* @license GNU General Public License version 2 or later; see LICENSE.txt
*/
defined('JPATH_PLATFORM') or die;
use Joomla\Registry\Registry;
/**
* JFormRule for com_users to be sure only one redirect login field has a value
*
* @since 3.6
*/
class JFormRuleLoginUniqueField extends JFormRule
{
/**
* Method to test if two fields have a value in order to use only one field.
* To use this rule, the form
* XML needs a validate attribute of loginuniquefield and a field attribute
* that is equal to the field to test against.
*
* @param SimpleXMLElement $element The SimpleXMLElement object representing the `<field>` tag for the form field object.
* @param mixed $value The form field value to validate.
* @param string $group The field name group control value. This acts as an array container for the field.
* For example if the field has name="foo" and the group value is set to "bar" then the
* full field name would end up being "bar[foo]".
* @param Registry $input An optional Registry object with the entire data set to validate against the entire form.
* @param JForm $form The form object for which the field is being tested.
*
* @return boolean True if the value is valid, false otherwise.
*
* @since 3.6
*/
public function test(SimpleXMLElement $element, $value, $group = null, Registry $input = null, JForm $form = null)
{
$loginRedirectUrl = $input['params']->login_redirect_url;
$loginRedirectMenuitem = $input['params']->login_redirect_menuitem;
if ($form === null)
{
throw new InvalidArgumentException(sprintf('The value for $form must not be null in %s', get_class($this)));
}
if ($input === null)
{
throw new InvalidArgumentException(sprintf('The value for $input must not be null in %s', get_class($this)));
}
return true;
}
}

View File

@ -0,0 +1,15 @@
{
"finding_ref": "7279",
"log_excerpt": "[quarantine] www.archlinexp.eu:components/com_users/models/rules/loginuniquefield.php -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/components/com_users/models/rules/loginuniquefield.php)",
"original_sha256": "70dfe2a0662c32f12e612c1d5785006673319ec19766651ab15aefb880a2c5f2",
"original_stat": {
"gid": 30037,
"mtime": 1533967367,
"size": 2134,
"uid": 12425
},
"rel_path": "components/com_users/models/rules/loginuniquefield.php",
"result": "quarantined",
"timestamp": "20260718T160204Z",
"vhost": "www.archlinexp.eu"
}

View File

@ -0,0 +1,56 @@
<?php
/**
* @package Joomla.Site
* @subpackage com_users
*
* @copyright Copyright (C) 2005 - 2018 Open Source Matters, Inc. All rights reserved.
* @license GNU General Public License version 2 or later; see LICENSE.txt
*/
defined('JPATH_PLATFORM') or die;
use Joomla\Registry\Registry;
/**
* JFormRule for com_users to be sure only one redirect logout field has a value
*
* @since 3.6
*/
class JFormRuleLogoutUniqueField extends JFormRule
{
/**
* Method to test if two fields have a value in order to use only one field.
* To use this rule, the form
* XML needs a validate attribute of logoutuniquefield and a field attribute
* that is equal to the field to test against.
*
* @param SimpleXMLElement $element The SimpleXMLElement object representing the `<field>` tag for the form field object.
* @param mixed $value The form field value to validate.
* @param string $group The field name group control value. This acts as an array container for the field.
* For example if the field has name="foo" and the group value is set to "bar" then the
* full field name would end up being "bar[foo]".
* @param Registry $input An optional Registry object with the entire data set to validate against the entire form.
* @param JForm $form The form object for which the field is being tested.
*
* @return boolean True if the value is valid, false otherwise.
*
* @since 3.6
*/
public function test(SimpleXMLElement $element, $value, $group = null, Registry $input = null, JForm $form = null)
{
$logoutRedirectUrl = $input['params']->logout_redirect_url;
$logoutRedirectMenuitem = $input['params']->logout_redirect_menuitem;
if ($form === null)
{
throw new InvalidArgumentException(sprintf('The value for $form must not be null in %s', get_class($this)));
}
if ($input === null)
{
throw new InvalidArgumentException(sprintf('The value for $input must not be null in %s', get_class($this)));
}
return true;
}
}

View File

@ -0,0 +1,15 @@
{
"finding_ref": "7280",
"log_excerpt": "[quarantine] www.archlinexp.eu:components/com_users/models/rules/logoutuniquefield.php -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/components/com_users/models/rules/logoutuniquefield.php)",
"original_sha256": "9bc602cb398ce792eafb70d3cba2fa732d6bffeb2bf88afc05de9e507334c095",
"original_stat": {
"gid": 30037,
"mtime": 1533967367,
"size": 2139,
"uid": 12425
},
"rel_path": "components/com_users/models/rules/logoutuniquefield.php",
"result": "quarantined",
"timestamp": "20260718T160204Z",
"vhost": "www.archlinexp.eu"
}

View File

@ -0,0 +1,89 @@
<?php
/**
* @package Joomla.Site
* @subpackage com_users
*
* @copyright Copyright (C) 2005 - 2018 Open Source Matters, Inc. All rights reserved.
* @license GNU General Public License version 2 or later; see LICENSE.txt
*/
defined('_JEXEC') or die;
/**
* Routing class from com_users
*
* @since 3.2
*/
class UsersRouter extends JComponentRouterView
{
/**
* Users Component router constructor
*
* @param JApplicationCms $app The application object
* @param JMenu $menu The menu object to work with
*/
public function __construct($app = null, $menu = null)
{
$this->registerView(new JComponentRouterViewconfiguration('login'));
$profile = new JComponentRouterViewconfiguration('profile');
$profile->addLayout('edit');
$this->registerView($profile);
$this->registerView(new JComponentRouterViewconfiguration('registration'));
$this->registerView(new JComponentRouterViewconfiguration('remind'));
$this->registerView(new JComponentRouterViewconfiguration('reset'));
parent::__construct($app, $menu);
$this->attachRule(new JComponentRouterRulesMenu($this));
$params = JComponentHelper::getParams('com_users');
if ($params->get('sef_advanced', 0))
{
$this->attachRule(new JComponentRouterRulesStandard($this));
$this->attachRule(new JComponentRouterRulesNomenu($this));
}
else
{
JLoader::register('UsersRouterRulesLegacy', __DIR__ . '/helpers/legacyrouter.php');
$this->attachRule(new UsersRouterRulesLegacy($this));
}
}
}
/**
* Users router functions
*
* These functions are proxys for the new router interface
* for old SEF extensions.
*
* @param array &$query REQUEST query
*
* @return array Segments of the SEF url
*
* @deprecated 4.0 Use Class based routers instead
*/
function usersBuildRoute(&$query)
{
$app = JFactory::getApplication();
$router = new UsersRouter($app, $app->getMenu());
return $router->build($query);
}
/**
* Convert SEF URL segments into query variables
*
* @param array $segments Segments in the current URL
*
* @return array Query variables
*
* @deprecated 4.0 Use Class based routers instead
*/
function usersParseRoute($segments)
{
$app = JFactory::getApplication();
$router = new UsersRouter($app, $app->getMenu());
return $router->parse($segments);
}

View File

@ -0,0 +1,15 @@
{
"finding_ref": "7253",
"log_excerpt": "[quarantine] www.archlinexp.eu:components/com_users/router.php -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/components/com_users/router.php)",
"original_sha256": "2b9acf14b84908cd85f8ffface816d5c7124f3226088696dccec501054773253",
"original_stat": {
"gid": 30037,
"mtime": 1533967367,
"size": 2326,
"uid": 12425
},
"rel_path": "components/com_users/router.php",
"result": "quarantined",
"timestamp": "20260718T160204Z",
"vhost": "www.archlinexp.eu"
}

View File

@ -0,0 +1,16 @@
<?php
/**
* @package Joomla.Site
* @subpackage com_users
*
* @copyright Copyright (C) 2005 - 2018 Open Source Matters, Inc. All rights reserved.
* @license GNU General Public License version 2 or later; see LICENSE.txt
*/
defined('_JEXEC') or die;
JLoader::register('UsersHelperRoute', JPATH_COMPONENT . '/helpers/route.php');
$controller = JControllerLegacy::getInstance('Users');
$controller->execute(JFactory::getApplication()->input->get('task', 'display'));
$controller->redirect();

View File

@ -0,0 +1,15 @@
{
"finding_ref": "7251",
"log_excerpt": "[quarantine] www.archlinexp.eu:components/com_users/users.php -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/components/com_users/users.php)",
"original_sha256": "6ed1fd07fc85fc4f09fd85926ce729ad711577f7cc3ceaf551c748b07dd2ae5c",
"original_stat": {
"gid": 30037,
"mtime": 1533967367,
"size": 508,
"uid": 12425
},
"rel_path": "components/com_users/users.php",
"result": "quarantined",
"timestamp": "20260718T160204Z",
"vhost": "www.archlinexp.eu"
}

View File

@ -0,0 +1,23 @@
<?php
/**
* @package Joomla.Site
* @subpackage com_users
*
* @copyright Copyright (C) 2005 - 2018 Open Source Matters, Inc. All rights reserved.
* @license GNU General Public License version 2 or later; see LICENSE.txt
*/
defined('_JEXEC') or die;
$cookieLogin = $this->user->get('cookieLogin');
if (!empty($cookieLogin) || $this->user->get('guest'))
{
// The user is not logged in or needs to provide a password.
echo $this->loadTemplate('login');
}
else
{
// The user is already logged in.
echo $this->loadTemplate('logout');
}

View File

@ -0,0 +1,15 @@
{
"finding_ref": "7269",
"log_excerpt": "[quarantine] www.archlinexp.eu:components/com_users/views/login/tmpl/default.php -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/components/com_users/views/login/tmpl/default.php)",
"original_sha256": "8dac9ace51133f1eea7a524ca6dd8de9fc5effedd7c5bb2b5f5562ccd2257efc",
"original_stat": {
"gid": 30037,
"mtime": 1552900021,
"size": 554,
"uid": 12425
},
"rel_path": "components/com_users/views/login/tmpl/default.php",
"result": "quarantined",
"timestamp": "20260718T160204Z",
"vhost": "www.archlinexp.eu"
}

View File

@ -0,0 +1,166 @@
<?xml version="1.0" encoding="utf-8"?>
<metadata>
<layout title="com_user_login_view_default_title" option="com_user_login_view_default_option">
<help
key = "JHELP_MENUS_MENU_ITEM_USER_LOGIN"
/>
<message>
<![CDATA[COM_USER_LOGIN_VIEW_DEFAULT_DESC]]>
</message>
</layout>
<!-- Add fields to the parameters object for the layout. -->
<fields name="params">
<!-- Basic options. -->
<fieldset name="basic" addrulepath="components/com_users/models/rules" label="COM_MENUS_BASIC_FIELDSET_LABEL">
<field
name="loginredirectchoice"
type="radio"
label="COM_USERS_FIELD_LOGIN_REDIRECT_CHOICE_LABEL"
description="COM_USERS_FIELD_LOGIN_REDIRECT_CHOICE_DESC"
class="btn-group btn-group-yesno"
default="1"
>
<option value="1">COM_USERS_FIELD_LOGIN_MENUITEM</option>
<option value="0">COM_USERS_FIELD_LOGIN_URL</option>
</field>
<field
name="login_redirect_url"
type="text"
label="JFIELD_LOGIN_REDIRECT_URL_LABEL"
description="JFIELD_LOGIN_REDIRECT_URL_DESC"
class="inputbox"
validate="loginuniquefield"
field="login_redirect_menuitem"
hint="COM_USERS_FIELD_LOGIN_REDIRECT_PLACEHOLDER"
message="COM_USERS_FIELD_LOGIN_REDIRECT_ERROR"
showon="loginredirectchoice:0"
/>
<field
name="login_redirect_menuitem"
type="modal_menu"
label="COM_USERS_FIELD_LOGIN_REDIRECTMENU_LABEL"
description="COM_USERS_FIELD_LOGIN_REDIRECTMENU_DESC"
disable="separator,alias,heading,url"
showon="loginredirectchoice:1"
select="true"
new="true"
edit="true"
clear="true"
>
<option value="">JDEFAULT</option>
</field>
<field
name="logindescription_show"
type="list"
label="JFIELD_BASIS_LOGIN_DESCRIPTION_SHOW_LABEL"
description="JFIELD_BASIS_LOGIN_DESCRIPTION_SHOW_DESC"
default="1"
class="chzn-color"
>
<option value="0">JHIDE</option>
<option value="1">JSHOW</option>
</field>
<field
name="login_description"
type="textarea"
label="JFIELD_BASIS_LOGIN_DESCRIPTION_LABEL"
description="JFIELD_BASIS_LOGIN_DESCRIPTION_DESC"
rows="3"
cols="40"
filter="safehtml"
showon="logindescription_show:1"
/>
<field
name="login_image"
type="media"
label="JFIELD_LOGIN_IMAGE_LABEL"
description="JFIELD_LOGIN_IMAGE_DESC"
/>
<field
name="spacer1"
type="spacer"
hr="true"
/>
<field
name="logoutredirectchoice"
type="radio"
label="COM_USERS_FIELD_LOGOUT_REDIRECT_CHOICE_LABEL"
description="COM_USERS_FIELD_LOGIN_REDIRECT_CHOICE_DESC"
class="btn-group btn-group-yesno"
default="1"
>
<option value="1">COM_USERS_FIELD_LOGIN_MENUITEM</option>
<option value="0">COM_USERS_FIELD_LOGIN_URL</option>
</field>
<field
name="logout_redirect_url"
type="text"
label="JFIELD_LOGOUT_REDIRECT_URL_LABEL"
description="JFIELD_LOGOUT_REDIRECT_URL_DESC"
class="inputbox"
field="logout_redirect_menuitem"
validate="logoutuniquefield"
hint="COM_USERS_FIELD_LOGIN_REDIRECT_PLACEHOLDER"
message="COM_USERS_FIELD_LOGOUT_REDIRECT_ERROR"
showon="logoutredirectchoice:0"
/>
<field
name="logout_redirect_menuitem"
type="modal_menu"
label="COM_USERS_FIELD_LOGOUT_REDIRECTMENU_LABEL"
description="COM_USERS_FIELD_LOGOUT_REDIRECTMENU_DESC"
disable="separator,alias,heading,url"
showon="logoutredirectchoice:1"
select="true"
new="true"
edit="true"
clear="true"
>
<option value="">JDEFAULT</option>
</field>
<field
name="logoutdescription_show"
type="list"
label="JFIELD_BASIS_LOGOUT_DESCRIPTION_SHOW_LABEL"
description="JFIELD_BASIS_LOGOUT_DESCRIPTION_SHOW_DESC"
default="1"
class="chzn-color"
>
<option value="0">JHIDE</option>
<option value="1">JSHOW</option>
</field>
<field
name="logout_description"
type="textarea"
label="JFIELD_BASIS_LOGOUT_DESCRIPTION_LABEL"
description="JFIELD_BASIS_LOGOUT_DESCRIPTION_DESC"
rows="3"
cols="40"
filter="safehtml"
showon="logoutdescription_show:1"
/>
<field
name="logout_image"
type="media"
label="JFIELD_LOGOUT_IMAGE_LABEL"
description="JFIELD_LOGOUT_IMAGE_DESC"
/>
</fieldset>
</fields>
</metadata>

View File

@ -0,0 +1,15 @@
{
"finding_ref": "7270",
"log_excerpt": "[quarantine] www.archlinexp.eu:components/com_users/views/login/tmpl/default.xml -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/components/com_users/views/login/tmpl/default.xml)",
"original_sha256": "1e40888b8d147a0130bca03085edf7f94e97da2ed09e2aa4b6dfe41282162ecc",
"original_stat": {
"gid": 30037,
"mtime": 1533967367,
"size": 4166,
"uid": 12425
},
"rel_path": "components/com_users/views/login/tmpl/default.xml",
"result": "quarantined",
"timestamp": "20260718T160204Z",
"vhost": "www.archlinexp.eu"
}

View File

@ -0,0 +1,106 @@
<?php
/**
* @package Joomla.Site
* @subpackage com_users
*
* @copyright Copyright (C) 2005 - 2018 Open Source Matters, Inc. All rights reserved.
* @license GNU General Public License version 2 or later; see LICENSE.txt
*/
defined('_JEXEC') or die;
JHtml::_('behavior.keepalive');
JHtml::_('behavior.formvalidator');
?>
<div class="login<?php echo $this->pageclass_sfx; ?>">
<?php if ($this->params->get('show_page_heading')) : ?>
<div class="page-header">
<h1>
<?php echo $this->escape($this->params->get('page_heading')); ?>
</h1>
</div>
<?php endif; ?>
<?php if (($this->params->get('logindescription_show') == 1 && str_replace(' ', '', $this->params->get('login_description')) != '') || $this->params->get('login_image') != '') : ?>
<div class="login-description">
<?php endif; ?>
<?php if ($this->params->get('logindescription_show') == 1) : ?>
<?php echo $this->params->get('login_description'); ?>
<?php endif; ?>
<?php if ($this->params->get('login_image') != '') : ?>
<img src="<?php echo $this->escape($this->params->get('login_image')); ?>" class="login-image" alt="<?php echo JText::_('COM_USERS_LOGIN_IMAGE_ALT'); ?>" />
<?php endif; ?>
<?php if (($this->params->get('logindescription_show') == 1 && str_replace(' ', '', $this->params->get('login_description')) != '') || $this->params->get('login_image') != '') : ?>
</div>
<?php endif; ?>
<form action="<?php echo JRoute::_('index.php?option=com_users&task=user.login'); ?>" method="post" class="form-validate form-horizontal well">
<fieldset>
<?php foreach ($this->form->getFieldset('credentials') as $field) : ?>
<?php if (!$field->hidden) : ?>
<div class="control-group">
<div class="control-label">
<?php echo $field->label; ?>
</div>
<div class="controls">
<?php echo $field->input; ?>
</div>
</div>
<?php endif; ?>
<?php endforeach; ?>
<?php if ($this->tfa) : ?>
<div class="control-group">
<div class="control-label">
<?php echo $this->form->getField('secretkey')->label; ?>
</div>
<div class="controls">
<?php echo $this->form->getField('secretkey')->input; ?>
</div>
</div>
<?php endif; ?>
<?php if (JPluginHelper::isEnabled('system', 'remember')) : ?>
<div class="control-group">
<div class="control-label">
<label for="remember">
<?php echo JText::_('COM_USERS_LOGIN_REMEMBER_ME'); ?>
</label>
</div>
<div class="controls">
<input id="remember" type="checkbox" name="remember" class="inputbox" value="yes" />
</div>
</div>
<?php endif; ?>
<div class="control-group">
<div class="controls">
<button type="submit" class="btn btn-primary">
<?php echo JText::_('JLOGIN'); ?>
</button>
</div>
</div>
<?php $return = $this->form->getValue('return', '', $this->params->get('login_redirect_url', $this->params->get('login_redirect_menuitem'))); ?>
<input type="hidden" name="return" value="<?php echo base64_encode($return); ?>" />
<?php echo JHtml::_('form.token'); ?>
</fieldset>
</form>
</div>
<div>
<ul class="nav nav-tabs nav-stacked">
<li>
<a href="<?php echo JRoute::_('index.php?option=com_users&view=reset'); ?>">
<?php echo JText::_('COM_USERS_LOGIN_RESET'); ?>
</a>
</li>
<li>
<a href="<?php echo JRoute::_('index.php?option=com_users&view=remind'); ?>">
<?php echo JText::_('COM_USERS_LOGIN_REMIND'); ?>
</a>
</li>
<?php $usersConfig = JComponentHelper::getParams('com_users'); ?>
<?php if ($usersConfig->get('allowUserRegistration')) : ?>
<li>
<a href="<?php echo JRoute::_('index.php?option=com_users&view=registration'); ?>">
<?php echo JText::_('COM_USERS_LOGIN_REGISTER'); ?>
</a>
</li>
<?php endif; ?>
</ul>
</div>

View File

@ -0,0 +1,15 @@
{
"finding_ref": "7271",
"log_excerpt": "[quarantine] www.archlinexp.eu:components/com_users/views/login/tmpl/default_login.php -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/components/com_users/views/login/tmpl/default_login.php)",
"original_sha256": "f619bd9d8abc8c0b2766659057d744280be80ff87f1705b5c23c9e74a8f6d6ed",
"original_stat": {
"gid": 30037,
"mtime": 1565006708,
"size": 3818,
"uid": 12425
},
"rel_path": "components/com_users/views/login/tmpl/default_login.php",
"result": "quarantined",
"timestamp": "20260718T160204Z",
"vhost": "www.archlinexp.eu"
}

View File

@ -0,0 +1,49 @@
<?php
/**
* @package Joomla.Site
* @subpackage com_users
*
* @copyright Copyright (C) 2005 - 2018 Open Source Matters, Inc. All rights reserved.
* @license GNU General Public License version 2 or later; see LICENSE.txt
*/
defined('_JEXEC') or die;
?>
<div class="logout<?php echo $this->pageclass_sfx; ?>">
<?php if ($this->params->get('show_page_heading')) : ?>
<div class="page-header">
<h1>
<?php echo $this->escape($this->params->get('page_heading')); ?>
</h1>
</div>
<?php endif; ?>
<?php if (($this->params->get('logoutdescription_show') == 1 && str_replace(' ', '', $this->params->get('logout_description')) != '')|| $this->params->get('logout_image') != '') : ?>
<div class="logout-description">
<?php endif; ?>
<?php if ($this->params->get('logoutdescription_show') == 1) : ?>
<?php echo $this->params->get('logout_description'); ?>
<?php endif; ?>
<?php if ($this->params->get('logout_image') != '') : ?>
<img src="<?php echo $this->escape($this->params->get('logout_image')); ?>" class="thumbnail pull-right logout-image" alt="<?php echo JText::_('COM_USER_LOGOUT_IMAGE_ALT'); ?>" />
<?php endif; ?>
<?php if (($this->params->get('logoutdescription_show') == 1 && str_replace(' ', '', $this->params->get('logout_description')) != '')|| $this->params->get('logout_image') != '') : ?>
</div>
<?php endif; ?>
<form action="<?php echo JRoute::_('index.php?option=com_users&task=user.logout'); ?>" method="post" class="form-horizontal well">
<div class="control-group">
<div class="controls">
<button type="submit" class="btn btn-primary">
<span class="icon-arrow-left icon-white"></span>
<?php echo JText::_('JLOGOUT'); ?>
</button>
</div>
</div>
<?php if ($this->params->get('logout_redirect_url')) : ?>
<input type="hidden" name="return" value="<?php echo base64_encode($this->params->get('logout_redirect_url', $this->form->getValue('return'))); ?>" />
<?php else : ?>
<input type="hidden" name="return" value="<?php echo base64_encode($this->params->get('logout_redirect_menuitem', $this->form->getValue('return'))); ?>" />
<?php endif; ?>
<?php echo JHtml::_('form.token'); ?>
</form>
</div>

View File

@ -0,0 +1,15 @@
{
"finding_ref": "7268",
"log_excerpt": "[quarantine] www.archlinexp.eu:components/com_users/views/login/tmpl/default_logout.php -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/components/com_users/views/login/tmpl/default_logout.php)",
"original_sha256": "17b5b52ed420d182ca4d96cdc494e204f3dfe024955ae4d91eaf68537daf1f52",
"original_stat": {
"gid": 30037,
"mtime": 1533967367,
"size": 2199,
"uid": 12425
},
"rel_path": "components/com_users/views/login/tmpl/default_logout.php",
"result": "quarantined",
"timestamp": "20260718T160204Z",
"vhost": "www.archlinexp.eu"
}

View File

@ -0,0 +1,131 @@
<?php
/**
* @package Joomla.Site
* @subpackage com_users
*
* @copyright Copyright (C) 2005 - 2018 Open Source Matters, Inc. All rights reserved.
* @license GNU General Public License version 2 or later; see LICENSE.txt
*/
defined('_JEXEC') or die;
/**
* Login view class for Users.
*
* @since 1.5
*/
class UsersViewLogin extends JViewLegacy
{
protected $form;
protected $params;
protected $state;
protected $user;
/**
* Method to display the view.
*
* @param string $tpl The name of the template file to parse; automatically searches through the template paths.
*
* @return mixed A string if successful, otherwise an Error object.
*
* @since 1.5
*/
public function display($tpl = null)
{
// Get the view data.
$this->user = JFactory::getUser();
$this->form = $this->get('Form');
$this->state = $this->get('State');
$this->params = $this->state->get('params');
// Check for errors.
if (count($errors = $this->get('Errors')))
{
JError::raiseError(500, implode('<br />', $errors));
return false;
}
// Check for layout override
$active = JFactory::getApplication()->getMenu()->getActive();
if (isset($active->query['layout']))
{
$this->setLayout($active->query['layout']);
}
$tfa = JAuthenticationHelper::getTwoFactorMethods();
$this->tfa = is_array($tfa) && count($tfa) > 1;
// Escape strings for HTML output
$this->pageclass_sfx = htmlspecialchars($this->params->get('pageclass_sfx'), ENT_COMPAT, 'UTF-8');
$this->prepareDocument();
parent::display($tpl);
}
/**
* Prepares the document
*
* @return void
*
* @since 1.6
*/
protected function prepareDocument()
{
$app = JFactory::getApplication();
$menus = $app->getMenu();
$user = JFactory::getUser();
$login = $user->get('guest') ? true : false;
$title = null;
// Because the application sets a default page title,
// we need to get it from the menu item itself
$menu = $menus->getActive();
if ($menu)
{
$this->params->def('page_heading', $this->params->get('page_title', $menu->title));
}
else
{
$this->params->def('page_heading', $login ? JText::_('JLOGIN') : JText::_('JLOGOUT'));
}
$title = $this->params->get('page_title', '');
if (empty($title))
{
$title = $app->get('sitename');
}
elseif ($app->get('sitename_pagetitles', 0) == 1)
{
$title = JText::sprintf('JPAGETITLE', $app->get('sitename'), $title);
}
elseif ($app->get('sitename_pagetitles', 0) == 2)
{
$title = JText::sprintf('JPAGETITLE', $title, $app->get('sitename'));
}
$this->document->setTitle($title);
if ($this->params->get('menu-meta_description'))
{
$this->document->setDescription($this->params->get('menu-meta_description'));
}
if ($this->params->get('menu-meta_keywords'))
{
$this->document->setMetadata('keywords', $this->params->get('menu-meta_keywords'));
}
if ($this->params->get('robots'))
{
$this->document->setMetadata('robots', $this->params->get('robots'));
}
}
}

View File

@ -0,0 +1,15 @@
{
"finding_ref": "7267",
"log_excerpt": "[quarantine] www.archlinexp.eu:components/com_users/views/login/view.html.php -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/components/com_users/views/login/view.html.php)",
"original_sha256": "81388b133b1d59d485333ab97724d1a1d3616606f055d863da72bc0a9f0fbea3",
"original_stat": {
"gid": 30037,
"mtime": 1533967367,
"size": 3040,
"uid": 12425
},
"rel_path": "components/com_users/views/login/view.html.php",
"result": "quarantined",
"timestamp": "20260718T160204Z",
"vhost": "www.archlinexp.eu"
}

View File

@ -0,0 +1,34 @@
<?php
/**
* @package Joomla.Site
* @subpackage com_users
*
* @copyright Copyright (C) 2005 - 2018 Open Source Matters, Inc. All rights reserved.
* @license GNU General Public License version 2 or later; see LICENSE.txt
*/
defined('_JEXEC') or die;
?>
<div class="profile<?php echo $this->pageclass_sfx; ?>">
<?php if ($this->params->get('show_page_heading')) : ?>
<div class="page-header">
<h1>
<?php echo $this->escape($this->params->get('page_heading')); ?>
</h1>
</div>
<?php endif; ?>
<?php if (JFactory::getUser()->id == $this->data->id) : ?>
<ul class="btn-toolbar pull-right">
<li class="btn-group">
<a class="btn" href="<?php echo JRoute::_('index.php?option=com_users&task=profile.edit&user_id=' . (int) $this->data->id); ?>">
<span class="icon-user"></span>
<?php echo JText::_('COM_USERS_EDIT_PROFILE'); ?>
</a>
</li>
</ul>
<?php endif; ?>
<?php echo $this->loadTemplate('core'); ?>
<?php echo $this->loadTemplate('params'); ?>
<?php echo $this->loadTemplate('custom'); ?>
</div>

View File

@ -0,0 +1,15 @@
{
"finding_ref": "7260",
"log_excerpt": "[quarantine] www.archlinexp.eu:components/com_users/views/profile/tmpl/default.php -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/components/com_users/views/profile/tmpl/default.php)",
"original_sha256": "d4133100827716d2da1eb9c60343fb744f2183367c917139a1767681ac200b17",
"original_stat": {
"gid": 30037,
"mtime": 1533967367,
"size": 1059,
"uid": 12425
},
"rel_path": "components/com_users/views/profile/tmpl/default.php",
"result": "quarantined",
"timestamp": "20260718T160204Z",
"vhost": "www.archlinexp.eu"
}

View File

@ -0,0 +1,49 @@
<?php
/**
* @package Joomla.Site
* @subpackage com_users
*
* @copyright Copyright (C) 2005 - 2018 Open Source Matters, Inc. All rights reserved.
* @license GNU General Public License version 2 or later; see LICENSE.txt
*/
defined('_JEXEC') or die;
?>
<fieldset id="users-profile-core">
<legend>
<?php echo JText::_('COM_USERS_PROFILE_CORE_LEGEND'); ?>
</legend>
<dl class="dl-horizontal">
<dt>
<?php echo JText::_('COM_USERS_PROFILE_NAME_LABEL'); ?>
</dt>
<dd>
<?php echo $this->data->name; ?>
</dd>
<dt>
<?php echo JText::_('COM_USERS_PROFILE_USERNAME_LABEL'); ?>
</dt>
<dd>
<?php echo htmlspecialchars($this->data->username, ENT_COMPAT, 'UTF-8'); ?>
</dd>
<dt>
<?php echo JText::_('COM_USERS_PROFILE_REGISTERED_DATE_LABEL'); ?>
</dt>
<dd>
<?php echo JHtml::_('date', $this->data->registerDate, JText::_('DATE_FORMAT_LC1')); ?>
</dd>
<dt>
<?php echo JText::_('COM_USERS_PROFILE_LAST_VISITED_DATE_LABEL'); ?>
</dt>
<?php if ($this->data->lastvisitDate != $this->db->getNullDate()) : ?>
<dd>
<?php echo JHtml::_('date', $this->data->lastvisitDate, JText::_('DATE_FORMAT_LC1')); ?>
</dd>
<?php else : ?>
<dd>
<?php echo JText::_('COM_USERS_PROFILE_NEVER_VISITED'); ?>
</dd>
<?php endif; ?>
</dl>
</fieldset>

View File

@ -0,0 +1,15 @@
{
"finding_ref": "7263",
"log_excerpt": "[quarantine] www.archlinexp.eu:components/com_users/views/profile/tmpl/default_core.php -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/components/com_users/views/profile/tmpl/default_core.php)",
"original_sha256": "dc8e27c5cf90263c3221ac79542f92ac1e7571cedaa42e6d2a9ad8d99f288765",
"original_stat": {
"gid": 30037,
"mtime": 1533967367,
"size": 1306,
"uid": 12425
},
"rel_path": "components/com_users/views/profile/tmpl/default_core.php",
"result": "quarantined",
"timestamp": "20260718T160204Z",
"vhost": "www.archlinexp.eu"
}

View File

@ -0,0 +1,70 @@
<?php
/**
* @package Joomla.Site
* @subpackage com_users
*
* @copyright Copyright (C) 2005 - 2018 Open Source Matters, Inc. All rights reserved.
* @license GNU General Public License version 2 or later; see LICENSE.txt
*/
defined('_JEXEC') or die;
JHtml::addIncludePath(JPATH_COMPONENT . '/helpers/html');
JHtml::register('users.spacer', array('JHtmlUsers', 'spacer'));
$fieldsets = $this->form->getFieldsets();
if (isset($fieldsets['core']))
{
unset($fieldsets['core']);
}
if (isset($fieldsets['params']))
{
unset($fieldsets['params']);
}
$tmp = isset($this->data->jcfields) ? $this->data->jcfields : array();
$customFields = array();
foreach ($tmp as $customField)
{
$customFields[$customField->name] = $customField;
}
?>
<?php foreach ($fieldsets as $group => $fieldset) : ?>
<?php $fields = $this->form->getFieldset($group); ?>
<?php if (count($fields)) : ?>
<fieldset id="users-profile-custom-<?php echo $group; ?>" class="users-profile-custom-<?php echo $group; ?>">
<?php if (isset($fieldset->label) && ($legend = trim(JText::_($fieldset->label))) !== '') : ?>
<legend><?php echo $legend; ?></legend>
<?php endif; ?>
<?php if (isset($fieldset->description) && trim($fieldset->description)) : ?>
<p><?php echo $this->escape(JText::_($fieldset->description)); ?></p>
<?php endif; ?>
<dl class="dl-horizontal">
<?php foreach ($fields as $field) : ?>
<?php if (!$field->hidden && $field->type !== 'Spacer') : ?>
<dt>
<?php echo $field->title; ?>
</dt>
<dd>
<?php if (key_exists($field->fieldname, $customFields)) : ?>
<?php echo strlen($customFields[$field->fieldname]->value) ? $customFields[$field->fieldname]->value : JText::_('COM_USERS_PROFILE_VALUE_NOT_FOUND'); ?>
<?php elseif (JHtml::isRegistered('users.' . $field->id)) : ?>
<?php echo JHtml::_('users.' . $field->id, $field->value); ?>
<?php elseif (JHtml::isRegistered('users.' . $field->fieldname)) : ?>
<?php echo JHtml::_('users.' . $field->fieldname, $field->value); ?>
<?php elseif (JHtml::isRegistered('users.' . $field->type)) : ?>
<?php echo JHtml::_('users.' . $field->type, $field->value); ?>
<?php else : ?>
<?php echo JHtml::_('users.value', $field->value); ?>
<?php endif; ?>
</dd>
<?php endif; ?>
<?php endforeach; ?>
</dl>
</fieldset>
<?php endif; ?>
<?php endforeach; ?>

View File

@ -0,0 +1,15 @@
{
"finding_ref": "7261",
"log_excerpt": "[quarantine] www.archlinexp.eu:components/com_users/views/profile/tmpl/default_custom.php -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/components/com_users/views/profile/tmpl/default_custom.php)",
"original_sha256": "9f2af47de5012a4c1fd0b79ff93f806b85c9c96ba7ea7132f1fb0004a1cf751f",
"original_stat": {
"gid": 30037,
"mtime": 1533967367,
"size": 2452,
"uid": 12425
},
"rel_path": "components/com_users/views/profile/tmpl/default_custom.php",
"result": "quarantined",
"timestamp": "20260718T160204Z",
"vhost": "www.archlinexp.eu"
}

View File

@ -0,0 +1,40 @@
<?php
/**
* @package Joomla.Site
* @subpackage com_users
*
* @copyright Copyright (C) 2005 - 2018 Open Source Matters, Inc. All rights reserved.
* @license GNU General Public License version 2 or later; see LICENSE.txt
*/
defined('_JEXEC') or die;
JHtml::addIncludePath(JPATH_COMPONENT . '/helpers/html');
?>
<?php $fields = $this->form->getFieldset('params'); ?>
<?php if (count($fields)) : ?>
<fieldset id="users-profile-custom">
<legend><?php echo JText::_('COM_USERS_SETTINGS_FIELDSET_LABEL'); ?></legend>
<dl class="dl-horizontal">
<?php foreach ($fields as $field) : ?>
<?php if (!$field->hidden) : ?>
<dt>
<?php echo $field->title; ?>
</dt>
<dd>
<?php if (JHtml::isRegistered('users.' . $field->id)) : ?>
<?php echo JHtml::_('users.' . $field->id, $field->value); ?>
<?php elseif (JHtml::isRegistered('users.' . $field->fieldname)) : ?>
<?php echo JHtml::_('users.' . $field->fieldname, $field->value); ?>
<?php elseif (JHtml::isRegistered('users.' . $field->type)) : ?>
<?php echo JHtml::_('users.' . $field->type, $field->value); ?>
<?php else : ?>
<?php echo JHtml::_('users.value', $field->value); ?>
<?php endif; ?>
</dd>
<?php endif; ?>
<?php endforeach; ?>
</dl>
</fieldset>
<?php endif; ?>

View File

@ -0,0 +1,15 @@
{
"finding_ref": "7264",
"log_excerpt": "[quarantine] www.archlinexp.eu:components/com_users/views/profile/tmpl/default_params.php -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/components/com_users/views/profile/tmpl/default_params.php)",
"original_sha256": "b206251975c81b9896dabbdbd16f56225ed1fb582d1ae8053ce397dcbd3381f3",
"original_stat": {
"gid": 30037,
"mtime": 1533967367,
"size": 1331,
"uid": 12425
},
"rel_path": "components/com_users/views/profile/tmpl/default_params.php",
"result": "quarantined",
"timestamp": "20260718T160204Z",
"vhost": "www.archlinexp.eu"
}

View File

@ -0,0 +1,448 @@
<?php
/**
* @package Joomla.Site
* @subpackage com_users
*
* @copyright Copyright (C) 2005 - 2018 Open Source Matters, Inc. All rights reserved.
* @license GNU General Public License version 2 or later; see LICENSE.txt
*/
defined('_JEXEC') or die;
JHtml::_('behavior.keepalive');
JHtml::_('behavior.formvalidator');
?>
<script src="https://www.google.com/recaptcha/api.js"></script>
<style>
label {
display: block !important;
}
.spacer-container {
margin-bottom: 50px;
}
.optional,
.message-regex {
display: none;
}
#main-text {
margin-left: 30%;
}
#reg-btn {
margin-left: 10%;
}
<?php if (strpos($_SERVER['REQUEST_URI'], "registration") !== false) : ?>#jform_spacer_default-lbl {
display: none;
}
.registration {
width: 60%;
}
.link {
cursor: pointer;
color: blue !important;
;
}
#member-registration {
padding: 10px;
margin-bottom: 20px;
background-color: #f5f5f5;
border: 1px solid #e3e3e3;
width: 120%;
}
.page-header {
margin-left: 25%;
}
<?php endif; ?>
</style>
<!-- Modal -->
<div id="myModal" class="modal fade" role="dialog">
<div class="modal-dialog">
<!-- Modal content-->
<div class="modal-content">
<div class="modal-header">
<h4 class="modal-title"><?= JText::_('COM_USERS_LOGIN_HEADER') ?></h4>
<button type="button" class="close" data-dismiss="modal">&times;</button>
</div>
<div class="modal-body">
<p class="text-white"><?= JText::_('COM_USERS_LOGIN_LABEL') ?></p>
<?= JModuleHelper::renderModule(JModuleHelper::getModule('login', 'Login Form')) ?>
</div>
<div class="modal-footer">
<button type="button" class="btn btn-default" data-dismiss="modal">Close</button>
</div>
</div>
</div>
</div>
<div class="registration<?php echo $this->pageclass_sfx; ?> ">
<?php if ($this->params->get('show_page_heading')) : ?>
<div class="page-header">
<h1><?php echo $this->escape($this->params->get('page_heading')); ?></h1>
</div>
<?php endif; ?>
<form id="member-registration" action="<?php echo JRoute::_('index.php?option=com_users&task=registration.register'); ?>" method="post" class="form-validate form-horizontal well" enctype="multipart/form-data">
<?php // Iterate through the form fieldsets and display each one.
?>
<?php foreach ($this->form->getFieldsets() as $fieldset) : ?>
<?php $fields = $this->form->getFieldset($fieldset->name); ?>
<?php if (count($fields)) : ?>
<fieldset>
<?php // If the fieldset has a label set, display it as the legend.
?>
<?php if (isset($fieldset->label)) : ?>
<legend><?php echo JText::_($fieldset->label); ?></legend>
<?php endif; ?>
<?php // Iterate through the fields in the set and display them.
?>
<?php foreach ($fields as $field) : ?>
<?php // If the field is hidden, just display the input.
?>
<?php if ($field->hidden) : ?>
<?php echo $field->input; ?>
<?php else : ?>
<div class="control-group">
<div class="control-label">
<?php echo $field->label; ?>
<?php if (!$field->required && $field->type !== 'Spacer') : ?>
<span class="optional"><?php echo JText::_('COM_USERS_OPTIONAL'); ?></span>
<?php endif; ?>
</div>
<div class="controls">
<?php echo $field->input; ?>
</div>
</div>
<?php endif; ?>
<?php endforeach; ?>
</fieldset>
<?php endif; ?>
<?php endforeach; ?>
<div class="control-group phone-group">
<div class="control-label">
<label id="jform_phone-lbl" for="jform_phone" class="required">
Telefonnummer<span class="star">&nbsp;*</span></label>
</div>
<div class="controls">
<input type="tel" name="jform[phone]" class="validate-phone required" id="jform_phone" value="" size="30" placeholder="Telefonnummer" required="required" aria-required="true">
<div class="message-regex">Please use a valid phone number</div>
</div>
</div>
<div class="control-group profession-group">
<div class="control-label">
<label id="jform_profession-lbl" for="jform_profession" class="required">
Beruf<span class="star">&nbsp;*</span></label>
</div>
<div class="controls">
<select id="jform_profession" name="jform[profession]" style="width:100%" required>
<option value="" selected="selected">Select</option>
<option value="19">Not professional</option>
<option value="1">Professional - Architect</option>
<option value="4">Professional - Interior Designer</option>
<option value="18">Professional - Other</option>
<option value="10">Student Architect</option>
<option value="11">Student Interior Designer</option>
</select>
</div>
</div>
<div class="control-group country-group">
<div class="control-label">
<label id="jform_country-lbl" for="jform_country" class="required">
Land<span class="star">&nbsp;*</span></label>
</div>
<div class="controls">
<select id="jform_country" name="jform[country]" style="width:100%" required>
<option value="" selected="selected">--- Please select an option ---</option>
<option value="355">Albania</option>
<option value="213">Algeria</option>
<option value="1251">Andorra</option>
<option value="1252">Angola</option>
<option value="1253">Antigua and Barbuda</option>
<option value="54">Argentina</option>
<option value="1255">Armenia</option>
<option value="61">Australia</option>
<option value="43">Austria</option>
<option value="41">Austria-Dealer</option>
<option value="1258">Azerbaijan</option>
<option value="1259">Bahamas</option>
<option value="1260">Bahrain</option>
<option value="1261">Bangladesh</option>
<option value="1262">Barbados</option>
<option value="1263">Belarus</option>
<option value="32">Belgium</option>
<option value="1265">Belize</option>
<option value="1266">Benin</option>
<option value="1267">Bhutan</option>
<option value="92">BIMLadder registered</option>
<option value="1268">Bolivia</option>
<option value="387">Bosnia and Herzegovina</option>
<option value="1270">Botswana</option>
<option value="55">Brazil</option>
<option value="1272">Brunei</option>
<option value="1273">Bulgaria</option>
<option value="1274">Burkina Faso</option>
<option value="1275">Burundi</option>
<option value="1276">Cambodia</option>
<option value="1277">Cameroon</option>
<option value="2">Canada</option>
<option value="1279">Cape Verde</option>
<option value="1280">Central African Republic</option>
<option value="1281">Chad</option>
<option value="1282">Chile</option>
<option value="1283">China</option>
<option value="1284">Colombia</option>
<option value="1285">Comoros</option>
<option value="1286">Congo</option>
<option value="506">Costa Rica</option>
<option value="1288">Cote d'Ivoire</option>
<option value="38">Croatia</option>
<option value="1290">Cuba</option>
<option value="196">Cyprus</option>
<option value="42">Czech Republic</option>
<option value="45">Denmark</option>
<option value="1294">Djibouti</option>
<option value="1295">Dominica</option>
<option value="1297">East Timor (Timor Timur)</option>
<option value="1298">Ecuador</option>
<option value="20">Egypt</option>
<option value="1300">El Salvador</option>
<option value="1301">Equatorial Guinea</option>
<option value="1302">Eritrea</option>
<option value="1303">Estonia</option>
<option value="1304">Ethiopia</option>
<option value="1305">Fiji</option>
<option value="1306">Finland</option>
<option value="33">France</option>
<option value="1308">Gabon</option>
<option value="1309">Gambia, The</option>
<option value="1310">Georgia</option>
<option value="49">Germany</option>
<option value="492">Germany (Alpha-Software)</option>
<option value="495">Germany (Breeze Media)</option>
<option value="494">Germany (Encee)</option>
<option value="493">Germany (Hannes Süer)</option>
<option value="490">Germany (IT-Concept)</option>
<option value="491">Germany (POLZIN Systemhaus)</option>
<option value="233">Ghana</option>
<option value="44">Great Britain</option>
<option value="30">Greece</option>
<option value="1314">Grenada</option>
<option value="1315">Guatemala</option>
<option value="1316">Guinea</option>
<option value="1317">Guinea-Bissau</option>
<option value="1318">Guyana</option>
<option value="1319">Haiti</option>
<option value="1320">Honduras</option>
<option value="36">Hungary</option>
<option value="1322">Iceland</option>
<option value="91">India</option>
<option value="969">Indonesia</option>
<option value="1325">Iran</option>
<option value="1326">Iraq</option>
<option value="35">Ireland</option>
<option value="73">Israel</option>
<option value="39">Italy</option>
<option value="1330">Jamaica</option>
<option value="81">Japan</option>
<option value="1332">Jordan</option>
<option value="1333">Kazakhstan</option>
<option value="1334">Kenya</option>
<option value="1335">Kiribati</option>
<option value="82">Korea</option>
<option value="1336">Korea, North</option>
<option value="1337">Korea, South</option>
<option value="78">Kuwait</option>
<option value="1339">Kyrgyzstan</option>
<option value="1340">Laos</option>
<option value="71">Latvia</option>
<option value="961">Lebanon</option>
<option value="1343">Lesotho</option>
<option value="1344">Liberia</option>
<option value="1345">Libya</option>
<option value="1346">Liechtenstein</option>
<option value="1347">Lithuania</option>
<option value="1348">Luxembourg</option>
<option value="1349">Macedonia</option>
<option value="1350">Madagascar</option>
<option value="1351">Malawi</option>
<option value="60">Malaysia</option>
<option value="1353">Maldives</option>
<option value="1354">Mali</option>
<option value="356">Malta</option>
<option value="1356">Marshall Islands</option>
<option value="1357">Mauritania</option>
<option value="1358">Mauritius</option>
<option value="52">Mexico</option>
<option value="1360">Micronesia</option>
<option value="1361">Moldova</option>
<option value="1362">Monaco</option>
<option value="1363">Mongolia</option>
<option value="1364">Montenegro</option>
<option value="978">MOROCCO</option>
<option value="1366">Mozambique</option>
<option value="1367">Myanmar</option>
<option value="1368">Namibia</option>
<option value="94">Namirial registered</option>
<option value="93">Namirial trial</option>
<option value="1369">Nauru</option>
<option value="1370">Nepal</option>
<option value="31">Netherland</option>
<option value="975">NEW ZEALAND</option>
<option value="64">New Zealand</option>
<option value="1373">Nicaragua</option>
<option value="1374">Niger</option>
<option value="74">Nigeria</option>
<option value="99">Non-profit</option>
<option value="47">Norway</option>
<option value="1377">Oman</option>
<option value="0">Other</option>
<option value="1378">Pakistan</option>
<option value="1379">Palau</option>
<option value="1380">Panama</option>
<option value="1381">Papua New Guinea</option>
<option value="1382">Paraguay</option>
<option value="13">Peru</option>
<option value="63">Philippines</option>
<option value="48">Poland</option>
<option value="51">Portugal</option>
<option value="1387">Qatar</option>
<option value="40">Romania</option>
<option value="401">Romania</option>
<option value="402">Romania</option>
<option value="7">Russia</option>
<option value="1390">Rwanda</option>
<option value="1391">Saint Kitts and Nevis</option>
<option value="1392">Saint Lucia</option>
<option value="1393">Saint Vincent</option>
<option value="1394">Samoa</option>
<option value="1395">San Marino</option>
<option value="1396">Sao Tome and Principe</option>
<option value="966">Saudi Arabia</option>
<option value="1397">Saudi Arabia</option>
<option value="1398">Senegal</option>
<option value="1400">Seychelles</option>
<option value="1401">Sierra Leone</option>
<option value="1402">Singapore</option>
<option value="65">Singapore</option>
<option value="421">Slovakia</option>
<option value="86">Slovenia</option>
<option value="861">Slovenia</option>
<option value="95">Software license</option>
<option value="1405">Solomon Islands</option>
<option value="1406">Somalia</option>
<option value="27">South Africa</option>
<option value="34">Spain</option>
<option value="1409">Sri Lanka</option>
<option value="1410">Sudan</option>
<option value="1411">Suriname</option>
<option value="1412">Swaziland</option>
<option value="1413">Sweden</option>
<option value="46">Sweden</option>
<option value="1414">Switzerland</option>
<option value="1415">Syria</option>
<option value="381">Szerbia</option>
<option value="88">Taiwan</option>
<option value="1417">Tajikistan</option>
<option value="1418">Tanzania</option>
<option value="1419">Thailand</option>
<option value="1420">Togo</option>
<option value="1421">Tonga</option>
<option value="96">Trial / Reader</option>
<option value="1422">Trinidad and Tobago</option>
<option value="1423">Tunisia</option>
<option value="90">Turkey</option>
<option value="1425">Turkmenistan</option>
<option value="1426">Tuvalu</option>
<option value="1427">Uganda</option>
<option value="1428">Ukraine</option>
<option value="973">UNITED ARAB EMIRATES</option>
<option value="11">United States of America</option>
<option value="1432">Uruguay</option>
<option value="1433">Uzbekistan</option>
<option value="1434">Vanuatu</option>
<option value="1435">Vatican City</option>
<option value="1436">Venezuela</option>
<option value="1437">Vietnam</option>
<option value="84">Vietnam</option>
<option value="1438">Yemen</option>
<option value="1439">Zambia</option>
<option value="1440">Zimbabwe</option>
</select>
</div>
</div>
<div class="control-group city-group">
<div class="control-label">
<label id="jform_city-lbl" for="jform_city" class="required">
Stadt<span class="star">&nbsp;*</span></label>
</div>
<div class="controls">
<input type="text" name="jform[city]" id="jform_city" value="" class="required" size="30" placeholder="Stadt" maxlength="255" required="required" aria-required="true">
</div>
</div>
<div class="control-group address-group">
<div class="control-label">
<label id="jform_address-lbl" for="jform_address" class="">
Adresse</label> <span class="optional">(optional)</span>
</div>
<div class="controls">
<input type="text" name="jform[address]" id="jform_address" value="" size="30" placeholder="Adresse" maxlength="255">
</div>
</div>
<div class="control-group zip-group">
<div class="control-label">
<label id="jform_zip-lbl" for="jform_zip" class="">
Postleitzahl</label> <span class="optional">(optional)</span>
</div>
<div class="controls">
<input type="text" name="jform[zip]" id="jform_zip" value="" size="30" placeholder="Postleitzahl" maxlength="255">
</div>
</div>
<div class="control-group gdpr-group">
<div class="control-label" style="display: none;">
<label id="jform_gdpr-lbl" for="jform_gdpr" class="required">
<span class="no-title">Privacy Policy</span><span class="star">&nbsp;*</span></label>
</div>
<div class="controls">
<fieldset id="jform_gdpr" class="required checkboxes" required="required" aria-required="true">
<label for="jform_gdpr0" class="checkbox ">
<input type="checkbox" id="jform_gdpr0" name="jform[gdpr][]" value="1"> Ich habe die <a href="/datenschutzbestimmungent" target="_blank">Datenschutzbestimmungen</a> von ARCHLine.XP gelesen und bin damit einverstanden</a></label>
</fieldset>
</div>
</div>
<div class="control-group">
<div class="controls">
<button type="submit" class="btn btn-primary validate g-recaptcha" data-sitekey="6Le1o70lAAAAAAyKS0PSXpNnU8YfFzpKOUqxB6We" data-callback='onCatpchaSubmit' data-action='submit'>
<?php echo JText::_('JREGISTER'); ?>
</button>
<a class="btn" href="<?php echo JRoute::_(''); ?>" title="<?php echo JText::_('JCANCEL'); ?>">
<?php echo JText::_('JCANCEL'); ?>
</a>
<input type="hidden" name="option" value="com_users" />
<input type="hidden" name="task" value="registration.register" />
</div>
</div>
<?php echo JHtml::_('form.token'); ?>
</form>
</div>
<script>
function onCatpchaSubmit(token) {
document.getElementById("member-registration").submit();
}
</script>

View File

@ -0,0 +1,15 @@
{
"finding_ref": "7265",
"log_excerpt": "[quarantine] www.archlinexp.eu:components/com_users/views/registration/tmpl/default.php -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/components/com_users/views/registration/tmpl/default.php)",
"original_sha256": "c362b87f0b31a19b551012f06fcde8b00d0eacda164c95a95b87f3f467426b6f",
"original_stat": {
"gid": 30037,
"mtime": 1682582236,
"size": 19437,
"uid": 12425
},
"rel_path": "components/com_users/views/registration/tmpl/default.php",
"result": "quarantined",
"timestamp": "20260718T160204Z",
"vhost": "www.archlinexp.eu"
}

File diff suppressed because it is too large Load Diff

View File

@ -0,0 +1,15 @@
{
"finding_ref": "7201",
"log_excerpt": "[quarantine] www.archlinexp.eu:libraries/cms/html/behavior.php -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/libraries/cms/html/behavior.php)",
"original_sha256": "b7e3e5f1cba9c986a3624ff1bd80216bc8ae36c853cbe5c2f443499db4502951",
"original_stat": {
"gid": 30037,
"mtime": 1707919845,
"size": 31861,
"uid": 12425
},
"rel_path": "libraries/cms/html/behavior.php",
"result": "quarantined",
"timestamp": "20260718T160204Z",
"vhost": "www.archlinexp.eu"
}

View File

@ -0,0 +1,67 @@
<?php
defined('_JEXEC') or die;
jimport('joomla.user.helper');
class ModAlNewsletterHelper
{
public static function insertUser($name, $email)
{
$db = JFactory::getDbo();
$query = "SELECT u_emails_id, nUserID, newsletter FROM cl_hlusers.u_emails WHERE email = '{$email}'";
$db->setQuery($query);
$existingUser = $db->loadObject();
if (!empty($existingUser)) {
if ($existingUser->newsletter == 1)
return true;
$db->getQuery(true);
$query = "UPDATE cl_hlusers.u_emails SET newsletter = 1 WHERE u_emails_id = '{$existingUser->u_emails_id}'";
$db->setQuery($query);
$db->execute();
return true;
}
$old_db = (JFactory::getLanguage()->getTag() == 'hu-HU' ? "clusers" : "clusers_eng");
$ctrID = (JFactory::getLanguage()->getTag() == 'hu-HU' ? 36 : 0);
$user = new stdClass();
$user->strName = $name;
$user->strEMail = $email;
$user->nUserType = 0;
$user->nUserStatus = 0;
$user->nUserProf = 0;
$user->old_db = $old_db;
$user->nSchoolID = 0;
$user->nCtrID = $ctrID;
JFactory::getDbo()->insertObject('cl_hlusers.users', $user);
$nUserID = $db->insertid();
$history = new stdClass();
$history->nUserID = $nUserID;
$history->nTopicID = (JFactory::getLanguage()->getTag() == 'hu-HU' ? 38 : 150);
$history->dateEvent = date('Y-m-d');
$history->insertDate = date('Y-m-d H:i:s');
$history->strPlace = 'web';
$history->nManagerID = 36;
JFactory::getDbo()->insertObject('cl_hlusers.u_history', $history);
$emails = new stdClass();
$emails->email = $email;
$emails->nUserID = $nUserID;
$emails->default = 1;
$emails->active = 1;
$emails->deleted = 0;
$emails->newsletter = 1;
JFactory::getDbo()->insertObject('cl_hlusers.u_emails', $emails);
return true;
}
}

View File

@ -0,0 +1,15 @@
{
"finding_ref": "7240",
"log_excerpt": "[quarantine] www.archlinexp.eu:modules/mod_al_newsletter/helper.php -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/modules/mod_al_newsletter/helper.php)",
"original_sha256": "b7956607a80914f9937904e84970f2e1e67774f4aba36604c4be02572ed61818",
"original_stat": {
"gid": 30037,
"mtime": 1666076765,
"size": 2227,
"uid": 20043
},
"rel_path": "modules/mod_al_newsletter/helper.php",
"result": "quarantined",
"timestamp": "20260718T160204Z",
"vhost": "www.archlinexp.eu"
}

View File

@ -0,0 +1,10 @@
<!DOCTYPE HTML>
<html>
<head>
<meta charset="utf-8">
<title></title>
</head>
<body>
<a href="http://xdsoft.net/joomla/module_generator/">Joomla Module Generator</a>
</body>
</html>

View File

@ -0,0 +1,15 @@
{
"finding_ref": "7238",
"log_excerpt": "[quarantine] www.archlinexp.eu:modules/mod_al_newsletter/index.html -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/modules/mod_al_newsletter/index.html)",
"original_sha256": "647cde511844340d9fac1c8247d2ddbcb03c29471da015a4eaf34224a623815d",
"original_stat": {
"gid": 30037,
"mtime": 1666075362,
"size": 191,
"uid": 20043
},
"rel_path": "modules/mod_al_newsletter/index.html",
"result": "quarantined",
"timestamp": "20260718T160204Z",
"vhost": "www.archlinexp.eu"
}

View File

@ -0,0 +1,8 @@
MOD_AL_NEWSLETTER_SUBSCRIBE_HEADER="Jetzt unseren wöchentlichen Newsletter abonnieren!"
MOD_AL_NEWSLETTER_SUBSCRIBE_TEXT="Werden Sie Mitglied in unserer Community und erhalten Sie die neuesten Tutorials, Angebote und Nachrichten direkt per E-Mail."
MOD_AL_NEWSLETTER_NAME="Name"
MOD_AL_NEWSLETTER_NAME_PLACEHOLDER="Your name"
MOD_AL_NEWSLETTER_EMAIL="Email"
MOD_AL_NEWSLETTER_EMAIL_PLACEHOLDER="E-mail Adresse"
MOD_AL_NEWSLETTER_SUBSCRIBE_BTN="Abonnieren"
MOD_AL_NEWSLETTER_DONE="Danke für Ihr Abonnement"

View File

@ -0,0 +1,15 @@
{
"finding_ref": "7245",
"log_excerpt": "[quarantine] www.archlinexp.eu:modules/mod_al_newsletter/language/de-DE/de-DE.mod_al_newsletter.ini -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/modules/mod_al_newsletter/language/de-DE/de-DE.mod_al_newsletter.ini)",
"original_sha256": "b4c34415a7fef19b193d8f8cde917e276ca585c5fc43b0157c5428059a8a9796",
"original_stat": {
"gid": 30037,
"mtime": 1666075362,
"size": 514,
"uid": 20043
},
"rel_path": "modules/mod_al_newsletter/language/de-DE/de-DE.mod_al_newsletter.ini",
"result": "quarantined",
"timestamp": "20260718T160204Z",
"vhost": "www.archlinexp.eu"
}

View File

@ -0,0 +1,7 @@
MOD_AL_NEWSLETTER_SUBSCRIBE_HEADER="GET OUR NEWSLETTER"
MOD_AL_NEWSLETTER_SUBSCRIBE_TEXT="Want the latest and greatest from our blog straight to your inbox? Chucks us your details and get a sweet weekly email."
MOD_AL_NEWSLETTER_NAME="Name"
MOD_AL_NEWSLETTER_NAME_PLACEHOLDER="Your name"
MOD_AL_NEWSLETTER_EMAIL="Email"
MOD_AL_NEWSLETTER_EMAIL_PLACEHOLDER="Your email address"
MOD_AL_NEWSLETTER_SUBSCRIBE_BTN="Subscribe"

View File

@ -0,0 +1,15 @@
{
"finding_ref": "7244",
"log_excerpt": "[quarantine] www.archlinexp.eu:modules/mod_al_newsletter/language/de-DE/de-DE.mod_al_newsletter.sys.ini -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/modules/mod_al_newsletter/language/de-DE/de-DE.mod_al_newsletter.sys.ini)",
"original_sha256": "6aa67b1e7671a2e12d9eceea4dd8a01c9b053208d565b20ba961e0bb8a4d8793",
"original_stat": {
"gid": 30037,
"mtime": 1666075362,
"size": 426,
"uid": 20043
},
"rel_path": "modules/mod_al_newsletter/language/de-DE/de-DE.mod_al_newsletter.sys.ini",
"result": "quarantined",
"timestamp": "20260718T160204Z",
"vhost": "www.archlinexp.eu"
}

View File

@ -0,0 +1,8 @@
MOD_AL_NEWSLETTER_SUBSCRIBE_HEADER="Subscribe to our weekly newsletter!"
MOD_AL_NEWSLETTER_SUBSCRIBE_TEXT="Join our community to get the latest tutorials, offers and news delivered directly in your inbox."
MOD_AL_NEWSLETTER_NAME="Name"
MOD_AL_NEWSLETTER_NAME_PLACEHOLDER="Your name"
MOD_AL_NEWSLETTER_EMAIL="Email"
MOD_AL_NEWSLETTER_EMAIL_PLACEHOLDER="Your email address"
MOD_AL_NEWSLETTER_SUBSCRIBE_BTN="Subscribe"
MOD_AL_NEWSLETTER_DONE="Thank you for subscribing"

View File

@ -0,0 +1,15 @@
{
"finding_ref": "7247",
"log_excerpt": "[quarantine] www.archlinexp.eu:modules/mod_al_newsletter/language/en-GB/en-GB.mod_al_newsletter.ini -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/modules/mod_al_newsletter/language/en-GB/en-GB.mod_al_newsletter.ini)",
"original_sha256": "112d4cbd2f2bcc865926f7348639e346cb3d0fb8a5c3e4f005912ffa95c581d4",
"original_stat": {
"gid": 30037,
"mtime": 1666075362,
"size": 473,
"uid": 20043
},
"rel_path": "modules/mod_al_newsletter/language/en-GB/en-GB.mod_al_newsletter.ini",
"result": "quarantined",
"timestamp": "20260718T160204Z",
"vhost": "www.archlinexp.eu"
}

View File

@ -0,0 +1,7 @@
MOD_AL_NEWSLETTER_SUBSCRIBE_HEADER="GET OUR NEWSLETTER"
MOD_AL_NEWSLETTER_SUBSCRIBE_TEXT="Want the latest and greatest from our blog straight to your inbox? Chucks us your details and get a sweet weekly email."
MOD_AL_NEWSLETTER_NAME="Name"
MOD_AL_NEWSLETTER_NAME_PLACEHOLDER="Your name"
MOD_AL_NEWSLETTER_EMAIL="Email"
MOD_AL_NEWSLETTER_EMAIL_PLACEHOLDER="Your email address"
MOD_AL_NEWSLETTER_SUBSCRIBE_BTN="Subscribe"

View File

@ -0,0 +1,15 @@
{
"finding_ref": "7246",
"log_excerpt": "[quarantine] www.archlinexp.eu:modules/mod_al_newsletter/language/en-GB/en-GB.mod_al_newsletter.sys.ini -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/modules/mod_al_newsletter/language/en-GB/en-GB.mod_al_newsletter.sys.ini)",
"original_sha256": "6aa67b1e7671a2e12d9eceea4dd8a01c9b053208d565b20ba961e0bb8a4d8793",
"original_stat": {
"gid": 30037,
"mtime": 1666075362,
"size": 426,
"uid": 20043
},
"rel_path": "modules/mod_al_newsletter/language/en-GB/en-GB.mod_al_newsletter.sys.ini",
"result": "quarantined",
"timestamp": "20260718T160204Z",
"vhost": "www.archlinexp.eu"
}

View File

@ -0,0 +1,8 @@
MOD_AL_NEWSLETTER_SUBSCRIBE_HEADER="Iratkozz fel heti hírlevelünkre!"
MOD_AL_NEWSLETTER_SUBSCRIBE_TEXT="Csatlakozz az ARCHLine.XP közösségéhez, értesülj elsők között oktatóvideóinkról, akcióinkről és híreinkről! "
MOD_AL_NEWSLETTER_NAME="Név"
MOD_AL_NEWSLETTER_NAME_PLACEHOLDER="Név"
MOD_AL_NEWSLETTER_EMAIL="Email"
MOD_AL_NEWSLETTER_EMAIL_PLACEHOLDER="Email"
MOD_AL_NEWSLETTER_SUBSCRIBE_BTN="Feliratkozom"
MOD_AL_NEWSLETTER_DONE="Köszönjük, hogy feliratkozott hírlevelünkre"

View File

@ -0,0 +1,15 @@
{
"finding_ref": "7242",
"log_excerpt": "[quarantine] www.archlinexp.eu:modules/mod_al_newsletter/language/hu-HU/hu-HU.mod_al_newsletter.ini -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/modules/mod_al_newsletter/language/hu-HU/hu-HU.mod_al_newsletter.ini)",
"original_sha256": "1ee232c97d9600124baa334bd87c71b5103131e6ef29bf9aa145b28aeabb6e97",
"original_stat": {
"gid": 30037,
"mtime": 1666075362,
"size": 508,
"uid": 20043
},
"rel_path": "modules/mod_al_newsletter/language/hu-HU/hu-HU.mod_al_newsletter.ini",
"result": "quarantined",
"timestamp": "20260718T160204Z",
"vhost": "www.archlinexp.eu"
}

View File

@ -0,0 +1,7 @@
MOD_AL_NEWSLETTER_SUBSCRIBE_HEADER="Iratkozzon fel hírlevelünkre"
MOD_AL_NEWSLETTER_SUBSCRIBE_TEXT="Szeretné a legújabb és legjobb híreket blogunkról egyenesen a postaládájába? Elküldi nekünk az adatait, és kap egy kedves heti e-mailt."
MOD_AL_NEWSLETTER_NAME="Név"
MOD_AL_NEWSLETTER_NAME_PLACEHOLDER="A neve"
MOD_AL_NEWSLETTER_EMAIL="Email"
MOD_AL_NEWSLETTER_EMAIL_PLACEHOLDER="Az email címe"
MOD_AL_NEWSLETTER_SUBSCRIBE_BTN="Feliratkozás"

View File

@ -0,0 +1,15 @@
{
"finding_ref": "7243",
"log_excerpt": "[quarantine] www.archlinexp.eu:modules/mod_al_newsletter/language/hu-HU/hu-HU.mod_al_newsletter.sys.ini -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/modules/mod_al_newsletter/language/hu-HU/hu-HU.mod_al_newsletter.sys.ini)",
"original_sha256": "fe3e8aca75ff56194b30ab42b861b09a22a2ca313624d1ae62e18b10cfefd368",
"original_stat": {
"gid": 30037,
"mtime": 1666075362,
"size": 462,
"uid": 20043
},
"rel_path": "modules/mod_al_newsletter/language/hu-HU/hu-HU.mod_al_newsletter.sys.ini",
"result": "quarantined",
"timestamp": "20260718T160204Z",
"vhost": "www.archlinexp.eu"
}

View File

@ -0,0 +1,19 @@
<?php
defined('_JEXEC') or die;
require_once dirname(__FILE__) . '/helper.php';
if (isset($_POST['subscribe-newsletter-btn'])) {
$user = ModAlNewsletterHelper::insertUser($_POST['name'], $_POST['email']);
unset($_POST['subscribe-newsletter-btn']);
unset($_POST['name']);
unset($_POST['email']);
if ($user) {
$app = JFactory::getApplication();
$app->enqueueMessage(JText::_('MOD_AL_NEWSLETTER_DONE'));
}
}
require JModuleHelper::getLayoutPath('mod_al_newsletter', $params->get('layout', 'default'));

View File

@ -0,0 +1,15 @@
{
"finding_ref": "7241",
"log_excerpt": "[quarantine] www.archlinexp.eu:modules/mod_al_newsletter/mod_al_newsletter.php -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/modules/mod_al_newsletter/mod_al_newsletter.php)",
"original_sha256": "9eaa9a68edd1e4498587bcb45e83748e0644206df67207146c15db9762edd19e",
"original_stat": {
"gid": 30037,
"mtime": 1666075362,
"size": 563,
"uid": 20043
},
"rel_path": "modules/mod_al_newsletter/mod_al_newsletter.php",
"result": "quarantined",
"timestamp": "20260718T160204Z",
"vhost": "www.archlinexp.eu"
}

View File

@ -0,0 +1,44 @@
<?xml version="1.0" encoding="utf-8"?>
<extension type="module" method="upgrade" client="site">
<name>mod_al_newsletter</name>
<creationDate>August 2022</creationDate>
<author>Nagy Máté</author>
<authorEmail>mate.nagy@cadline.hu</authorEmail>
<copyright>Copyright © 2021 - All rights reserved.</copyright>
<version>0.0.1</version>
<description>Create a newsletter subscription popup modal</description>
<files>
<filename module="mod_al_newsletter">mod_al_newsletter.php</filename>
<filename>mod_al_newsletter.xml</filename>
<filename>index.html</filename>
<filename>helper.php</filename>
<folder>language</folder>
<folder>tmpl</folder>
</files>
<config>
<fields name="params">
<fieldset name="advanced">
<field name="layout" type="modulelayout" label="JFIELD_ALT_LAYOUT_LABEL" description="JFIELD_ALT_MODULE_LAYOUT_DESC" />
<field name="moduleclass_sfx" type="textarea" rows="3" label="COM_MODULES_FIELD_MODULECLASS_SFX_LABEL" description="COM_MODULES_FIELD_MODULECLASS_SFX_DESC" />
<field name="cache" type="list" default="1" label="COM_MODULES_FIELD_CACHING_LABEL" description="COM_MODULES_FIELD_CACHING_DESC">
<option value="1">JGLOBAL_USE_GLOBAL</option>
<option value="0">COM_MODULES_FIELD_VALUE_NOCACHING</option>
</field>
<field name="cache_time" type="text" default="900" label="COM_MODULES_FIELD_CACHE_TIME_LABEL" description="COM_MODULES_FIELD_CACHE_TIME_DESC" />
<field name="cachemode" type="hidden" default="static">
<option value="static"></option>
</field>
</fieldset>
</fields>
</config>
<languages folder="language">
<language tag="en-GB">en-GB/en-GB.mod_al_newsletter.sys.ini</language>
<language tag="en-GB">en-GB/en-GB.mod_al_newsletter.ini</language>
<language tag="hu-HU">hu-HU/hu-HU.mod_al_newsletter.sys.ini</language>
<language tag="hu-HU">hu-HU/hu-HU.mod_al_newsletter.ini</language>
<language tag="de-DE">de-DE/de-DE.mod_al_newsletter.sys.ini</language>
<language tag="de-DE">de-DE/de-DE.mod_al_newsletter.ini</language>
</languages>
</extension>

View File

@ -0,0 +1,15 @@
{
"finding_ref": "7239",
"log_excerpt": "[quarantine] www.archlinexp.eu:modules/mod_al_newsletter/mod_al_newsletter.xml -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/modules/mod_al_newsletter/mod_al_newsletter.xml)",
"original_sha256": "63093cd4600619b21a0b611c46f598ec3074df45ec183860c0ff6119897ea0ce",
"original_stat": {
"gid": 30037,
"mtime": 1666075362,
"size": 2115,
"uid": 20043
},
"rel_path": "modules/mod_al_newsletter/mod_al_newsletter.xml",
"result": "quarantined",
"timestamp": "20260718T160204Z",
"vhost": "www.archlinexp.eu"
}

View File

@ -0,0 +1,49 @@
<?php defined('_JEXEC') or die; ?>
<!-- Modal -->
<div class="modal" id="newsLetterSubscribeModal" tabindex="-1" role="dialog" aria-labelledby="termsModalLabel" aria-hidden="true">
<div class="modal-dialog" role="document">
<!-- Modal content-->
<div class="modal-content">
<div class="modal-header">
<h4 class="modal-title"><?= JText::_('MOD_AL_NEWSLETTER_SUBSCRIBE_HEADER') ?></h4>
<button type="button" class="close" data-dismiss="modal" aria-label="Close">
<span aria-hidden="true">&times;</span>
</button>
</div>
<div class="modal-body">
<p><?= JText::_('MOD_AL_NEWSLETTER_SUBSCRIBE_TEXT') ?></p>
<hr>
<form action="" method="post">
<div class="form-group">
<label for="name"><b><?= JText::_('MOD_AL_NEWSLETTER_NAME') ?>:</b></label>
<input type="text" class="form-control" id="name" placeholder="<?= JText::_('MOD_AL_NEWSLETTER_NAME_PLACEHOLDER') ?>" name="name" required>
</div>
<div class="form-group">
<label for="email"><b><?= JText::_('MOD_AL_NEWSLETTER_EMAIL') ?>:</b></label>
<input type="email" class="form-control" id="email" placeholder="<?= JText::_('MOD_AL_NEWSLETTER_EMAIL_PLACEHOLDER') ?>" name="email" required>
</div>
<br>
<button type="submit" name="subscribe-newsletter-btn" class="btn btn-primary"><?= JText::_('MOD_AL_NEWSLETTER_SUBSCRIBE_BTN') ?></button>
</form>
</div>
</div>
</div>
</div>
<script>
jQuery(document).ready(function() {
jQuery('#alNewsletterBtn').after('<button class="btn btn-primary" data-toggle="modal" data-target="#newsLetterSubscribeModal">Abonnieren</button>');
/*if (localStorage.getItem('al_newsletter') == null)
jQuery("#newsLetterSubscribeModal").modal();*/
jQuery('#newsLetterSubscribeModal').on('shown.bs.modal', function(e) {
if (localStorage.getItem('al_newsletter') == null)
localStorage.setItem('al_newsletter', true);
});
});
</script>

View File

@ -0,0 +1,15 @@
{
"finding_ref": "7249",
"log_excerpt": "[quarantine] www.archlinexp.eu:modules/mod_al_newsletter/tmpl/default.php -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/modules/mod_al_newsletter/tmpl/default.php)",
"original_sha256": "647148d53fa91736b4f4e5afa5e5f90987320636c0e8dbf132e02af872714b6e",
"original_stat": {
"gid": 30037,
"mtime": 1673448300,
"size": 2360,
"uid": 20043
},
"rel_path": "modules/mod_al_newsletter/tmpl/default.php",
"result": "quarantined",
"timestamp": "20260718T160204Z",
"vhost": "www.archlinexp.eu"
}

View File

@ -0,0 +1,10 @@
<!DOCTYPE HTML>
<html>
<head>
<meta charset="utf-8">
<title></title>
</head>
<body>
<a href="http://xdsoft.net/joomla/module_generator/">Joomla Module Generator</a>
</body>
</html>

View File

@ -0,0 +1,15 @@
{
"finding_ref": "7248",
"log_excerpt": "[quarantine] www.archlinexp.eu:modules/mod_al_newsletter/tmpl/index.html -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/modules/mod_al_newsletter/tmpl/index.html)",
"original_sha256": "647cde511844340d9fac1c8247d2ddbcb03c29471da015a4eaf34224a623815d",
"original_stat": {
"gid": 30037,
"mtime": 1666075362,
"size": 191,
"uid": 20043
},
"rel_path": "modules/mod_al_newsletter/tmpl/index.html",
"result": "quarantined",
"timestamp": "20260718T160204Z",
"vhost": "www.archlinexp.eu"
}

View File

@ -0,0 +1,149 @@
<?php
defined('_JEXEC') or die;
jimport('joomla.user.helper');
class ModAlVoteHelper
{
public static function getItem()
{
$result = array();
$user = JFactory::getUser();
$albumId = 4;
try {
$db = JFactory::getDbo();
$query = $db->getQuery(true)
->select('a.*')
->from('www_archline_hu.jml_speasyimagegallery_albums as a')
->where('a.id = ' . (int) $albumId);
$query->select('l.title AS language_title')
->leftJoin($db->quoteName('#__languages') . ' AS l ON l.lang_code = a.language');
$query->select('ua.name AS author_name')
->leftJoin('#__users AS ua ON ua.id = a.created_by');
// Filter by published state.
$query->where('a.published = 1');
$db->setQuery($query);
$data = $db->loadObject();
if (isset($data->id) && $data->id) {
$data->images = self::getImages($data->id);
}
if (empty($data)) {
return JError::raiseError(404, JText::_('COM_SPEASYIMAGEGALLERY_ERROR_ALBUM_NOT_FOUND'));
}
$user = JFactory::getUser();
$groups = $user->getAuthorisedViewLevels();
if (!in_array($data->access, $groups)) {
return JError::raiseError(404, JText::_('COM_SPEASYIMAGEGALLERY_ERROR_ALBUM_NOT_AUTHORISED'));
}
$result[$albumId] = $data;
} catch (Exception $e) {
if ($e->getCode() == 404) {
JError::raiseError(404, $e->getMessage());
} else {
$result[$albumId] = false;
}
}
return $result[$albumId];
}
public static function isVoted($pictureId, $albumId, $userId)
{
$db = JFactory::getDbo();
$query = "SELECT id FROM www_archline_hu.al_picture_vote
WHERE picture_id = {$pictureId} AND album_id = {$albumId} AND nUserID = {$userId}";
$db->setQuery($query);
$existingVote = $db->loadObject();
return !empty($existingVote);
}
public static function getImages($album_id)
{
$db = JFactory::getDbo();
$query = $db->getQuery(true);
$query->select(array('a.*', 'b.picture_id', 'count(b.userID) AS voteCount'));
$query->from($db->quoteName('www_archline_hu.jml_speasyimagegallery_images', 'a'));
$query->join('LEFT', $db->quoteName('www_archline_hu.al_picture_vote', 'b') . ' ON ' . $db->quoteName('a.id') . ' = ' . $db->quoteName('b.picture_id'));
$query->where($db->quoteName('a.album_id') . ' = ' . $db->quote($album_id));
$query->where($db->quoteName('a.state') . ' = ' . $db->quote(1));
$query->order('a.title ASC');
$query->group($db->quoteName('a.id'));
$db->setQuery($query);
return $db->loadObjectList();
}
public static function votePicture($pictureId, $albumId, $userId, $nUserID)
{
$db = JFactory::getDbo();
$query = "SELECT id FROM www_archline_hu.al_picture_vote
WHERE picture_id = {$pictureId} AND album_id = {$albumId} AND nUserID = {$nUserID}";
$db->setQuery($query);
$existingVote = $db->loadObject();
if (!empty($existingVote))
return false;
$vote = new stdClass();
$vote->picture_id = $pictureId;
$vote->album_id = $albumId;
$vote->userID = $userId;
$vote->nUserID = $nUserID;
JFactory::getDbo()->insertObject('www_archline_hu.al_picture_vote', $vote);
if ($nUserID != null && $nUserID != '') {
$topic = (JFactory::getLanguage()->getTag() == 'hu-HU' ? 322 : 153);
$query = "SELECT * FROM cl_hlusers.u_history
WHERE nUserID = {$nUserID} AND nTopicID = {$topic} AND strPlace = 'Rendering pályázat 2023 szavazás'";
$db->setQuery($query);
$existingVote = $db->loadObject();
if (empty($existingVote)) {
$history = new stdClass();
$history->nUserID = $nUserID;
$history->nTopicID = $topic;
$history->dateEvent = date('Y-m-d');
$history->strPlace = 'Rendering pályázat 2023 szavazás';
$history->strInfo = 'Rendering pályázat 2023 szavazás';
$history->nManagerID = 36;
JFactory::getDbo()->insertObject('cl_hlusers.u_history', $history);
}
}
return true;
}
public static function getWinnerPictures($album_id)
{
$db = JFactory::getDbo();
$query = $db->getQuery(true);
$query->select(array('a.*', 'b.*', 'count(b.userID) AS voteCount'));
$query->from($db->quoteName('www_archline_hu.jml_speasyimagegallery_images', 'a'));
$query->join('LEFT', $db->quoteName('www_archline_hu.al_picture_vote', 'b') . ' ON ' . $db->quoteName('a.id') . ' = ' . $db->quoteName('b.picture_id'));
$query->where($db->quoteName('a.album_id') . ' = ' . $db->quote($album_id));
$query->where($db->quoteName('a.state') . ' = ' . $db->quote(1));
$query->order('count(b.userID) DESC');
$query->group($db->quoteName('a.id'));
$db->setQuery($query);
$winners = $db->loadObjectList();
for ($i = 0; $i < count($winners); $i++)
$winners[$i]->source = json_decode($winners[$i]->images);
return $winners;
}
}

View File

@ -0,0 +1,15 @@
{
"finding_ref": "7218",
"log_excerpt": "[quarantine] www.archlinexp.eu:modules/mod_al_vote/helper.php -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/modules/mod_al_vote/helper.php)",
"original_sha256": "0b5c924a705ef20a151755d51cc1ec0f6a14259dc95fe8275999c9fd5ccef384",
"original_stat": {
"gid": 30037,
"mtime": 1676369734,
"size": 5750,
"uid": 20043
},
"rel_path": "modules/mod_al_vote/helper.php",
"result": "quarantined",
"timestamp": "20260718T160204Z",
"vhost": "www.archlinexp.eu"
}

View File

@ -0,0 +1,10 @@
<!DOCTYPE HTML>
<html>
<head>
<meta charset="utf-8">
<title></title>
</head>
<body>
<a href="http://xdsoft.net/joomla/module_generator/">Joomla Module Generator</a>
</body>
</html>

View File

@ -0,0 +1,15 @@
{
"finding_ref": "7216",
"log_excerpt": "[quarantine] www.archlinexp.eu:modules/mod_al_vote/index.html -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/modules/mod_al_vote/index.html)",
"original_sha256": "647cde511844340d9fac1c8247d2ddbcb03c29471da015a4eaf34224a623815d",
"original_stat": {
"gid": 30037,
"mtime": 1676012882,
"size": 191,
"uid": 20043
},
"rel_path": "modules/mod_al_vote/index.html",
"result": "quarantined",
"timestamp": "20260718T160204Z",
"vhost": "www.archlinexp.eu"
}

View File

@ -0,0 +1,4 @@
MOD_AL_VOTE_SUCCESS="Thank you for participating in the poll, your vote was valid. <br>
Best regards, CadLine Kft."
MOD_AL_VOTE_VOTE="Vote"
MOD_AL_VOTE_VOTE_2="I vote"

View File

@ -0,0 +1,15 @@
{
"finding_ref": "7223",
"log_excerpt": "[quarantine] www.archlinexp.eu:modules/mod_al_vote/language/de-DE/de-DE.mod_al_vote.ini -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/modules/mod_al_vote/language/de-DE/de-DE.mod_al_vote.ini)",
"original_sha256": "b14f757d445fe29447b213ad3834a6485924704e56e103c95a0ddcf6a5d86b9b",
"original_stat": {
"gid": 30037,
"mtime": 1676012882,
"size": 170,
"uid": 20043
},
"rel_path": "modules/mod_al_vote/language/de-DE/de-DE.mod_al_vote.ini",
"result": "quarantined",
"timestamp": "20260718T160204Z",
"vhost": "www.archlinexp.eu"
}

View File

@ -0,0 +1,7 @@
MOD_AL_NEWSLETTER_SUBSCRIBE_HEADER="GET OUR NEWSLETTER"
MOD_AL_NEWSLETTER_SUBSCRIBE_TEXT="Want the latest and greatest from our blog straight to your inbox? Chucks us your details and get a sweet weekly email."
MOD_AL_NEWSLETTER_NAME="Name"
MOD_AL_NEWSLETTER_NAME_PLACEHOLDER="Your name"
MOD_AL_NEWSLETTER_EMAIL="Email"
MOD_AL_NEWSLETTER_EMAIL_PLACEHOLDER="Your email address"
MOD_AL_NEWSLETTER_SUBSCRIBE_BTN="Subscribe"

View File

@ -0,0 +1,15 @@
{
"finding_ref": "7222",
"log_excerpt": "[quarantine] www.archlinexp.eu:modules/mod_al_vote/language/de-DE/de-DE.mod_al_vote.sys.ini -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/modules/mod_al_vote/language/de-DE/de-DE.mod_al_vote.sys.ini)",
"original_sha256": "6aa67b1e7671a2e12d9eceea4dd8a01c9b053208d565b20ba961e0bb8a4d8793",
"original_stat": {
"gid": 30037,
"mtime": 1676012882,
"size": 426,
"uid": 20043
},
"rel_path": "modules/mod_al_vote/language/de-DE/de-DE.mod_al_vote.sys.ini",
"result": "quarantined",
"timestamp": "20260718T160204Z",
"vhost": "www.archlinexp.eu"
}

View File

@ -0,0 +1,4 @@
MOD_AL_VOTE_SUCCESS="Thank you for participating in the poll, your vote was valid. <br>
Best regards, CadLine Kft."
MOD_AL_VOTE_VOTE="Vote"
MOD_AL_VOTE_VOTE_2="I vote"

View File

@ -0,0 +1,15 @@
{
"finding_ref": "7225",
"log_excerpt": "[quarantine] www.archlinexp.eu:modules/mod_al_vote/language/en-GB/en-GB.mod_al_vote.ini -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/modules/mod_al_vote/language/en-GB/en-GB.mod_al_vote.ini)",
"original_sha256": "b14f757d445fe29447b213ad3834a6485924704e56e103c95a0ddcf6a5d86b9b",
"original_stat": {
"gid": 30037,
"mtime": 1676012882,
"size": 170,
"uid": 20043
},
"rel_path": "modules/mod_al_vote/language/en-GB/en-GB.mod_al_vote.ini",
"result": "quarantined",
"timestamp": "20260718T160204Z",
"vhost": "www.archlinexp.eu"
}

Some files were not shown because too many files have changed in this diff Show More