vanilla-restore: category=modified-benign (79 fájl)
vhost: www.archlinexp.eu rel_path: components/com_users/controller.php result: quarantined evidence_sha256: 2d0e5a25333180fc0976159ba409b32506d458b3239daa930474d8140a95bb92 timestamp: 20260718T160204Z finding_ref: 7252 vhost: www.archlinexp.eu rel_path: components/com_users/controllers/profile.json.php result: quarantined evidence_sha256: 14089aed5d01c80be03a7ff13f0b8f5b6a5fb5c37b7f8e72bf9ab98e5bbb976b timestamp: 20260718T160204Z finding_ref: 7257 vhost: www.archlinexp.eu rel_path: components/com_users/controllers/profile.php result: quarantined evidence_sha256: 0cef6b3e5fc0304afdb0005711b02d9a39d01fee0ce14903d4312f31a2fa540b timestamp: 20260718T160204Z finding_ref: 7258 vhost: www.archlinexp.eu rel_path: components/com_users/controllers/profile_base_json.php result: quarantined evidence_sha256: 11ec9184dddb0f201b18ec05c6a279f1d4b387813b80ed01dfe5040e00c93d4a timestamp: 20260718T160204Z finding_ref: 7259 vhost: www.archlinexp.eu rel_path: components/com_users/controllers/remind.php result: quarantined evidence_sha256: a6ef6d7b60043fa180e39c8efce1dcff804c8c2bbfa11d4e5e4d2ca36601972d timestamp: 20260718T160204Z finding_ref: 7255 vhost: www.archlinexp.eu rel_path: components/com_users/controllers/reset.php result: quarantined evidence_sha256: 224404ff37d78b3baf18f77b89e51e7599304b44b51fe6e4bf1ff9abf354ac0c timestamp: 20260718T160204Z finding_ref: 7256 vhost: www.archlinexp.eu rel_path: components/com_users/controllers/user.php result: quarantined evidence_sha256: d7472a9cb222592b7799229831d00ed6e728d082fd5ed5be616404edb8ad275c timestamp: 20260718T160204Z finding_ref: 7254 vhost: www.archlinexp.eu rel_path: components/com_users/helpers/html/users.php result: quarantined evidence_sha256: cb229ad16ba915a20aa22c49f2b5863cb4079cb5ce5fb3975b07b5caa161e786 timestamp: 20260718T160204Z finding_ref: 7283 vhost: www.archlinexp.eu rel_path: components/com_users/helpers/legacyrouter.php result: quarantined evidence_sha256: e25f6683f53657c5f1f0f03e80126eb3acbc3b270dd26f3bcd8e16fc72f72343 timestamp: 20260718T160204Z finding_ref: 7281 vhost: www.archlinexp.eu rel_path: components/com_users/helpers/route.php result: quarantined evidence_sha256: 2f2d92b287b854fc6ad31c8168badc5938e39bec1f8b6202d4df348cd23a23f0 timestamp: 20260718T160204Z finding_ref: 7282 vhost: www.archlinexp.eu rel_path: components/com_users/layouts/joomla/form/renderfield.php result: quarantined evidence_sha256: 767cc86103a71d15914e028fc231d5b48ffb5cdc5bf6ab8ecc3e22bb73d9190b timestamp: 20260718T160204Z finding_ref: 7284 vhost: www.archlinexp.eu rel_path: components/com_users/models/forms/profile.xml result: quarantined evidence_sha256: 6f217de7628ab4c162bef301a62851bd90557bc43062783410df850901f536ba timestamp: 20260718T160204Z finding_ref: 7278 vhost: www.archlinexp.eu rel_path: components/com_users/models/forms/registration.xml result: quarantined evidence_sha256: d8d90d9badd444b08bd7243d3621f6af3feaee137523c212b5b883883f805b7e timestamp: 20260718T160204Z finding_ref: 7277 vhost: www.archlinexp.eu rel_path: components/com_users/models/login.php result: quarantined evidence_sha256: 1bd545c9d69235efbd0ca01aa8e3fee5c0416f9d7e57647314f029d01c7bcb75 timestamp: 20260718T160204Z finding_ref: 7272 vhost: www.archlinexp.eu rel_path: components/com_users/models/profile.php result: quarantined evidence_sha256: 9120583bc9b1fc6d5c5b7a81fdd14c2d18250715cc89c672b743038cd62f7682 timestamp: 20260718T160204Z finding_ref: 7276 vhost: www.archlinexp.eu rel_path: components/com_users/models/registration.php result: quarantined evidence_sha256: 36f98683f5d734fd65acabfd638da4bff54196ce0f4fc2574c23ab9ef9b66ba6 timestamp: 20260718T160204Z finding_ref: 7275 vhost: www.archlinexp.eu rel_path: components/com_users/models/remind.php result: quarantined evidence_sha256: 25d8b3522b7b6fc0456dda7a2cc346c94e9b3889f4180d32f3e3101998791f1a timestamp: 20260718T160204Z finding_ref: 7273 vhost: www.archlinexp.eu rel_path: components/com_users/models/reset.php result: quarantined evidence_sha256: f948b6a494c8fe051b43bff9f12801d462e4d22f37607da2c5b3b6a7886dcd72 timestamp: 20260718T160204Z finding_ref: 7274 vhost: www.archlinexp.eu rel_path: components/com_users/models/rules/loginuniquefield.php result: quarantined evidence_sha256: 70dfe2a0662c32f12e612c1d5785006673319ec19766651ab15aefb880a2c5f2 timestamp: 20260718T160204Z finding_ref: 7279 vhost: www.archlinexp.eu rel_path: components/com_users/models/rules/logoutuniquefield.php result: quarantined evidence_sha256: 9bc602cb398ce792eafb70d3cba2fa732d6bffeb2bf88afc05de9e507334c095 timestamp: 20260718T160204Z finding_ref: 7280 vhost: www.archlinexp.eu rel_path: components/com_users/router.php result: quarantined evidence_sha256: 2b9acf14b84908cd85f8ffface816d5c7124f3226088696dccec501054773253 timestamp: 20260718T160204Z finding_ref: 7253 vhost: www.archlinexp.eu rel_path: components/com_users/users.php result: quarantined evidence_sha256: 6ed1fd07fc85fc4f09fd85926ce729ad711577f7cc3ceaf551c748b07dd2ae5c timestamp: 20260718T160204Z finding_ref: 7251 vhost: www.archlinexp.eu rel_path: components/com_users/views/login/tmpl/default.php result: quarantined evidence_sha256: 8dac9ace51133f1eea7a524ca6dd8de9fc5effedd7c5bb2b5f5562ccd2257efc timestamp: 20260718T160204Z finding_ref: 7269 vhost: www.archlinexp.eu rel_path: components/com_users/views/login/tmpl/default.xml result: quarantined evidence_sha256: 1e40888b8d147a0130bca03085edf7f94e97da2ed09e2aa4b6dfe41282162ecc timestamp: 20260718T160204Z finding_ref: 7270 vhost: www.archlinexp.eu rel_path: components/com_users/views/login/tmpl/default_login.php result: quarantined evidence_sha256: f619bd9d8abc8c0b2766659057d744280be80ff87f1705b5c23c9e74a8f6d6ed timestamp: 20260718T160204Z finding_ref: 7271 vhost: www.archlinexp.eu rel_path: components/com_users/views/login/tmpl/default_logout.php result: quarantined evidence_sha256: 17b5b52ed420d182ca4d96cdc494e204f3dfe024955ae4d91eaf68537daf1f52 timestamp: 20260718T160204Z finding_ref: 7268 vhost: www.archlinexp.eu rel_path: components/com_users/views/login/view.html.php result: quarantined evidence_sha256: 81388b133b1d59d485333ab97724d1a1d3616606f055d863da72bc0a9f0fbea3 timestamp: 20260718T160204Z finding_ref: 7267 vhost: www.archlinexp.eu rel_path: components/com_users/views/profile/tmpl/default.php result: quarantined evidence_sha256: d4133100827716d2da1eb9c60343fb744f2183367c917139a1767681ac200b17 timestamp: 20260718T160204Z finding_ref: 7260 vhost: www.archlinexp.eu rel_path: components/com_users/views/profile/tmpl/default_core.php result: quarantined evidence_sha256: dc8e27c5cf90263c3221ac79542f92ac1e7571cedaa42e6d2a9ad8d99f288765 timestamp: 20260718T160204Z finding_ref: 7263 vhost: www.archlinexp.eu rel_path: components/com_users/views/profile/tmpl/default_custom.php result: quarantined evidence_sha256: 9f2af47de5012a4c1fd0b79ff93f806b85c9c96ba7ea7132f1fb0004a1cf751f timestamp: 20260718T160204Z finding_ref: 7261 vhost: www.archlinexp.eu rel_path: components/com_users/views/profile/tmpl/default_params.php result: quarantined evidence_sha256: b206251975c81b9896dabbdbd16f56225ed1fb582d1ae8053ce397dcbd3381f3 timestamp: 20260718T160204Z finding_ref: 7264 vhost: www.archlinexp.eu rel_path: components/com_users/views/registration/tmpl/default.php result: quarantined evidence_sha256: c362b87f0b31a19b551012f06fcde8b00d0eacda164c95a95b87f3f467426b6f timestamp: 20260718T160204Z finding_ref: 7265 vhost: www.archlinexp.eu rel_path: libraries/cms/html/behavior.php result: quarantined evidence_sha256: b7e3e5f1cba9c986a3624ff1bd80216bc8ae36c853cbe5c2f443499db4502951 timestamp: 20260718T160204Z finding_ref: 7201 vhost: www.archlinexp.eu rel_path: modules/mod_al_newsletter/helper.php result: quarantined evidence_sha256: b7956607a80914f9937904e84970f2e1e67774f4aba36604c4be02572ed61818 timestamp: 20260718T160204Z finding_ref: 7240 vhost: www.archlinexp.eu rel_path: modules/mod_al_newsletter/index.html result: quarantined evidence_sha256: 647cde511844340d9fac1c8247d2ddbcb03c29471da015a4eaf34224a623815d timestamp: 20260718T160204Z finding_ref: 7238 vhost: www.archlinexp.eu rel_path: modules/mod_al_newsletter/language/de-DE/de-DE.mod_al_newsletter.ini result: quarantined evidence_sha256: b4c34415a7fef19b193d8f8cde917e276ca585c5fc43b0157c5428059a8a9796 timestamp: 20260718T160204Z finding_ref: 7245 vhost: www.archlinexp.eu rel_path: modules/mod_al_newsletter/language/de-DE/de-DE.mod_al_newsletter.sys.ini result: quarantined evidence_sha256: 6aa67b1e7671a2e12d9eceea4dd8a01c9b053208d565b20ba961e0bb8a4d8793 timestamp: 20260718T160204Z finding_ref: 7244 vhost: www.archlinexp.eu rel_path: modules/mod_al_newsletter/language/en-GB/en-GB.mod_al_newsletter.ini result: quarantined evidence_sha256: 112d4cbd2f2bcc865926f7348639e346cb3d0fb8a5c3e4f005912ffa95c581d4 timestamp: 20260718T160204Z finding_ref: 7247 vhost: www.archlinexp.eu rel_path: modules/mod_al_newsletter/language/en-GB/en-GB.mod_al_newsletter.sys.ini result: quarantined evidence_sha256: 6aa67b1e7671a2e12d9eceea4dd8a01c9b053208d565b20ba961e0bb8a4d8793 timestamp: 20260718T160204Z finding_ref: 7246 vhost: www.archlinexp.eu rel_path: modules/mod_al_newsletter/language/hu-HU/hu-HU.mod_al_newsletter.ini result: quarantined evidence_sha256: 1ee232c97d9600124baa334bd87c71b5103131e6ef29bf9aa145b28aeabb6e97 timestamp: 20260718T160204Z finding_ref: 7242 vhost: www.archlinexp.eu rel_path: modules/mod_al_newsletter/language/hu-HU/hu-HU.mod_al_newsletter.sys.ini result: quarantined evidence_sha256: fe3e8aca75ff56194b30ab42b861b09a22a2ca313624d1ae62e18b10cfefd368 timestamp: 20260718T160204Z finding_ref: 7243 vhost: www.archlinexp.eu rel_path: modules/mod_al_newsletter/mod_al_newsletter.php result: quarantined evidence_sha256: 9eaa9a68edd1e4498587bcb45e83748e0644206df67207146c15db9762edd19e timestamp: 20260718T160204Z finding_ref: 7241 vhost: www.archlinexp.eu rel_path: modules/mod_al_newsletter/mod_al_newsletter.xml result: quarantined evidence_sha256: 63093cd4600619b21a0b611c46f598ec3074df45ec183860c0ff6119897ea0ce timestamp: 20260718T160204Z finding_ref: 7239 vhost: www.archlinexp.eu rel_path: modules/mod_al_newsletter/tmpl/default.php result: quarantined evidence_sha256: 647148d53fa91736b4f4e5afa5e5f90987320636c0e8dbf132e02af872714b6e timestamp: 20260718T160204Z finding_ref: 7249 vhost: www.archlinexp.eu rel_path: modules/mod_al_newsletter/tmpl/index.html result: quarantined evidence_sha256: 647cde511844340d9fac1c8247d2ddbcb03c29471da015a4eaf34224a623815d timestamp: 20260718T160204Z finding_ref: 7248 vhost: www.archlinexp.eu rel_path: modules/mod_al_vote/helper.php result: quarantined evidence_sha256: 0b5c924a705ef20a151755d51cc1ec0f6a14259dc95fe8275999c9fd5ccef384 timestamp: 20260718T160204Z finding_ref: 7218 vhost: www.archlinexp.eu rel_path: modules/mod_al_vote/index.html result: quarantined evidence_sha256: 647cde511844340d9fac1c8247d2ddbcb03c29471da015a4eaf34224a623815d timestamp: 20260718T160204Z finding_ref: 7216 vhost: www.archlinexp.eu rel_path: modules/mod_al_vote/language/de-DE/de-DE.mod_al_vote.ini result: quarantined evidence_sha256: b14f757d445fe29447b213ad3834a6485924704e56e103c95a0ddcf6a5d86b9b timestamp: 20260718T160204Z finding_ref: 7223 vhost: www.archlinexp.eu rel_path: modules/mod_al_vote/language/de-DE/de-DE.mod_al_vote.sys.ini result: quarantined evidence_sha256: 6aa67b1e7671a2e12d9eceea4dd8a01c9b053208d565b20ba961e0bb8a4d8793 timestamp: 20260718T160204Z finding_ref: 7222 vhost: www.archlinexp.eu rel_path: modules/mod_al_vote/language/en-GB/en-GB.mod_al_vote.ini result: quarantined evidence_sha256: b14f757d445fe29447b213ad3834a6485924704e56e103c95a0ddcf6a5d86b9b timestamp: 20260718T160204Z finding_ref: 7225 vhost: www.archlinexp.eu rel_path: modules/mod_al_vote/language/en-GB/en-GB.mod_al_vote.sys.ini result: quarantined evidence_sha256: 6aa67b1e7671a2e12d9eceea4dd8a01c9b053208d565b20ba961e0bb8a4d8793 timestamp: 20260718T160204Z finding_ref: 7224 vhost: www.archlinexp.eu rel_path: modules/mod_al_vote/language/hu-HU/hu-HU.mod_al_vote.ini result: quarantined evidence_sha256: 5d8093e15f311eb8a3e44cd1710baaa1d347c423b5e2c9ff07fb0ea1876cd0de timestamp: 20260718T160204Z finding_ref: 7221 vhost: www.archlinexp.eu rel_path: modules/mod_al_vote/language/hu-HU/hu-HU.mod_al_vote.sys.ini result: quarantined evidence_sha256: fe3e8aca75ff56194b30ab42b861b09a22a2ca313624d1ae62e18b10cfefd368 timestamp: 20260718T160204Z finding_ref: 7220 vhost: www.archlinexp.eu rel_path: modules/mod_al_vote/mod_al_vote.php result: quarantined evidence_sha256: 176fd1c778009daba61f1e1289363e5b657a9ac6f558f21f9bc3723c14659135 timestamp: 20260718T160204Z finding_ref: 7219 vhost: www.archlinexp.eu rel_path: modules/mod_al_vote/mod_al_vote.xml result: quarantined evidence_sha256: 1ed8c27095489f0a0011b846d9a5434f5d1900b1e445dd3af1e1ae84d67ee5b5 timestamp: 20260718T160204Z finding_ref: 7217 vhost: www.archlinexp.eu rel_path: modules/mod_al_vote/tmpl/default.php result: quarantined evidence_sha256: 5bff3f42b1a1627e018b8c2ca635a83435f8504e9ff43e995bbbccbc401b548e timestamp: 20260718T160204Z finding_ref: 7227 vhost: www.archlinexp.eu rel_path: modules/mod_al_vote/tmpl/index.html result: quarantined evidence_sha256: 647cde511844340d9fac1c8247d2ddbcb03c29471da015a4eaf34224a623815d timestamp: 20260718T160204Z finding_ref: 7226 vhost: www.archlinexp.eu rel_path: modules/mod_alusers/assets/css/images/index.html result: quarantined evidence_sha256: 647cde511844340d9fac1c8247d2ddbcb03c29471da015a4eaf34224a623815d timestamp: 20260718T160204Z finding_ref: 7214 vhost: www.archlinexp.eu rel_path: modules/mod_alusers/assets/css/index.html result: quarantined evidence_sha256: 647cde511844340d9fac1c8247d2ddbcb03c29471da015a4eaf34224a623815d timestamp: 20260718T160204Z finding_ref: 7211 vhost: www.archlinexp.eu rel_path: modules/mod_alusers/assets/css/newstyle.css result: quarantined evidence_sha256: d70abf50ed939eb2e298de25d32af4f33a54815c9b90c4d0118c20ba498ffa32 timestamp: 20260718T160204Z finding_ref: 7212 vhost: www.archlinexp.eu rel_path: modules/mod_alusers/assets/css/style.css result: quarantined evidence_sha256: 34722adf5908c18835675b48bf1f7108c208216ce2ae7056455c1e160a86e887 timestamp: 20260718T160204Z finding_ref: 7213 vhost: www.archlinexp.eu rel_path: modules/mod_alusers/assets/index.html result: quarantined evidence_sha256: 647cde511844340d9fac1c8247d2ddbcb03c29471da015a4eaf34224a623815d timestamp: 20260718T160204Z finding_ref: 7210 vhost: www.archlinexp.eu rel_path: modules/mod_alusers/assets/js/index.html result: quarantined evidence_sha256: 647cde511844340d9fac1c8247d2ddbcb03c29471da015a4eaf34224a623815d timestamp: 20260718T160204Z finding_ref: 7215 vhost: www.archlinexp.eu rel_path: modules/mod_alusers/helper.php result: quarantined evidence_sha256: f32a272853a5e3b28097863308241216bf9ca011cf6dafe4ac4ccb63aeb8d7ae timestamp: 20260718T160204Z finding_ref: 7206 vhost: www.archlinexp.eu rel_path: modules/mod_alusers/index.html result: quarantined evidence_sha256: 647cde511844340d9fac1c8247d2ddbcb03c29471da015a4eaf34224a623815d timestamp: 20260718T160204Z finding_ref: 7204 vhost: www.archlinexp.eu rel_path: modules/mod_alusers/mod_alusers.php result: quarantined evidence_sha256: b3a03c1a602038b8d04ed872392111f716c34c5d602a192d4960aa9830ed95b5 timestamp: 20260718T160204Z finding_ref: 7207 vhost: www.archlinexp.eu rel_path: modules/mod_alusers/mod_alusers.xml result: quarantined evidence_sha256: 6c84ae2988438c5b40555e8862b72fce0d349b203dfcf54a58f3f9ba1ebf289e timestamp: 20260718T160204Z finding_ref: 7205 vhost: www.archlinexp.eu rel_path: modules/mod_alusers/tmpl/default.php result: quarantined evidence_sha256: 1fa3716d8853febb7a6630ffa262cd2dd2e3c9cdbf04b7fa107b4fafe7afa990 timestamp: 20260718T160204Z finding_ref: 7209 vhost: www.archlinexp.eu rel_path: modules/mod_alusers/tmpl/index.html result: quarantined evidence_sha256: 647cde511844340d9fac1c8247d2ddbcb03c29471da015a4eaf34224a623815d timestamp: 20260718T160204Z finding_ref: 7208 vhost: www.archlinexp.eu rel_path: modules/mod_course_list/helper.php result: quarantined evidence_sha256: 7b74a823c28f5516bbc785b36d16beafb6d01d229db1af93561488d67911fd27 timestamp: 20260718T160204Z finding_ref: 7230 vhost: www.archlinexp.eu rel_path: modules/mod_course_list/index.html result: quarantined evidence_sha256: 647cde511844340d9fac1c8247d2ddbcb03c29471da015a4eaf34224a623815d timestamp: 20260718T160204Z finding_ref: 7228 vhost: www.archlinexp.eu rel_path: modules/mod_course_list/language/en-GB/en-GB.mod_course_list.ini result: quarantined evidence_sha256: 4289718b100745f12113baff97d577817d0ad7fca3ed8a7d37360bd06b95d0ed timestamp: 20260718T160204Z finding_ref: 7235 vhost: www.archlinexp.eu rel_path: modules/mod_course_list/language/en-GB/en-GB.mod_course_list.sys.ini result: quarantined evidence_sha256: 4289718b100745f12113baff97d577817d0ad7fca3ed8a7d37360bd06b95d0ed timestamp: 20260718T160204Z finding_ref: 7234 vhost: www.archlinexp.eu rel_path: modules/mod_course_list/language/hu-HU/hu-HU.mod_course_list.ini result: quarantined evidence_sha256: 4289718b100745f12113baff97d577817d0ad7fca3ed8a7d37360bd06b95d0ed timestamp: 20260718T160204Z finding_ref: 7232 vhost: www.archlinexp.eu rel_path: modules/mod_course_list/language/hu-HU/hu-HU.mod_course_list.sys.ini result: quarantined evidence_sha256: 4289718b100745f12113baff97d577817d0ad7fca3ed8a7d37360bd06b95d0ed timestamp: 20260718T160204Z finding_ref: 7233 vhost: www.archlinexp.eu rel_path: modules/mod_course_list/mod_course_list.php result: quarantined evidence_sha256: 7ad520f80ac058de97c4942710890f49f62e7962bae0dc699694ddddc98961ac timestamp: 20260718T160204Z finding_ref: 7229 vhost: www.archlinexp.eu rel_path: modules/mod_course_list/mod_course_list.xml result: quarantined evidence_sha256: 2de45f9fb95060b6131cfba8e5a46bbd3f6027cbd11a97026966fbf948c0c89a timestamp: 20260718T160204Z finding_ref: 7231 vhost: www.archlinexp.eu rel_path: modules/mod_course_list/tmpl/default.php result: quarantined evidence_sha256: 7c7e3eec8538662acb59cbd9173f748aead4c052a1e10271c2216389983c83a2 timestamp: 20260718T160204Z finding_ref: 7237 vhost: www.archlinexp.eu rel_path: modules/mod_course_list/tmpl/index.html result: quarantined evidence_sha256: 647cde511844340d9fac1c8247d2ddbcb03c29471da015a4eaf34224a623815d timestamp: 20260718T160204Z finding_ref: 7236
This commit is contained in:
parent
9ccb96f418
commit
0ea6861988
@ -0,0 +1,136 @@
|
||||
<?php
|
||||
/**
|
||||
* @package Joomla.Site
|
||||
* @subpackage com_users
|
||||
*
|
||||
* @copyright Copyright (C) 2005 - 2018 Open Source Matters, Inc. All rights reserved.
|
||||
* @license GNU General Public License version 2 or later; see LICENSE.txt
|
||||
*/
|
||||
|
||||
defined('_JEXEC') or die;
|
||||
|
||||
/**
|
||||
* Base controller class for Users.
|
||||
*
|
||||
* @since 1.5
|
||||
*/
|
||||
class UsersController extends JControllerLegacy
|
||||
{
|
||||
/**
|
||||
* Method to display a view.
|
||||
*
|
||||
* @param boolean $cachable If true, the view output will be cached
|
||||
* @param array $urlparams An array of safe URL parameters and their variable types, for valid values see {@link JFilterInput::clean()}.
|
||||
*
|
||||
* @return JController This object to support chaining.
|
||||
*
|
||||
* @since 1.5
|
||||
*/
|
||||
public function display($cachable = false, $urlparams = false)
|
||||
{
|
||||
// Get the document object.
|
||||
$document = JFactory::getDocument();
|
||||
|
||||
// Set the default view name and format from the Request.
|
||||
$vName = $this->input->getCmd('view', 'login');
|
||||
$vFormat = $document->getType();
|
||||
$lName = $this->input->getCmd('layout', 'default');
|
||||
|
||||
if ($view = $this->getView($vName, $vFormat))
|
||||
{
|
||||
// Do any specific processing by view.
|
||||
switch ($vName)
|
||||
{
|
||||
case 'registration':
|
||||
// If the user is already logged in, redirect to the profile page.
|
||||
$user = JFactory::getUser();
|
||||
|
||||
if ($user->get('guest') != 1)
|
||||
{
|
||||
// Redirect to profile page.
|
||||
$this->setRedirect(JRoute::_('index.php?option=com_users&view=profile', false));
|
||||
|
||||
return;
|
||||
}
|
||||
|
||||
// Check if user registration is enabled
|
||||
if (JComponentHelper::getParams('com_users')->get('allowUserRegistration') == 0)
|
||||
{
|
||||
// Registration is disabled - Redirect to login page.
|
||||
$this->setRedirect(JRoute::_('index.php?option=com_users&view=login', false));
|
||||
|
||||
return;
|
||||
}
|
||||
|
||||
// The user is a guest, load the registration model and show the registration page.
|
||||
$model = $this->getModel('Registration');
|
||||
break;
|
||||
|
||||
// Handle view specific models.
|
||||
case 'profile':
|
||||
|
||||
// If the user is a guest, redirect to the login page.
|
||||
$user = JFactory::getUser();
|
||||
|
||||
if ($user->get('guest') == 1)
|
||||
{
|
||||
// Redirect to login page.
|
||||
$this->setRedirect(JRoute::_('index.php?option=com_users&view=login', false));
|
||||
|
||||
return;
|
||||
}
|
||||
|
||||
$model = $this->getModel($vName);
|
||||
break;
|
||||
|
||||
// Handle the default views.
|
||||
case 'login':
|
||||
$model = $this->getModel($vName);
|
||||
break;
|
||||
|
||||
case 'reset':
|
||||
// If the user is already logged in, redirect to the profile page.
|
||||
$user = JFactory::getUser();
|
||||
|
||||
if ($user->get('guest') != 1)
|
||||
{
|
||||
// Redirect to profile page.
|
||||
$this->setRedirect(JRoute::_('index.php?option=com_users&view=profile', false));
|
||||
|
||||
return;
|
||||
}
|
||||
|
||||
$model = $this->getModel($vName);
|
||||
break;
|
||||
|
||||
case 'remind':
|
||||
// If the user is already logged in, redirect to the profile page.
|
||||
$user = JFactory::getUser();
|
||||
|
||||
if ($user->get('guest') != 1)
|
||||
{
|
||||
// Redirect to profile page.
|
||||
$this->setRedirect(JRoute::_('index.php?option=com_users&view=profile', false));
|
||||
|
||||
return;
|
||||
}
|
||||
|
||||
$model = $this->getModel($vName);
|
||||
break;
|
||||
|
||||
default:
|
||||
$model = $this->getModel('Login');
|
||||
break;
|
||||
}
|
||||
|
||||
// Push the model into the view (as default).
|
||||
$view->setModel($model, true);
|
||||
$view->setLayout($lName);
|
||||
|
||||
// Push document object into the view.
|
||||
$view->document = $document;
|
||||
|
||||
$view->display();
|
||||
}
|
||||
}
|
||||
}
|
||||
@ -0,0 +1,15 @@
|
||||
{
|
||||
"finding_ref": "7252",
|
||||
"log_excerpt": "[quarantine] www.archlinexp.eu:components/com_users/controller.php -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/components/com_users/controller.php)",
|
||||
"original_sha256": "2d0e5a25333180fc0976159ba409b32506d458b3239daa930474d8140a95bb92",
|
||||
"original_stat": {
|
||||
"gid": 30037,
|
||||
"mtime": 1552901205,
|
||||
"size": 3467,
|
||||
"uid": 12425
|
||||
},
|
||||
"rel_path": "components/com_users/controller.php",
|
||||
"result": "quarantined",
|
||||
"timestamp": "20260718T160204Z",
|
||||
"vhost": "www.archlinexp.eu"
|
||||
}
|
||||
@ -0,0 +1,21 @@
|
||||
<?php
|
||||
/**
|
||||
* @package Joomla.Site
|
||||
* @subpackage com_users
|
||||
*
|
||||
* @copyright Copyright (C) 2005 - 2018 Open Source Matters, Inc. All rights reserved.
|
||||
* @license GNU General Public License version 2 or later; see LICENSE.txt
|
||||
*/
|
||||
|
||||
defined('_JEXEC') or die;
|
||||
|
||||
JLoader::register('UsersControllerProfile_Base_Json', __DIR__ . '/profile_base_json.php');
|
||||
|
||||
/**
|
||||
* Profile controller class for Users.
|
||||
*
|
||||
* @since 1.6
|
||||
*/
|
||||
class UsersControllerProfile extends UsersControllerProfile_Base_Json
|
||||
{
|
||||
}
|
||||
@ -0,0 +1,15 @@
|
||||
{
|
||||
"finding_ref": "7257",
|
||||
"log_excerpt": "[quarantine] www.archlinexp.eu:components/com_users/controllers/profile.json.php -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/components/com_users/controllers/profile.json.php)",
|
||||
"original_sha256": "14089aed5d01c80be03a7ff13f0b8f5b6a5fb5c37b7f8e72bf9ab98e5bbb976b",
|
||||
"original_stat": {
|
||||
"gid": 30037,
|
||||
"mtime": 1533967367,
|
||||
"size": 498,
|
||||
"uid": 12425
|
||||
},
|
||||
"rel_path": "components/com_users/controllers/profile.json.php",
|
||||
"result": "quarantined",
|
||||
"timestamp": "20260718T160204Z",
|
||||
"vhost": "www.archlinexp.eu"
|
||||
}
|
||||
@ -0,0 +1,260 @@
|
||||
<?php
|
||||
/**
|
||||
* @package Joomla.Site
|
||||
* @subpackage com_users
|
||||
*
|
||||
* @copyright Copyright (C) 2005 - 2018 Open Source Matters, Inc. All rights reserved.
|
||||
* @license GNU General Public License version 2 or later; see LICENSE.txt
|
||||
*/
|
||||
|
||||
defined('_JEXEC') or die;
|
||||
|
||||
JLoader::register('UsersController', JPATH_COMPONENT . '/controller.php');
|
||||
|
||||
/**
|
||||
* Profile controller class for Users.
|
||||
*
|
||||
* @since 1.6
|
||||
*/
|
||||
class UsersControllerProfile extends UsersController
|
||||
{
|
||||
/**
|
||||
* Method to check out a user for editing and redirect to the edit form.
|
||||
*
|
||||
* @return boolean
|
||||
*
|
||||
* @since 1.6
|
||||
*/
|
||||
public function edit()
|
||||
{
|
||||
$app = JFactory::getApplication();
|
||||
$user = JFactory::getUser();
|
||||
$loginUserId = (int) $user->get('id');
|
||||
|
||||
// Get the previous user id (if any) and the current user id.
|
||||
$previousId = (int) $app->getUserState('com_users.edit.profile.id');
|
||||
$userId = $this->input->getInt('user_id');
|
||||
|
||||
// Check if the user is trying to edit another users profile.
|
||||
if ($userId != $loginUserId)
|
||||
{
|
||||
$app->enqueueMessage(JText::_('JERROR_ALERTNOAUTHOR'), 'error');
|
||||
$app->setHeader('status', 403, true);
|
||||
|
||||
return false;
|
||||
}
|
||||
|
||||
$cookieLogin = $user->get('cookieLogin');
|
||||
|
||||
// Check if the user logged in with a cookie
|
||||
if (!empty($cookieLogin))
|
||||
{
|
||||
// If so, the user must login to edit the password and other data.
|
||||
$app->enqueueMessage(JText::_('JGLOBAL_REMEMBER_MUST_LOGIN'), 'message');
|
||||
$this->setRedirect(JRoute::_('index.php?option=com_users&view=login', false));
|
||||
|
||||
return false;
|
||||
}
|
||||
|
||||
// Set the user id for the user to edit in the session.
|
||||
$app->setUserState('com_users.edit.profile.id', $userId);
|
||||
|
||||
// Get the model.
|
||||
$model = $this->getModel('Profile', 'UsersModel');
|
||||
|
||||
// Check out the user.
|
||||
if ($userId)
|
||||
{
|
||||
$model->checkout($userId);
|
||||
}
|
||||
|
||||
// Check in the previous user.
|
||||
if ($previousId)
|
||||
{
|
||||
$model->checkin($previousId);
|
||||
}
|
||||
|
||||
// Redirect to the edit screen.
|
||||
$this->setRedirect(JRoute::_('index.php?option=com_users&view=profile&layout=edit', false));
|
||||
|
||||
return true;
|
||||
}
|
||||
|
||||
/**
|
||||
* Method to save a user's profile data.
|
||||
*
|
||||
* @return void
|
||||
*
|
||||
* @since 1.6
|
||||
*/
|
||||
public function save()
|
||||
{
|
||||
// Check for request forgeries.
|
||||
$this->checkToken();
|
||||
|
||||
$app = JFactory::getApplication();
|
||||
$model = $this->getModel('Profile', 'UsersModel');
|
||||
$user = JFactory::getUser();
|
||||
$userId = (int) $user->get('id');
|
||||
|
||||
// Get the user data.
|
||||
$requestData = $app->input->post->get('jform', array(), 'array');
|
||||
|
||||
// Force the ID to this user.
|
||||
$requestData['id'] = $userId;
|
||||
|
||||
// Validate the posted data.
|
||||
$form = $model->getForm();
|
||||
|
||||
if (!$form)
|
||||
{
|
||||
JError::raiseError(500, $model->getError());
|
||||
|
||||
return false;
|
||||
}
|
||||
|
||||
// Send an object which can be modified through the plugin event
|
||||
$objData = (object) $requestData;
|
||||
$app->triggerEvent(
|
||||
'onContentNormaliseRequestData',
|
||||
array('com_users.user', $objData, $form)
|
||||
);
|
||||
$requestData = (array) $objData;
|
||||
|
||||
// Validate the posted data.
|
||||
$data = $model->validate($form, $requestData);
|
||||
|
||||
// Check for errors.
|
||||
if ($data === false)
|
||||
{
|
||||
// Get the validation messages.
|
||||
$errors = $model->getErrors();
|
||||
|
||||
// Push up to three validation messages out to the user.
|
||||
for ($i = 0, $n = count($errors); $i < $n && $i < 3; $i++)
|
||||
{
|
||||
if ($errors[$i] instanceof Exception)
|
||||
{
|
||||
$app->enqueueMessage($errors[$i]->getMessage(), 'warning');
|
||||
}
|
||||
else
|
||||
{
|
||||
$app->enqueueMessage($errors[$i], 'warning');
|
||||
}
|
||||
}
|
||||
|
||||
// Unset the passwords.
|
||||
unset($requestData['password1'], $requestData['password2']);
|
||||
|
||||
// Save the data in the session.
|
||||
$app->setUserState('com_users.edit.profile.data', $requestData);
|
||||
|
||||
// Redirect back to the edit screen.
|
||||
$userId = (int) $app->getUserState('com_users.edit.profile.id');
|
||||
$this->setRedirect(JRoute::_('index.php?option=com_users&view=profile&layout=edit&user_id=' . $userId, false));
|
||||
|
||||
return false;
|
||||
}
|
||||
|
||||
// Attempt to save the data.
|
||||
$return = $model->save($data);
|
||||
|
||||
// Check for errors.
|
||||
if ($return === false)
|
||||
{
|
||||
// Save the data in the session.
|
||||
$app->setUserState('com_users.edit.profile.data', $data);
|
||||
|
||||
// Redirect back to the edit screen.
|
||||
$userId = (int) $app->getUserState('com_users.edit.profile.id');
|
||||
$this->setMessage(JText::sprintf('COM_USERS_PROFILE_SAVE_FAILED', $model->getError()), 'warning');
|
||||
$this->setRedirect(JRoute::_('index.php?option=com_users&view=profile&layout=edit&user_id=' . $userId, false));
|
||||
|
||||
return false;
|
||||
}
|
||||
|
||||
// Redirect the user and adjust session state based on the chosen task.
|
||||
switch ($this->getTask())
|
||||
{
|
||||
case 'apply':
|
||||
// Check out the profile.
|
||||
$app->setUserState('com_users.edit.profile.id', $return);
|
||||
$model->checkout($return);
|
||||
|
||||
// Redirect back to the edit screen.
|
||||
$this->setMessage(JText::_('COM_USERS_PROFILE_SAVE_SUCCESS'));
|
||||
|
||||
$redirect = $app->getUserState('com_users.edit.profile.redirect');
|
||||
|
||||
// Don't redirect to an external URL.
|
||||
if (!JUri::isInternal($redirect))
|
||||
{
|
||||
$redirect = null;
|
||||
}
|
||||
|
||||
if (!$redirect)
|
||||
{
|
||||
$redirect = 'index.php?option=com_users&view=profile&layout=edit&hidemainmenu=1';
|
||||
}
|
||||
|
||||
$this->setRedirect(JRoute::_($redirect, false));
|
||||
break;
|
||||
|
||||
default:
|
||||
// Check in the profile.
|
||||
$userId = (int) $app->getUserState('com_users.edit.profile.id');
|
||||
|
||||
if ($userId)
|
||||
{
|
||||
$model->checkin($userId);
|
||||
}
|
||||
|
||||
// Clear the profile id from the session.
|
||||
$app->setUserState('com_users.edit.profile.id', null);
|
||||
|
||||
$redirect = $app->getUserState('com_users.edit.profile.redirect');
|
||||
|
||||
// Don't redirect to an external URL.
|
||||
if (!JUri::isInternal($redirect))
|
||||
{
|
||||
$redirect = null;
|
||||
}
|
||||
|
||||
if (!$redirect)
|
||||
{
|
||||
$redirect = 'index.php?option=com_users&view=profile&user_id=' . $return;
|
||||
}
|
||||
|
||||
// Redirect to the list screen.
|
||||
$this->setMessage(JText::_('COM_USERS_PROFILE_SAVE_SUCCESS'));
|
||||
$this->setRedirect(JRoute::_($redirect, false));
|
||||
break;
|
||||
}
|
||||
|
||||
// Flush the data from the session.
|
||||
$app->setUserState('com_users.edit.profile.data', null);
|
||||
}
|
||||
|
||||
/**
|
||||
* Function that allows child controller access to model data after the data has been saved.
|
||||
*
|
||||
* @param JModelLegacy $model The data model object.
|
||||
* @param array $validData The validated data.
|
||||
*
|
||||
* @return void
|
||||
*
|
||||
* @since 3.1
|
||||
*/
|
||||
protected function postSaveHook(JModelLegacy $model, $validData = array())
|
||||
{
|
||||
$item = $model->getData();
|
||||
$tags = $validData['tags'];
|
||||
|
||||
if ($tags)
|
||||
{
|
||||
$item->tags = new JHelperTags;
|
||||
$item->tags->getTagIds($item->id, 'com_users.user');
|
||||
$item->metadata['tags'] = $item->tags;
|
||||
}
|
||||
}
|
||||
}
|
||||
@ -0,0 +1,15 @@
|
||||
{
|
||||
"finding_ref": "7258",
|
||||
"log_excerpt": "[quarantine] www.archlinexp.eu:components/com_users/controllers/profile.php -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/components/com_users/controllers/profile.php)",
|
||||
"original_sha256": "0cef6b3e5fc0304afdb0005711b02d9a39d01fee0ce14903d4312f31a2fa540b",
|
||||
"original_stat": {
|
||||
"gid": 30037,
|
||||
"mtime": 1533967367,
|
||||
"size": 6630,
|
||||
"uid": 12425
|
||||
},
|
||||
"rel_path": "components/com_users/controllers/profile.php",
|
||||
"result": "quarantined",
|
||||
"timestamp": "20260718T160204Z",
|
||||
"vhost": "www.archlinexp.eu"
|
||||
}
|
||||
@ -0,0 +1,53 @@
|
||||
<?php
|
||||
/**
|
||||
* @package Joomla.Site
|
||||
* @subpackage com_users
|
||||
*
|
||||
* @copyright Copyright (C) 2005 - 2018 Open Source Matters, Inc. All rights reserved.
|
||||
* @license GNU General Public License version 2 or later; see LICENSE.txt
|
||||
*/
|
||||
|
||||
defined('_JEXEC') or die;
|
||||
|
||||
/**
|
||||
* Profile controller class for Users.
|
||||
*
|
||||
* @since 3.5
|
||||
*/
|
||||
class UsersControllerProfile_Base_Json extends JControllerLegacy
|
||||
{
|
||||
/**
|
||||
* Returns the updated options for help site selector
|
||||
*
|
||||
* @return void
|
||||
*
|
||||
* @since 3.5
|
||||
* @throws Exception
|
||||
*/
|
||||
public function gethelpsites()
|
||||
{
|
||||
jimport('joomla.filesystem.file');
|
||||
|
||||
// Set FTP credentials, if given
|
||||
JClientHelper::setCredentialsFromRequest('ftp');
|
||||
|
||||
if (($data = file_get_contents('https://update.joomla.org/helpsites/helpsites.xml')) === false)
|
||||
{
|
||||
throw new Exception(JText::_('COM_CONFIG_ERROR_HELPREFRESH_FETCH'), 500);
|
||||
}
|
||||
elseif (!JFile::write(JPATH_ADMINISTRATOR . '/help/helpsites.xml', $data))
|
||||
{
|
||||
throw new Exception(JText::_('COM_CONFIG_ERROR_HELPREFRESH_ERROR_STORE'), 500);
|
||||
}
|
||||
|
||||
$options = array_merge(
|
||||
array(
|
||||
JHtml::_('select.option', '', JText::_('JOPTION_USE_DEFAULT'))
|
||||
),
|
||||
JHelp::createSiteList(JPATH_ADMINISTRATOR . '/help/helpsites.xml')
|
||||
);
|
||||
|
||||
echo json_encode($options);
|
||||
JFactory::getApplication()->close();
|
||||
}
|
||||
}
|
||||
@ -0,0 +1,15 @@
|
||||
{
|
||||
"finding_ref": "7259",
|
||||
"log_excerpt": "[quarantine] www.archlinexp.eu:components/com_users/controllers/profile_base_json.php -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/components/com_users/controllers/profile_base_json.php)",
|
||||
"original_sha256": "11ec9184dddb0f201b18ec05c6a279f1d4b387813b80ed01dfe5040e00c93d4a",
|
||||
"original_stat": {
|
||||
"gid": 30037,
|
||||
"mtime": 1533967367,
|
||||
"size": 1301,
|
||||
"uid": 12425
|
||||
},
|
||||
"rel_path": "components/com_users/controllers/profile_base_json.php",
|
||||
"result": "quarantined",
|
||||
"timestamp": "20260718T160204Z",
|
||||
"vhost": "www.archlinexp.eu"
|
||||
}
|
||||
@ -0,0 +1,59 @@
|
||||
<?php
|
||||
/**
|
||||
* @package Joomla.Site
|
||||
* @subpackage com_users
|
||||
*
|
||||
* @copyright Copyright (C) 2005 - 2018 Open Source Matters, Inc. All rights reserved.
|
||||
* @license GNU General Public License version 2 or later; see LICENSE.txt
|
||||
*/
|
||||
|
||||
defined('_JEXEC') or die;
|
||||
|
||||
JLoader::register('UsersController', JPATH_COMPONENT . '/controller.php');
|
||||
|
||||
/**
|
||||
* Reset controller class for Users.
|
||||
*
|
||||
* @since 1.6
|
||||
*/
|
||||
class UsersControllerRemind extends UsersController
|
||||
{
|
||||
/**
|
||||
* Method to request a username reminder.
|
||||
*
|
||||
* @return boolean
|
||||
*
|
||||
* @since 1.6
|
||||
*/
|
||||
public function remind()
|
||||
{
|
||||
// Check the request token.
|
||||
$this->checkToken('post');
|
||||
|
||||
$model = $this->getModel('Remind', 'UsersModel');
|
||||
$data = $this->input->post->get('jform', array(), 'array');
|
||||
|
||||
// Submit the password reset request.
|
||||
$return = $model->processRemindRequest($data);
|
||||
|
||||
// Check for a hard error.
|
||||
if ($return == false)
|
||||
{
|
||||
// The request failed.
|
||||
// Go back to the request form.
|
||||
$message = JText::sprintf('COM_USERS_REMIND_REQUEST_FAILED', $model->getError());
|
||||
$this->setRedirect(JRoute::_('index.php?option=com_users&view=remind', false), $message, 'notice');
|
||||
|
||||
return false;
|
||||
}
|
||||
else
|
||||
{
|
||||
// The request succeeded.
|
||||
// Proceed to step two.
|
||||
$message = JText::_('COM_USERS_REMIND_REQUEST_SUCCESS');
|
||||
$this->setRedirect(JRoute::_('index.php?option=com_users&view=login', false), $message);
|
||||
|
||||
return true;
|
||||
}
|
||||
}
|
||||
}
|
||||
@ -0,0 +1,15 @@
|
||||
{
|
||||
"finding_ref": "7255",
|
||||
"log_excerpt": "[quarantine] www.archlinexp.eu:components/com_users/controllers/remind.php -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/components/com_users/controllers/remind.php)",
|
||||
"original_sha256": "a6ef6d7b60043fa180e39c8efce1dcff804c8c2bbfa11d4e5e4d2ca36601972d",
|
||||
"original_stat": {
|
||||
"gid": 30037,
|
||||
"mtime": 1533967367,
|
||||
"size": 1427,
|
||||
"uid": 12425
|
||||
},
|
||||
"rel_path": "components/com_users/controllers/remind.php",
|
||||
"result": "quarantined",
|
||||
"timestamp": "20260718T160204Z",
|
||||
"vhost": "www.archlinexp.eu"
|
||||
}
|
||||
@ -0,0 +1,190 @@
|
||||
<?php
|
||||
/**
|
||||
* @package Joomla.Site
|
||||
* @subpackage com_users
|
||||
*
|
||||
* @copyright Copyright (C) 2005 - 2018 Open Source Matters, Inc. All rights reserved.
|
||||
* @license GNU General Public License version 2 or later; see LICENSE.txt
|
||||
*/
|
||||
|
||||
defined('_JEXEC') or die;
|
||||
|
||||
JLoader::register('UsersController', JPATH_COMPONENT . '/controller.php');
|
||||
|
||||
/**
|
||||
* Reset controller class for Users.
|
||||
*
|
||||
* @since 1.6
|
||||
*/
|
||||
class UsersControllerReset extends UsersController
|
||||
{
|
||||
/**
|
||||
* Method to request a password reset.
|
||||
*
|
||||
* @return boolean
|
||||
*
|
||||
* @since 1.6
|
||||
*/
|
||||
public function request()
|
||||
{
|
||||
// Check the request token.
|
||||
$this->checkToken('post');
|
||||
|
||||
$app = JFactory::getApplication();
|
||||
$model = $this->getModel('Reset', 'UsersModel');
|
||||
$data = $this->input->post->get('jform', array(), 'array');
|
||||
|
||||
// Submit the password reset request.
|
||||
$return = $model->processResetRequest($data);
|
||||
|
||||
// Check for a hard error.
|
||||
if ($return instanceof Exception)
|
||||
{
|
||||
// Get the error message to display.
|
||||
if ($app->get('error_reporting'))
|
||||
{
|
||||
$message = $return->getMessage();
|
||||
}
|
||||
else
|
||||
{
|
||||
$message = JText::_('COM_USERS_RESET_REQUEST_ERROR');
|
||||
}
|
||||
|
||||
// Go back to the request form.
|
||||
$this->setRedirect(JRoute::_('index.php?option=com_users&view=reset', false), $message, 'error');
|
||||
|
||||
return false;
|
||||
}
|
||||
elseif ($return === false)
|
||||
{
|
||||
// The request failed.
|
||||
// Go back to the request form.
|
||||
$message = JText::sprintf('COM_USERS_RESET_REQUEST_FAILED', $model->getError());
|
||||
$this->setRedirect(JRoute::_('index.php?option=com_users&view=reset', false), $message, 'notice');
|
||||
|
||||
return false;
|
||||
}
|
||||
else
|
||||
{
|
||||
// The request succeeded.
|
||||
// Proceed to step two.
|
||||
$this->setRedirect(JRoute::_('index.php?option=com_users&view=reset&layout=confirm', false));
|
||||
|
||||
return true;
|
||||
}
|
||||
}
|
||||
|
||||
/**
|
||||
* Method to confirm the password request.
|
||||
*
|
||||
* @return boolean
|
||||
*
|
||||
* @access public
|
||||
* @since 1.6
|
||||
*/
|
||||
public function confirm()
|
||||
{
|
||||
// Check the request token.
|
||||
$this->checkToken('request');
|
||||
|
||||
$app = JFactory::getApplication();
|
||||
$model = $this->getModel('Reset', 'UsersModel');
|
||||
$data = $this->input->get('jform', array(), 'array');
|
||||
|
||||
// Confirm the password reset request.
|
||||
$return = $model->processResetConfirm($data);
|
||||
|
||||
// Check for a hard error.
|
||||
if ($return instanceof Exception)
|
||||
{
|
||||
// Get the error message to display.
|
||||
if ($app->get('error_reporting'))
|
||||
{
|
||||
$message = $return->getMessage();
|
||||
}
|
||||
else
|
||||
{
|
||||
$message = JText::_('COM_USERS_RESET_CONFIRM_ERROR');
|
||||
}
|
||||
|
||||
// Go back to the confirm form.
|
||||
$this->setRedirect(JRoute::_('index.php?option=com_users&view=reset&layout=confirm', false), $message, 'error');
|
||||
|
||||
return false;
|
||||
}
|
||||
elseif ($return === false)
|
||||
{
|
||||
// Confirm failed.
|
||||
// Go back to the confirm form.
|
||||
$message = JText::sprintf('COM_USERS_RESET_CONFIRM_FAILED', $model->getError());
|
||||
$this->setRedirect(JRoute::_('index.php?option=com_users&view=reset&layout=confirm', false), $message, 'notice');
|
||||
|
||||
return false;
|
||||
}
|
||||
else
|
||||
{
|
||||
// Confirm succeeded.
|
||||
// Proceed to step three.
|
||||
$this->setRedirect(JRoute::_('index.php?option=com_users&view=reset&layout=complete', false));
|
||||
|
||||
return true;
|
||||
}
|
||||
}
|
||||
|
||||
/**
|
||||
* Method to complete the password reset process.
|
||||
*
|
||||
* @return boolean
|
||||
*
|
||||
* @since 1.6
|
||||
*/
|
||||
public function complete()
|
||||
{
|
||||
// Check for request forgeries
|
||||
$this->checkToken('post');
|
||||
|
||||
$app = JFactory::getApplication();
|
||||
$model = $this->getModel('Reset', 'UsersModel');
|
||||
$data = $this->input->post->get('jform', array(), 'array');
|
||||
|
||||
// Complete the password reset request.
|
||||
$return = $model->processResetComplete($data);
|
||||
|
||||
// Check for a hard error.
|
||||
if ($return instanceof Exception)
|
||||
{
|
||||
// Get the error message to display.
|
||||
if ($app->get('error_reporting'))
|
||||
{
|
||||
$message = $return->getMessage();
|
||||
}
|
||||
else
|
||||
{
|
||||
$message = JText::_('COM_USERS_RESET_COMPLETE_ERROR');
|
||||
}
|
||||
|
||||
// Go back to the complete form.
|
||||
$this->setRedirect(JRoute::_('index.php?option=com_users&view=reset&layout=complete', false), $message, 'error');
|
||||
|
||||
return false;
|
||||
}
|
||||
elseif ($return === false)
|
||||
{
|
||||
// Complete failed.
|
||||
// Go back to the complete form.
|
||||
$message = JText::sprintf('COM_USERS_RESET_COMPLETE_FAILED', $model->getError());
|
||||
$this->setRedirect(JRoute::_('index.php?option=com_users&view=reset&layout=complete', false), $message, 'notice');
|
||||
|
||||
return false;
|
||||
}
|
||||
else
|
||||
{
|
||||
// Complete succeeded.
|
||||
// Proceed to the login form.
|
||||
$message = JText::_('COM_USERS_RESET_COMPLETE_SUCCESS');
|
||||
$this->setRedirect(JRoute::_('index.php?option=com_users&view=login', false), $message);
|
||||
|
||||
return true;
|
||||
}
|
||||
}
|
||||
}
|
||||
@ -0,0 +1,15 @@
|
||||
{
|
||||
"finding_ref": "7256",
|
||||
"log_excerpt": "[quarantine] www.archlinexp.eu:components/com_users/controllers/reset.php -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/components/com_users/controllers/reset.php)",
|
||||
"original_sha256": "224404ff37d78b3baf18f77b89e51e7599304b44b51fe6e4bf1ff9abf354ac0c",
|
||||
"original_stat": {
|
||||
"gid": 30037,
|
||||
"mtime": 1533967367,
|
||||
"size": 4662,
|
||||
"uid": 12425
|
||||
},
|
||||
"rel_path": "components/com_users/controllers/reset.php",
|
||||
"result": "quarantined",
|
||||
"timestamp": "20260718T160204Z",
|
||||
"vhost": "www.archlinexp.eu"
|
||||
}
|
||||
@ -0,0 +1,374 @@
|
||||
<?php
|
||||
/**
|
||||
* @package Joomla.Site
|
||||
* @subpackage com_users
|
||||
*
|
||||
* @copyright Copyright (C) 2005 - 2018 Open Source Matters, Inc. All rights reserved.
|
||||
* @license GNU General Public License version 2 or later; see LICENSE.txt
|
||||
*/
|
||||
|
||||
defined('_JEXEC') or die;
|
||||
|
||||
JLoader::register('UsersController', JPATH_COMPONENT . '/controller.php');
|
||||
|
||||
/**
|
||||
* Registration controller class for Users.
|
||||
*
|
||||
* @since 1.6
|
||||
*/
|
||||
class UsersControllerUser extends UsersController
|
||||
{
|
||||
/**
|
||||
* Method to log in a user.
|
||||
*
|
||||
* @return void
|
||||
*
|
||||
* @since 1.6
|
||||
*/
|
||||
public function login()
|
||||
{
|
||||
$this->checkToken('post');
|
||||
|
||||
$app = JFactory::getApplication();
|
||||
$input = $app->input->getInputForRequestMethod();
|
||||
|
||||
// Populate the data array:
|
||||
$data = array();
|
||||
|
||||
$data['return'] = base64_decode($input->get('return', '', 'BASE64'));
|
||||
$data['username'] = $input->get('username', '', 'USERNAME');
|
||||
$data['password'] = $input->get('password', '', 'RAW');
|
||||
$data['secretkey'] = $input->get('secretkey', '', 'RAW');
|
||||
|
||||
// Check for a simple menu item id
|
||||
if (is_numeric($data['return']))
|
||||
{
|
||||
if (JLanguageMultilang::isEnabled())
|
||||
{
|
||||
$db = JFactory::getDbo();
|
||||
$query = $db->getQuery(true)
|
||||
->select('language')
|
||||
->from($db->quoteName('#__menu'))
|
||||
->where('client_id = 0')
|
||||
->where('id =' . $data['return']);
|
||||
|
||||
$db->setQuery($query);
|
||||
|
||||
try
|
||||
{
|
||||
$language = $db->loadResult();
|
||||
}
|
||||
catch (RuntimeException $e)
|
||||
{
|
||||
return;
|
||||
}
|
||||
|
||||
if ($language !== '*')
|
||||
{
|
||||
$lang = '&lang=' . $language;
|
||||
}
|
||||
else
|
||||
{
|
||||
$lang = '';
|
||||
}
|
||||
}
|
||||
else
|
||||
{
|
||||
$lang = '';
|
||||
}
|
||||
|
||||
$data['return'] = 'index.php?Itemid=' . $data['return'] . $lang;
|
||||
}
|
||||
else
|
||||
{
|
||||
// Don't redirect to an external URL.
|
||||
if (!JUri::isInternal($data['return']))
|
||||
{
|
||||
$data['return'] = '';
|
||||
}
|
||||
}
|
||||
|
||||
// Set the return URL if empty.
|
||||
if (empty($data['return']))
|
||||
{
|
||||
$data['return'] = 'index.php?option=com_users&view=profile';
|
||||
}
|
||||
|
||||
// Set the return URL in the user state to allow modification by plugins
|
||||
$app->setUserState('users.login.form.return', $data['return']);
|
||||
|
||||
// Get the log in options.
|
||||
$options = array();
|
||||
$options['remember'] = $this->input->getBool('remember', false);
|
||||
$options['return'] = $data['return'];
|
||||
|
||||
// Get the log in credentials.
|
||||
$credentials = array();
|
||||
$credentials['username'] = $data['username'];
|
||||
$credentials['password'] = $data['password'];
|
||||
$credentials['secretkey'] = $data['secretkey'];
|
||||
|
||||
// Perform the log in.
|
||||
if (true !== $app->login($credentials, $options))
|
||||
{
|
||||
// Login failed !
|
||||
// Clear user name, password and secret key before sending the login form back to the user.
|
||||
$data['remember'] = (int) $options['remember'];
|
||||
$data['username'] = '';
|
||||
$data['password'] = '';
|
||||
$data['secretkey'] = '';
|
||||
$app->setUserState('users.login.form.data', $data);
|
||||
$uri = JFactory::getURI();
|
||||
$url = $uri->toString();
|
||||
$app->redirect(JRoute::_($url, false));
|
||||
//$app->redirect(JRoute::_('index.php?option=com_users&view=login', false)); //Eredeti
|
||||
}
|
||||
|
||||
// Success
|
||||
if ($options['remember'] == true)
|
||||
{
|
||||
$app->setUserState('rememberLogin', true);
|
||||
}
|
||||
|
||||
$app->setUserState('users.login.form.data', array());
|
||||
$app->redirect(JRoute::_($app->getUserState('users.login.form.return'), false));
|
||||
}
|
||||
|
||||
/**
|
||||
* Method to log out a user.
|
||||
*
|
||||
* @return void
|
||||
*
|
||||
* @since 1.6
|
||||
*/
|
||||
public function logout()
|
||||
{
|
||||
$this->checkToken('request');
|
||||
|
||||
$app = JFactory::getApplication();
|
||||
|
||||
// Prepare the logout options.
|
||||
$options = array(
|
||||
'clientid' => $app->get('shared_session', '0') ? null : 0,
|
||||
);
|
||||
|
||||
// Perform the log out.
|
||||
$error = $app->logout(null, $options);
|
||||
$input = $app->input->getInputForRequestMethod();
|
||||
|
||||
// Check if the log out succeeded.
|
||||
if ($error instanceof Exception)
|
||||
{
|
||||
$app->redirect(JRoute::_('index.php?option=com_users&view=login', false));
|
||||
}
|
||||
|
||||
// Get the return URL from the request and validate that it is internal.
|
||||
$return = $input->get('return', '', 'BASE64');
|
||||
$return = base64_decode($return);
|
||||
|
||||
// Check for a simple menu item id
|
||||
if (is_numeric($return))
|
||||
{
|
||||
if (JLanguageMultilang::isEnabled())
|
||||
{
|
||||
$db = JFactory::getDbo();
|
||||
$query = $db->getQuery(true)
|
||||
->select('language')
|
||||
->from($db->quoteName('#__menu'))
|
||||
->where('client_id = 0')
|
||||
->where('id =' . $return);
|
||||
|
||||
$db->setQuery($query);
|
||||
|
||||
try
|
||||
{
|
||||
$language = $db->loadResult();
|
||||
}
|
||||
catch (RuntimeException $e)
|
||||
{
|
||||
return;
|
||||
}
|
||||
|
||||
if ($language !== '*')
|
||||
{
|
||||
$lang = '&lang=' . $language;
|
||||
}
|
||||
else
|
||||
{
|
||||
$lang = '';
|
||||
}
|
||||
}
|
||||
else
|
||||
{
|
||||
$lang = '';
|
||||
}
|
||||
|
||||
$return = 'index.php?Itemid=' . $return . $lang;
|
||||
}
|
||||
else
|
||||
{
|
||||
// Don't redirect to an external URL.
|
||||
if (!JUri::isInternal($return))
|
||||
{
|
||||
$return = '';
|
||||
}
|
||||
}
|
||||
|
||||
// In case redirect url is not set, redirect user to homepage
|
||||
if (empty($return))
|
||||
{
|
||||
$return = JUri::root();
|
||||
}
|
||||
|
||||
// Redirect the user.
|
||||
$app->redirect(JRoute::_($return, false));
|
||||
}
|
||||
|
||||
/**
|
||||
* Method to logout directly and redirect to page.
|
||||
*
|
||||
* @return void
|
||||
*
|
||||
* @since 3.5
|
||||
*/
|
||||
public function menulogout()
|
||||
{
|
||||
// Get the ItemID of the page to redirect after logout
|
||||
$app = JFactory::getApplication();
|
||||
$itemid = $app->getMenu()->getActive()->params->get('logout');
|
||||
|
||||
// Get the language of the page when multilang is on
|
||||
if (JLanguageMultilang::isEnabled())
|
||||
{
|
||||
if ($itemid)
|
||||
{
|
||||
$db = JFactory::getDbo();
|
||||
$query = $db->getQuery(true)
|
||||
->select('language')
|
||||
->from($db->quoteName('#__menu'))
|
||||
->where('client_id = 0')
|
||||
->where('id =' . $itemid);
|
||||
|
||||
$db->setQuery($query);
|
||||
|
||||
try
|
||||
{
|
||||
$language = $db->loadResult();
|
||||
}
|
||||
catch (RuntimeException $e)
|
||||
{
|
||||
return;
|
||||
}
|
||||
|
||||
if ($language !== '*')
|
||||
{
|
||||
$lang = '&lang=' . $language;
|
||||
}
|
||||
else
|
||||
{
|
||||
$lang = '';
|
||||
}
|
||||
|
||||
// URL to redirect after logout
|
||||
$url = 'index.php?Itemid=' . $itemid . $lang;
|
||||
}
|
||||
else
|
||||
{
|
||||
// Logout is set to default. Get the home page ItemID
|
||||
$lang_code = $app->input->cookie->getString(JApplicationHelper::getHash('language'));
|
||||
$item = $app->getMenu()->getDefault($lang_code);
|
||||
$itemid = $item->id;
|
||||
|
||||
// Redirect to Home page after logout
|
||||
$url = 'index.php?Itemid=' . $itemid;
|
||||
}
|
||||
}
|
||||
else
|
||||
{
|
||||
// URL to redirect after logout, default page if no ItemID is set
|
||||
$url = $itemid ? 'index.php?Itemid=' . $itemid : JUri::root();
|
||||
}
|
||||
|
||||
// Logout and redirect
|
||||
$this->setRedirect('index.php?option=com_users&task=user.logout&' . JSession::getFormToken() . '=1&return=' . base64_encode($url));
|
||||
}
|
||||
|
||||
/**
|
||||
* Method to request a username reminder.
|
||||
*
|
||||
* @return boolean
|
||||
*
|
||||
* @since 1.6
|
||||
*/
|
||||
public function remind()
|
||||
{
|
||||
// Check the request token.
|
||||
$this->checkToken('post');
|
||||
|
||||
$app = JFactory::getApplication();
|
||||
$model = $this->getModel('User', 'UsersModel');
|
||||
$data = $this->input->post->get('jform', array(), 'array');
|
||||
|
||||
// Submit the username remind request.
|
||||
$return = $model->processRemindRequest($data);
|
||||
|
||||
// Check for a hard error.
|
||||
if ($return instanceof Exception)
|
||||
{
|
||||
// Get the error message to display.
|
||||
$message = $app->get('error_reporting')
|
||||
? $return->getMessage()
|
||||
: JText::_('COM_USERS_REMIND_REQUEST_ERROR');
|
||||
|
||||
// Get the route to the next page.
|
||||
$itemid = UsersHelperRoute::getRemindRoute();
|
||||
$itemid = $itemid !== null ? '&Itemid=' . $itemid : '';
|
||||
$route = 'index.php?option=com_users&view=remind' . $itemid;
|
||||
|
||||
// Go back to the complete form.
|
||||
$this->setRedirect(JRoute::_($route, false), $message, 'error');
|
||||
|
||||
return false;
|
||||
}
|
||||
|
||||
if ($return === false)
|
||||
{
|
||||
// Complete failed.
|
||||
// Get the route to the next page.
|
||||
$itemid = UsersHelperRoute::getRemindRoute();
|
||||
$itemid = $itemid !== null ? '&Itemid=' . $itemid : '';
|
||||
$route = 'index.php?option=com_users&view=remind' . $itemid;
|
||||
|
||||
// Go back to the complete form.
|
||||
$message = JText::sprintf('COM_USERS_REMIND_REQUEST_FAILED', $model->getError());
|
||||
$this->setRedirect(JRoute::_($route, false), $message, 'notice');
|
||||
|
||||
return false;
|
||||
}
|
||||
|
||||
// Complete succeeded.
|
||||
// Get the route to the next page.
|
||||
$itemid = UsersHelperRoute::getLoginRoute();
|
||||
$itemid = $itemid !== null ? '&Itemid=' . $itemid : '';
|
||||
$route = 'index.php?option=com_users&view=login' . $itemid;
|
||||
|
||||
// Proceed to the login form.
|
||||
$message = JText::_('COM_USERS_REMIND_REQUEST_SUCCESS');
|
||||
$this->setRedirect(JRoute::_($route, false), $message);
|
||||
|
||||
return true;
|
||||
}
|
||||
|
||||
/**
|
||||
* Method to resend a user.
|
||||
*
|
||||
* @return void
|
||||
*
|
||||
* @since 1.6
|
||||
*/
|
||||
public function resend()
|
||||
{
|
||||
// Check for request forgeries
|
||||
// $this->checkToken('post');
|
||||
}
|
||||
}
|
||||
@ -0,0 +1,15 @@
|
||||
{
|
||||
"finding_ref": "7254",
|
||||
"log_excerpt": "[quarantine] www.archlinexp.eu:components/com_users/controllers/user.php -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/components/com_users/controllers/user.php)",
|
||||
"original_sha256": "d7472a9cb222592b7799229831d00ed6e728d082fd5ed5be616404edb8ad275c",
|
||||
"original_stat": {
|
||||
"gid": 30037,
|
||||
"mtime": 1557908559,
|
||||
"size": 8730,
|
||||
"uid": 12425
|
||||
},
|
||||
"rel_path": "components/com_users/controllers/user.php",
|
||||
"result": "quarantined",
|
||||
"timestamp": "20260718T160204Z",
|
||||
"vhost": "www.archlinexp.eu"
|
||||
}
|
||||
@ -0,0 +1,251 @@
|
||||
<?php
|
||||
/**
|
||||
* @package Joomla.Site
|
||||
* @subpackage com_users
|
||||
*
|
||||
* @copyright Copyright (C) 2005 - 2018 Open Source Matters, Inc. All rights reserved.
|
||||
* @license GNU General Public License version 2 or later; see LICENSE.txt
|
||||
*/
|
||||
|
||||
defined('_JEXEC') or die;
|
||||
|
||||
/**
|
||||
* Users Html Helper
|
||||
*
|
||||
* @since 1.6
|
||||
*/
|
||||
abstract class JHtmlUsers
|
||||
{
|
||||
/**
|
||||
* Get the sanitized value
|
||||
*
|
||||
* @param mixed $value Value of the field
|
||||
*
|
||||
* @return mixed String/void
|
||||
*
|
||||
* @since 1.6
|
||||
*/
|
||||
public static function value($value)
|
||||
{
|
||||
if (is_string($value))
|
||||
{
|
||||
$value = trim($value);
|
||||
}
|
||||
|
||||
if (empty($value))
|
||||
{
|
||||
return JText::_('COM_USERS_PROFILE_VALUE_NOT_FOUND');
|
||||
}
|
||||
|
||||
elseif (!is_array($value))
|
||||
{
|
||||
return htmlspecialchars($value, ENT_COMPAT, 'UTF-8');
|
||||
}
|
||||
}
|
||||
|
||||
/**
|
||||
* Get the space symbol
|
||||
*
|
||||
* @param mixed $value Value of the field
|
||||
*
|
||||
* @return string
|
||||
*
|
||||
* @since 1.6
|
||||
*/
|
||||
public static function spacer($value)
|
||||
{
|
||||
return '';
|
||||
}
|
||||
|
||||
/**
|
||||
* Get the sanitized helpsite link
|
||||
*
|
||||
* @param mixed $value Value of the field
|
||||
*
|
||||
* @return mixed String/void
|
||||
*
|
||||
* @since 1.6
|
||||
*/
|
||||
public static function helpsite($value)
|
||||
{
|
||||
if (empty($value))
|
||||
{
|
||||
return static::value($value);
|
||||
}
|
||||
|
||||
$text = $value;
|
||||
|
||||
if ($xml = simplexml_load_file(JPATH_ADMINISTRATOR . '/help/helpsites.xml'))
|
||||
{
|
||||
foreach ($xml->sites->site as $site)
|
||||
{
|
||||
if ((string) $site->attributes()->url == $value)
|
||||
{
|
||||
$text = (string) $site;
|
||||
break;
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
$value = htmlspecialchars($value, ENT_COMPAT, 'UTF-8');
|
||||
|
||||
if (strpos($value, 'http') === 0)
|
||||
{
|
||||
return '<a href="' . $value . '">' . $text . '</a>';
|
||||
}
|
||||
|
||||
return '<a href="http://' . $value . '">' . $text . '</a>';
|
||||
}
|
||||
|
||||
/**
|
||||
* Get the sanitized template style
|
||||
*
|
||||
* @param mixed $value Value of the field
|
||||
*
|
||||
* @return mixed String/void
|
||||
*
|
||||
* @since 1.6
|
||||
*/
|
||||
public static function templatestyle($value)
|
||||
{
|
||||
if (empty($value))
|
||||
{
|
||||
return static::value($value);
|
||||
}
|
||||
else
|
||||
{
|
||||
$db = JFactory::getDbo();
|
||||
$query = $db->getQuery(true)
|
||||
->select('title')
|
||||
->from('#__template_styles')
|
||||
->where('id = ' . $db->quote($value));
|
||||
$db->setQuery($query);
|
||||
$title = $db->loadResult();
|
||||
|
||||
if ($title)
|
||||
{
|
||||
return htmlspecialchars($title, ENT_COMPAT, 'UTF-8');
|
||||
}
|
||||
else
|
||||
{
|
||||
return static::value('');
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
/**
|
||||
* Get the sanitized language
|
||||
*
|
||||
* @param mixed $value Value of the field
|
||||
*
|
||||
* @return mixed String/void
|
||||
*
|
||||
* @since 1.6
|
||||
*/
|
||||
public static function admin_language($value)
|
||||
{
|
||||
if (empty($value))
|
||||
{
|
||||
return static::value($value);
|
||||
}
|
||||
else
|
||||
{
|
||||
$file = JLanguageHelper::getLanguagePath(JPATH_ADMINISTRATOR, $value) . '/' . $value . '.xml';
|
||||
|
||||
$result = null;
|
||||
|
||||
if (is_file($file))
|
||||
{
|
||||
$result = JLanguageHelper::parseXMLLanguageFile($file);
|
||||
}
|
||||
|
||||
if ($result)
|
||||
{
|
||||
return htmlspecialchars($result['name'], ENT_COMPAT, 'UTF-8');
|
||||
}
|
||||
else
|
||||
{
|
||||
return static::value('');
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
/**
|
||||
* Get the sanitized language
|
||||
*
|
||||
* @param mixed $value Value of the field
|
||||
*
|
||||
* @return mixed String/void
|
||||
*
|
||||
* @since 1.6
|
||||
*/
|
||||
public static function language($value)
|
||||
{
|
||||
if (empty($value))
|
||||
{
|
||||
return static::value($value);
|
||||
}
|
||||
else
|
||||
{
|
||||
$file = JLanguageHelper::getLanguagePath(JPATH_SITE, $value) . '/' . $value . '.xml';
|
||||
|
||||
$result = null;
|
||||
|
||||
if (is_file($file))
|
||||
{
|
||||
$result = JLanguageHelper::parseXMLLanguageFile($file);
|
||||
}
|
||||
|
||||
if ($result)
|
||||
{
|
||||
return htmlspecialchars($result['name'], ENT_COMPAT, 'UTF-8');
|
||||
}
|
||||
else
|
||||
{
|
||||
return static::value('');
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
/**
|
||||
* Get the sanitized editor name
|
||||
*
|
||||
* @param mixed $value Value of the field
|
||||
*
|
||||
* @return mixed String/void
|
||||
*
|
||||
* @since 1.6
|
||||
*/
|
||||
public static function editor($value)
|
||||
{
|
||||
if (empty($value))
|
||||
{
|
||||
return static::value($value);
|
||||
}
|
||||
else
|
||||
{
|
||||
$db = JFactory::getDbo();
|
||||
$lang = JFactory::getLanguage();
|
||||
$query = $db->getQuery(true)
|
||||
->select('name')
|
||||
->from('#__extensions')
|
||||
->where('element = ' . $db->quote($value))
|
||||
->where('folder = ' . $db->quote('editors'));
|
||||
$db->setQuery($query);
|
||||
$title = $db->loadResult();
|
||||
|
||||
if ($title)
|
||||
{
|
||||
$lang->load("plg_editors_$value.sys", JPATH_ADMINISTRATOR, null, false, true)
|
||||
|| $lang->load("plg_editors_$value.sys", JPATH_PLUGINS . '/editors/' . $value, null, false, true);
|
||||
$lang->load($title . '.sys');
|
||||
|
||||
return JText::_($title);
|
||||
}
|
||||
else
|
||||
{
|
||||
return static::value('');
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
@ -0,0 +1,15 @@
|
||||
{
|
||||
"finding_ref": "7283",
|
||||
"log_excerpt": "[quarantine] www.archlinexp.eu:components/com_users/helpers/html/users.php -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/components/com_users/helpers/html/users.php)",
|
||||
"original_sha256": "cb229ad16ba915a20aa22c49f2b5863cb4079cb5ce5fb3975b07b5caa161e786",
|
||||
"original_stat": {
|
||||
"gid": 30037,
|
||||
"mtime": 1533967367,
|
||||
"size": 4500,
|
||||
"uid": 12425
|
||||
},
|
||||
"rel_path": "components/com_users/helpers/html/users.php",
|
||||
"result": "quarantined",
|
||||
"timestamp": "20260718T160204Z",
|
||||
"vhost": "www.archlinexp.eu"
|
||||
}
|
||||
@ -0,0 +1,309 @@
|
||||
<?php
|
||||
/**
|
||||
* @package Joomla.Site
|
||||
* @subpackage com_users
|
||||
*
|
||||
* @copyright Copyright (C) 2005 - 2018 Open Source Matters, Inc. All rights reserved.
|
||||
* @license GNU General Public License version 2 or later; see LICENSE.txt
|
||||
*/
|
||||
|
||||
defined('_JEXEC') or die;
|
||||
|
||||
/**
|
||||
* Legacy routing rules class from com_users
|
||||
*
|
||||
* @since 3.6
|
||||
* @deprecated 4.0
|
||||
*/
|
||||
class UsersRouterRulesLegacy implements JComponentRouterRulesInterface
|
||||
{
|
||||
/**
|
||||
* Constructor for this legacy router
|
||||
*
|
||||
* @param JComponentRouterAdvanced $router The router this rule belongs to
|
||||
*
|
||||
* @since 3.6
|
||||
* @deprecated 4.0
|
||||
*/
|
||||
public function __construct($router)
|
||||
{
|
||||
$this->router = $router;
|
||||
}
|
||||
|
||||
/**
|
||||
* Preprocess the route for the com_users component
|
||||
*
|
||||
* @param array &$query An array of URL arguments
|
||||
*
|
||||
* @return void
|
||||
*
|
||||
* @since 3.6
|
||||
* @deprecated 4.0
|
||||
*/
|
||||
public function preprocess(&$query)
|
||||
{
|
||||
}
|
||||
|
||||
/**
|
||||
* Build the route for the com_users component
|
||||
*
|
||||
* @param array &$query An array of URL arguments
|
||||
* @param array &$segments The URL arguments to use to assemble the subsequent URL.
|
||||
*
|
||||
* @return void
|
||||
*
|
||||
* @since 3.6
|
||||
* @deprecated 4.0
|
||||
*/
|
||||
public function build(&$query, &$segments)
|
||||
{
|
||||
// Declare static variables.
|
||||
static $items;
|
||||
static $default;
|
||||
static $registration;
|
||||
static $profile;
|
||||
static $login;
|
||||
static $remind;
|
||||
static $resend;
|
||||
static $reset;
|
||||
|
||||
// Get the relevant menu items if not loaded.
|
||||
if (empty($items))
|
||||
{
|
||||
// Get all relevant menu items.
|
||||
$items = $this->router->menu->getItems('component', 'com_users');
|
||||
|
||||
// Build an array of serialized query strings to menu item id mappings.
|
||||
foreach ($items as $item)
|
||||
{
|
||||
if (empty($item->query['view']))
|
||||
{
|
||||
continue;
|
||||
}
|
||||
|
||||
// Check to see if we have found the resend menu item.
|
||||
if (empty($resend) && $item->query['view'] === 'resend')
|
||||
{
|
||||
$resend = $item->id;
|
||||
|
||||
continue;
|
||||
}
|
||||
|
||||
// Check to see if we have found the reset menu item.
|
||||
if (empty($reset) && $item->query['view'] === 'reset')
|
||||
{
|
||||
$reset = $item->id;
|
||||
|
||||
continue;
|
||||
}
|
||||
|
||||
// Check to see if we have found the remind menu item.
|
||||
if (empty($remind) && $item->query['view'] === 'remind')
|
||||
{
|
||||
$remind = $item->id;
|
||||
|
||||
continue;
|
||||
}
|
||||
|
||||
// Check to see if we have found the login menu item.
|
||||
if (empty($login) && $item->query['view'] === 'login')
|
||||
{
|
||||
$login = $item->id;
|
||||
|
||||
continue;
|
||||
}
|
||||
|
||||
// Check to see if we have found the registration menu item.
|
||||
if (empty($registration) && $item->query['view'] === 'registration')
|
||||
{
|
||||
$registration = $item->id;
|
||||
|
||||
continue;
|
||||
}
|
||||
|
||||
// Check to see if we have found the profile menu item.
|
||||
if (empty($profile) && $item->query['view'] === 'profile')
|
||||
{
|
||||
$profile = $item->id;
|
||||
}
|
||||
}
|
||||
|
||||
// Set the default menu item to use for com_users if possible.
|
||||
if ($profile)
|
||||
{
|
||||
$default = $profile;
|
||||
}
|
||||
elseif ($registration)
|
||||
{
|
||||
$default = $registration;
|
||||
}
|
||||
elseif ($login)
|
||||
{
|
||||
$default = $login;
|
||||
}
|
||||
}
|
||||
|
||||
if (!empty($query['view']))
|
||||
{
|
||||
switch ($query['view'])
|
||||
{
|
||||
case 'reset':
|
||||
if ($query['Itemid'] = $reset)
|
||||
{
|
||||
unset($query['view']);
|
||||
}
|
||||
else
|
||||
{
|
||||
$query['Itemid'] = $default;
|
||||
}
|
||||
break;
|
||||
|
||||
case 'resend':
|
||||
if ($query['Itemid'] = $resend)
|
||||
{
|
||||
unset($query['view']);
|
||||
}
|
||||
else
|
||||
{
|
||||
$query['Itemid'] = $default;
|
||||
}
|
||||
break;
|
||||
|
||||
case 'remind':
|
||||
if ($query['Itemid'] = $remind)
|
||||
{
|
||||
unset($query['view']);
|
||||
}
|
||||
else
|
||||
{
|
||||
$query['Itemid'] = $default;
|
||||
}
|
||||
break;
|
||||
|
||||
case 'login':
|
||||
if ($query['Itemid'] = $login)
|
||||
{
|
||||
unset($query['view']);
|
||||
}
|
||||
else
|
||||
{
|
||||
$query['Itemid'] = $default;
|
||||
}
|
||||
break;
|
||||
|
||||
case 'registration':
|
||||
if ($query['Itemid'] = $registration)
|
||||
{
|
||||
unset($query['view']);
|
||||
}
|
||||
else
|
||||
{
|
||||
$query['Itemid'] = $default;
|
||||
}
|
||||
break;
|
||||
|
||||
default:
|
||||
case 'profile':
|
||||
if (!empty($query['view']))
|
||||
{
|
||||
$segments[] = $query['view'];
|
||||
}
|
||||
|
||||
unset($query['view']);
|
||||
|
||||
if ($query['Itemid'] = $profile)
|
||||
{
|
||||
unset($query['view']);
|
||||
}
|
||||
else
|
||||
{
|
||||
$query['Itemid'] = $default;
|
||||
}
|
||||
|
||||
// Only append the user id if not "me".
|
||||
$user = JFactory::getUser();
|
||||
|
||||
if (!empty($query['user_id']) && ($query['user_id'] != $user->id))
|
||||
{
|
||||
$segments[] = $query['user_id'];
|
||||
}
|
||||
|
||||
unset($query['user_id']);
|
||||
|
||||
break;
|
||||
}
|
||||
}
|
||||
|
||||
$total = count($segments);
|
||||
|
||||
for ($i = 0; $i < $total; $i++)
|
||||
{
|
||||
$segments[$i] = str_replace(':', '-', $segments[$i]);
|
||||
}
|
||||
}
|
||||
|
||||
/**
|
||||
* Parse the segments of a URL.
|
||||
*
|
||||
* @param array &$segments The segments of the URL to parse.
|
||||
* @param array &$vars The URL attributes to be used by the application.
|
||||
*
|
||||
* @return void
|
||||
*
|
||||
* @since 3.6
|
||||
* @deprecated 4.0
|
||||
*/
|
||||
public function parse(&$segments, &$vars)
|
||||
{
|
||||
$total = count($segments);
|
||||
|
||||
for ($i = 0; $i < $total; $i++)
|
||||
{
|
||||
$segments[$i] = preg_replace('/-/', ':', $segments[$i], 1);
|
||||
}
|
||||
|
||||
// Only run routine if there are segments to parse.
|
||||
if (count($segments) < 1)
|
||||
{
|
||||
return;
|
||||
}
|
||||
|
||||
// Get the package from the route segments.
|
||||
$userId = array_pop($segments);
|
||||
|
||||
if (!is_numeric($userId))
|
||||
{
|
||||
$vars['view'] = 'profile';
|
||||
|
||||
return;
|
||||
}
|
||||
|
||||
if (is_numeric($userId))
|
||||
{
|
||||
$db = JFactory::getDbo();
|
||||
$query = $db->getQuery(true)
|
||||
->select($db->quoteName('id'))
|
||||
->from($db->quoteName('#__users'))
|
||||
->where($db->quoteName('id') . ' = ' . (int) $userId);
|
||||
$db->setQuery($query);
|
||||
$userId = $db->loadResult();
|
||||
}
|
||||
|
||||
// Set the package id if present.
|
||||
if ($userId)
|
||||
{
|
||||
// Set the package id.
|
||||
$vars['user_id'] = (int) $userId;
|
||||
|
||||
// Set the view to package if not already set.
|
||||
if (empty($vars['view']))
|
||||
{
|
||||
$vars['view'] = 'profile';
|
||||
}
|
||||
}
|
||||
else
|
||||
{
|
||||
JError::raiseError(404, JText::_('JGLOBAL_RESOURCE_NOT_FOUND'));
|
||||
}
|
||||
}
|
||||
}
|
||||
@ -0,0 +1,15 @@
|
||||
{
|
||||
"finding_ref": "7281",
|
||||
"log_excerpt": "[quarantine] www.archlinexp.eu:components/com_users/helpers/legacyrouter.php -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/components/com_users/helpers/legacyrouter.php)",
|
||||
"original_sha256": "e25f6683f53657c5f1f0f03e80126eb3acbc3b270dd26f3bcd8e16fc72f72343",
|
||||
"original_stat": {
|
||||
"gid": 30037,
|
||||
"mtime": 1533967367,
|
||||
"size": 6013,
|
||||
"uid": 12425
|
||||
},
|
||||
"rel_path": "components/com_users/helpers/legacyrouter.php",
|
||||
"result": "quarantined",
|
||||
"timestamp": "20260718T160204Z",
|
||||
"vhost": "www.archlinexp.eu"
|
||||
}
|
||||
@ -0,0 +1,199 @@
|
||||
<?php
|
||||
/**
|
||||
* @package Joomla.Site
|
||||
* @subpackage com_users
|
||||
*
|
||||
* @copyright Copyright (C) 2005 - 2018 Open Source Matters, Inc. All rights reserved.
|
||||
* @license GNU General Public License version 2 or later; see LICENSE.txt
|
||||
*/
|
||||
|
||||
defined('_JEXEC') or die;
|
||||
|
||||
/**
|
||||
* Users Route Helper
|
||||
*
|
||||
* @since 1.6
|
||||
* @deprecated 4.0
|
||||
*/
|
||||
class UsersHelperRoute
|
||||
{
|
||||
/**
|
||||
* Method to get the menu items for the component.
|
||||
*
|
||||
* @return array An array of menu items.
|
||||
*
|
||||
* @since 1.6
|
||||
* @deprecated 4.0
|
||||
*/
|
||||
public static function &getItems()
|
||||
{
|
||||
static $items;
|
||||
|
||||
// Get the menu items for this component.
|
||||
if (!isset($items))
|
||||
{
|
||||
$component = JComponentHelper::getComponent('com_users');
|
||||
$items = JFactory::getApplication()->getMenu()->getItems('component_id', $component->id);
|
||||
|
||||
// If no items found, set to empty array.
|
||||
if (!$items)
|
||||
{
|
||||
$items = array();
|
||||
}
|
||||
}
|
||||
|
||||
return $items;
|
||||
}
|
||||
|
||||
/**
|
||||
* Method to get a route configuration for the login view.
|
||||
*
|
||||
* @return mixed Integer menu id on success, null on failure.
|
||||
*
|
||||
* @since 1.6
|
||||
* @deprecated 4.0
|
||||
*/
|
||||
public static function getLoginRoute()
|
||||
{
|
||||
// Get the items.
|
||||
$items = self::getItems();
|
||||
|
||||
// Search for a suitable menu id.
|
||||
foreach ($items as $item)
|
||||
{
|
||||
if (isset($item->query['view']) && $item->query['view'] === 'login')
|
||||
{
|
||||
return $item->id;
|
||||
}
|
||||
}
|
||||
|
||||
return null;
|
||||
}
|
||||
|
||||
/**
|
||||
* Method to get a route configuration for the profile view.
|
||||
*
|
||||
* @return mixed Integer menu id on success, null on failure.
|
||||
*
|
||||
* @since 1.6
|
||||
* @deprecated 4.0
|
||||
*/
|
||||
public static function getProfileRoute()
|
||||
{
|
||||
// Get the items.
|
||||
$items = self::getItems();
|
||||
|
||||
// Search for a suitable menu id.
|
||||
// Menu link can only go to users own profile.
|
||||
|
||||
foreach ($items as $item)
|
||||
{
|
||||
if (isset($item->query['view']) && $item->query['view'] === 'profile')
|
||||
{
|
||||
return $item->id;
|
||||
}
|
||||
}
|
||||
|
||||
return null;
|
||||
}
|
||||
|
||||
/**
|
||||
* Method to get a route configuration for the registration view.
|
||||
*
|
||||
* @return mixed Integer menu id on success, null on failure.
|
||||
*
|
||||
* @since 1.6
|
||||
* @deprecated 4.0
|
||||
*/
|
||||
public static function getRegistrationRoute()
|
||||
{
|
||||
// Get the items.
|
||||
$items = self::getItems();
|
||||
|
||||
// Search for a suitable menu id.
|
||||
foreach ($items as $item)
|
||||
{
|
||||
if (isset($item->query['view']) && $item->query['view'] === 'registration')
|
||||
{
|
||||
return $item->id;
|
||||
}
|
||||
}
|
||||
|
||||
return null;
|
||||
}
|
||||
|
||||
/**
|
||||
* Method to get a route configuration for the remind view.
|
||||
*
|
||||
* @return mixed Integer menu id on success, null on failure.
|
||||
*
|
||||
* @since 1.6
|
||||
* @deprecated 4.0
|
||||
*/
|
||||
public static function getRemindRoute()
|
||||
{
|
||||
// Get the items.
|
||||
$items = self::getItems();
|
||||
|
||||
// Search for a suitable menu id.
|
||||
foreach ($items as $item)
|
||||
{
|
||||
if (isset($item->query['view']) && $item->query['view'] === 'remind')
|
||||
{
|
||||
return $item->id;
|
||||
}
|
||||
}
|
||||
|
||||
return null;
|
||||
}
|
||||
|
||||
/**
|
||||
* Method to get a route configuration for the resend view.
|
||||
*
|
||||
* @return mixed Integer menu id on success, null on failure.
|
||||
*
|
||||
* @since 1.6
|
||||
* @deprecated 4.0
|
||||
*/
|
||||
public static function getResendRoute()
|
||||
{
|
||||
// Get the items.
|
||||
$items = self::getItems();
|
||||
|
||||
// Search for a suitable menu id.
|
||||
foreach ($items as $item)
|
||||
{
|
||||
if (isset($item->query['view']) && $item->query['view'] === 'resend')
|
||||
{
|
||||
return $item->id;
|
||||
}
|
||||
}
|
||||
|
||||
return null;
|
||||
}
|
||||
|
||||
/**
|
||||
* Method to get a route configuration for the reset view.
|
||||
*
|
||||
* @return mixed Integer menu id on success, null on failure.
|
||||
*
|
||||
* @since 1.6
|
||||
* @deprecated 4.0
|
||||
*/
|
||||
public static function getResetRoute()
|
||||
{
|
||||
// Get the items.
|
||||
$items = self::getItems();
|
||||
|
||||
// Search for a suitable menu id.
|
||||
foreach ($items as $item)
|
||||
{
|
||||
if (isset($item->query['view']) && $item->query['view'] === 'reset')
|
||||
{
|
||||
return $item->id;
|
||||
}
|
||||
}
|
||||
|
||||
return null;
|
||||
}
|
||||
}
|
||||
@ -0,0 +1,15 @@
|
||||
{
|
||||
"finding_ref": "7282",
|
||||
"log_excerpt": "[quarantine] www.archlinexp.eu:components/com_users/helpers/route.php -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/components/com_users/helpers/route.php)",
|
||||
"original_sha256": "2f2d92b287b854fc6ad31c8168badc5938e39bec1f8b6202d4df348cd23a23f0",
|
||||
"original_stat": {
|
||||
"gid": 30037,
|
||||
"mtime": 1533967367,
|
||||
"size": 3867,
|
||||
"uid": 12425
|
||||
},
|
||||
"rel_path": "components/com_users/helpers/route.php",
|
||||
"result": "quarantined",
|
||||
"timestamp": "20260718T160204Z",
|
||||
"vhost": "www.archlinexp.eu"
|
||||
}
|
||||
@ -0,0 +1,60 @@
|
||||
<?php
|
||||
/**
|
||||
* @package Joomla.Site
|
||||
* @subpackage Layout
|
||||
*
|
||||
* @copyright Copyright (C) 2005 - 2019 Open Source Matters, Inc. All rights reserved.
|
||||
* @license GNU General Public License version 2 or later; see LICENSE.txt
|
||||
*/
|
||||
|
||||
defined('JPATH_BASE') or die;
|
||||
|
||||
extract($displayData);
|
||||
|
||||
/**
|
||||
* Layout variables
|
||||
* ---------------------
|
||||
* $options : (array) Optional parameters
|
||||
* $label : (string) The html code for the label (not required if $options['hiddenLabel'] is true)
|
||||
* $input : (string) The input field html code
|
||||
*/
|
||||
|
||||
if (!empty($options['showonEnabled']))
|
||||
{
|
||||
JHtml::_('jquery.framework');
|
||||
JHtml::_('script', 'jui/cms.js', array('version' => 'auto', 'relative' => true));
|
||||
}
|
||||
|
||||
$class = empty($options['class']) ? '' : ' ' . $options['class'];
|
||||
$rel = empty($options['rel']) ? '' : ' ' . $options['rel'];
|
||||
|
||||
/**
|
||||
* @TODO:
|
||||
*
|
||||
* As mentioned in #8473 (https://github.com/joomla/joomla-cms/pull/8473), ...
|
||||
* as long as we cannot access the field properties properly, this seems to
|
||||
* be the way to go for now.
|
||||
*
|
||||
* On a side note: Parsing html is seldom a good idea.
|
||||
* https://stackoverflow.com/questions/1732348/regex-match-open-tags-except-xhtml-self-contained-tags/1732454#1732454
|
||||
*/
|
||||
preg_match('/class=\"([^\"]+)\"/i', $input, $match);
|
||||
|
||||
$required = (strpos($input, 'aria-required="true"') !== false || (!empty($match[1]) && strpos($match[1], 'required') !== false));
|
||||
$typeOfSpacer = (strpos($label, 'spacer-lbl') !== false);
|
||||
|
||||
?>
|
||||
|
||||
<div class="control-group<?php echo $class; ?>"<?php echo $rel; ?>>
|
||||
<?php if (empty($options['hiddenLabel'])): ?>
|
||||
<div class="control-label">
|
||||
<?php echo $label; ?>
|
||||
<?php if (!$required && !$typeOfSpacer) : ?>
|
||||
<span class="optional"><?php echo JText::_('COM_USERS_OPTIONAL'); ?></span>
|
||||
<?php endif; ?>
|
||||
</div>
|
||||
<?php endif; ?>
|
||||
<div class="controls">
|
||||
<?php echo $input; ?>
|
||||
</div>
|
||||
</div>
|
||||
@ -0,0 +1,15 @@
|
||||
{
|
||||
"finding_ref": "7284",
|
||||
"log_excerpt": "[quarantine] www.archlinexp.eu:components/com_users/layouts/joomla/form/renderfield.php -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/components/com_users/layouts/joomla/form/renderfield.php)",
|
||||
"original_sha256": "767cc86103a71d15914e028fc231d5b48ffb5cdc5bf6ab8ecc3e22bb73d9190b",
|
||||
"original_stat": {
|
||||
"gid": 30037,
|
||||
"mtime": 1642534578,
|
||||
"size": 1957,
|
||||
"uid": 12425
|
||||
},
|
||||
"rel_path": "components/com_users/layouts/joomla/form/renderfield.php",
|
||||
"result": "quarantined",
|
||||
"timestamp": "20260718T160204Z",
|
||||
"vhost": "www.archlinexp.eu"
|
||||
}
|
||||
@ -0,0 +1,92 @@
|
||||
<?xml version="1.0" encoding="utf-8"?>
|
||||
<form>
|
||||
<fieldset name="core" label="COM_USERS_PROFILE_DEFAULT_LABEL">
|
||||
<field
|
||||
name="id"
|
||||
type="hidden"
|
||||
filter="integer"
|
||||
/>
|
||||
|
||||
<field
|
||||
name="name"
|
||||
type="text"
|
||||
label="COM_USERS_PROFILE_NAME_LABEL"
|
||||
description="COM_USERS_PROFILE_NAME_DESC"
|
||||
filter="string"
|
||||
required="true"
|
||||
size="30"
|
||||
/>
|
||||
|
||||
<field
|
||||
name="username"
|
||||
type="text"
|
||||
label="COM_USERS_PROFILE_USERNAME_LABEL"
|
||||
description="COM_USERS_DESIRED_USERNAME"
|
||||
class="validate-username"
|
||||
filter="username"
|
||||
message="COM_USERS_PROFILE_USERNAME_MESSAGE"
|
||||
required="true"
|
||||
size="30"
|
||||
validate="username"
|
||||
/>
|
||||
|
||||
<field
|
||||
name="password1"
|
||||
type="password"
|
||||
label="COM_USERS_PROFILE_PASSWORD1_LABEL"
|
||||
description="COM_USERS_DESIRED_PASSWORD"
|
||||
autocomplete="off"
|
||||
class="validate-password"
|
||||
filter="raw"
|
||||
size="30"
|
||||
validate="password"
|
||||
/>
|
||||
|
||||
<field
|
||||
name="password2"
|
||||
type="password"
|
||||
label="COM_USERS_PROFILE_PASSWORD2_LABEL"
|
||||
description="COM_USERS_PROFILE_PASSWORD2_DESC"
|
||||
autocomplete="off"
|
||||
class="validate-password"
|
||||
field="password1"
|
||||
filter="raw"
|
||||
message="COM_USERS_PROFILE_PASSWORD1_MESSAGE"
|
||||
size="30"
|
||||
validate="equals"
|
||||
/>
|
||||
|
||||
<field
|
||||
name="email1"
|
||||
type="email"
|
||||
label="COM_USERS_PROFILE_EMAIL1_LABEL"
|
||||
description="COM_USERS_PROFILE_EMAIL1_DESC"
|
||||
filter="string"
|
||||
message="COM_USERS_PROFILE_EMAIL1_MESSAGE"
|
||||
required="true"
|
||||
size="30"
|
||||
unique="true"
|
||||
validate="email"
|
||||
autocomplete="email"
|
||||
/>
|
||||
|
||||
<field
|
||||
name="email2"
|
||||
type="email"
|
||||
label="COM_USERS_PROFILE_EMAIL2_LABEL"
|
||||
description="COM_USERS_PROFILE_EMAIL2_DESC"
|
||||
field="email1"
|
||||
filter="string"
|
||||
message="COM_USERS_PROFILE_EMAIL2_MESSAGE"
|
||||
required="true"
|
||||
size="30"
|
||||
validate="equals"
|
||||
/>
|
||||
</fieldset>
|
||||
|
||||
<!-- Used to get the two factor authentication configuration -->
|
||||
<field
|
||||
name="twofactor"
|
||||
type="hidden"
|
||||
/>
|
||||
</form>
|
||||
@ -0,0 +1,15 @@
|
||||
{
|
||||
"finding_ref": "7278",
|
||||
"log_excerpt": "[quarantine] www.archlinexp.eu:components/com_users/models/forms/profile.xml -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/components/com_users/models/forms/profile.xml)",
|
||||
"original_sha256": "6f217de7628ab4c162bef301a62851bd90557bc43062783410df850901f536ba",
|
||||
"original_stat": {
|
||||
"gid": 30037,
|
||||
"mtime": 1533967367,
|
||||
"size": 1914,
|
||||
"uid": 12425
|
||||
},
|
||||
"rel_path": "components/com_users/models/forms/profile.xml",
|
||||
"result": "quarantined",
|
||||
"timestamp": "20260718T160204Z",
|
||||
"vhost": "www.archlinexp.eu"
|
||||
}
|
||||
@ -0,0 +1,99 @@
|
||||
<?xml version="1.0" encoding="utf-8"?>
|
||||
<form>
|
||||
<fieldset name="default" label="COM_USERS_REGISTRATION_DEFAULT_LABEL">
|
||||
<field
|
||||
name="spacer"
|
||||
type="spacer"
|
||||
label="COM_USERS_REGISTER_REQUIRED"
|
||||
class="text"
|
||||
/>
|
||||
|
||||
<field
|
||||
name="name"
|
||||
type="text"
|
||||
label="COM_USERS_REGISTER_NAME_LABEL"
|
||||
description="COM_USERS_REGISTER_NAME_DESC"
|
||||
filter="string"
|
||||
required="true"
|
||||
size="30"
|
||||
/>
|
||||
|
||||
<field
|
||||
name="username"
|
||||
type="text"
|
||||
label="COM_USERS_REGISTER_USERNAME_LABEL"
|
||||
description="COM_USERS_DESIRED_USERNAME"
|
||||
class="validate-username"
|
||||
filter="username"
|
||||
message="COM_USERS_REGISTER_USERNAME_MESSAGE"
|
||||
required="true"
|
||||
size="30"
|
||||
validate="username"
|
||||
/>
|
||||
|
||||
<field
|
||||
name="password1"
|
||||
type="password"
|
||||
label="COM_USERS_PROFILE_PASSWORD1_LABEL"
|
||||
description="COM_USERS_DESIRED_PASSWORD"
|
||||
autocomplete="off"
|
||||
class="validate-password"
|
||||
field="password1"
|
||||
filter="raw"
|
||||
size="30"
|
||||
validate="password"
|
||||
required="true"
|
||||
/>
|
||||
|
||||
<field
|
||||
name="password2"
|
||||
type="password"
|
||||
label="COM_USERS_PROFILE_PASSWORD2_LABEL"
|
||||
description="COM_USERS_PROFILE_PASSWORD2_DESC"
|
||||
autocomplete="off"
|
||||
class="validate-password"
|
||||
field="password1"
|
||||
filter="raw"
|
||||
message="COM_USERS_PROFILE_PASSWORD1_MESSAGE"
|
||||
size="30"
|
||||
validate="equals"
|
||||
required="true"
|
||||
/>
|
||||
|
||||
<field
|
||||
name="email1"
|
||||
type="email"
|
||||
label="COM_USERS_REGISTER_EMAIL1_LABEL"
|
||||
description="COM_USERS_REGISTER_EMAIL1_DESC"
|
||||
field="id"
|
||||
filter="string"
|
||||
message="COM_USERS_REGISTER_EMAIL1_MESSAGE"
|
||||
required="true"
|
||||
size="30"
|
||||
unique="true"
|
||||
validate="email"
|
||||
autocomplete="email"
|
||||
/>
|
||||
|
||||
<field
|
||||
name="email2"
|
||||
type="email"
|
||||
label="COM_USERS_REGISTER_EMAIL2_LABEL"
|
||||
description="COM_USERS_REGISTER_EMAIL2_DESC"
|
||||
field="email1"
|
||||
filter="string"
|
||||
message="COM_USERS_REGISTER_EMAIL2_MESSAGE"
|
||||
required="true"
|
||||
size="30"
|
||||
validate="equals"
|
||||
/>
|
||||
|
||||
<field
|
||||
name="captcha"
|
||||
type="captcha"
|
||||
label="COM_USERS_CAPTCHA_LABEL"
|
||||
description="COM_USERS_CAPTCHA_DESC"
|
||||
validate="captcha"
|
||||
/>
|
||||
</fieldset>
|
||||
</form>
|
||||
@ -0,0 +1,15 @@
|
||||
{
|
||||
"finding_ref": "7277",
|
||||
"log_excerpt": "[quarantine] www.archlinexp.eu:components/com_users/models/forms/registration.xml -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/components/com_users/models/forms/registration.xml)",
|
||||
"original_sha256": "d8d90d9badd444b08bd7243d3621f6af3feaee137523c212b5b883883f805b7e",
|
||||
"original_stat": {
|
||||
"gid": 30037,
|
||||
"mtime": 1541586989,
|
||||
"size": 2079,
|
||||
"uid": 12425
|
||||
},
|
||||
"rel_path": "components/com_users/models/forms/registration.xml",
|
||||
"result": "quarantined",
|
||||
"timestamp": "20260718T160204Z",
|
||||
"vhost": "www.archlinexp.eu"
|
||||
}
|
||||
@ -0,0 +1,112 @@
|
||||
<?php
|
||||
/**
|
||||
* @package Joomla.Site
|
||||
* @subpackage com_users
|
||||
*
|
||||
* @copyright Copyright (C) 2005 - 2018 Open Source Matters, Inc. All rights reserved.
|
||||
* @license GNU General Public License version 2 or later; see LICENSE.txt
|
||||
*/
|
||||
|
||||
defined('_JEXEC') or die;
|
||||
|
||||
/**
|
||||
* Rest model class for Users.
|
||||
*
|
||||
* @since 1.6
|
||||
*/
|
||||
class UsersModelLogin extends JModelForm
|
||||
{
|
||||
/**
|
||||
* Method to get the login form.
|
||||
*
|
||||
* The base form is loaded from XML and then an event is fired
|
||||
* for users plugins to extend the form with extra fields.
|
||||
*
|
||||
* @param array $data An optional array of data for the form to interogate.
|
||||
* @param boolean $loadData True if the form is to load its own data (default case), false if not.
|
||||
*
|
||||
* @return JForm A JForm object on success, false on failure
|
||||
*
|
||||
* @since 1.6
|
||||
*/
|
||||
public function getForm($data = array(), $loadData = true)
|
||||
{
|
||||
// Get the form.
|
||||
$form = $this->loadForm('com_users.login', 'login', array('load_data' => $loadData));
|
||||
|
||||
if (empty($form))
|
||||
{
|
||||
return false;
|
||||
}
|
||||
|
||||
return $form;
|
||||
}
|
||||
|
||||
/**
|
||||
* Method to get the data that should be injected in the form.
|
||||
*
|
||||
* @return array The default data is an empty array.
|
||||
*
|
||||
* @since 1.6
|
||||
*/
|
||||
protected function loadFormData()
|
||||
{
|
||||
// Check the session for previously entered login form data.
|
||||
$app = JFactory::getApplication();
|
||||
$data = $app->getUserState('users.login.form.data', array());
|
||||
|
||||
$input = $app->input->getInputForRequestMethod();
|
||||
|
||||
// Check for return URL from the request first
|
||||
if ($return = $input->get('return', '', 'BASE64'))
|
||||
{
|
||||
$data['return'] = base64_decode($return);
|
||||
|
||||
if (!JUri::isInternal($data['return']))
|
||||
{
|
||||
$data['return'] = '';
|
||||
}
|
||||
}
|
||||
|
||||
$app->setUserState('users.login.form.data', $data);
|
||||
|
||||
$this->preprocessData('com_users.login', $data);
|
||||
|
||||
return $data;
|
||||
}
|
||||
|
||||
/**
|
||||
* Method to auto-populate the model state.
|
||||
*
|
||||
* Calling getState in this method will result in recursion.
|
||||
*
|
||||
* @return void
|
||||
*
|
||||
* @since 1.6
|
||||
*/
|
||||
protected function populateState()
|
||||
{
|
||||
// Get the application object.
|
||||
$params = JFactory::getApplication()->getParams('com_users');
|
||||
|
||||
// Load the parameters.
|
||||
$this->setState('params', $params);
|
||||
}
|
||||
|
||||
/**
|
||||
* Override JModelAdmin::preprocessForm to ensure the correct plugin group is loaded.
|
||||
*
|
||||
* @param JForm $form A JForm object.
|
||||
* @param mixed $data The data expected for the form.
|
||||
* @param string $group The name of the plugin group to import (defaults to "content").
|
||||
*
|
||||
* @return void
|
||||
*
|
||||
* @since 1.6
|
||||
* @throws Exception if there is an error in the form event.
|
||||
*/
|
||||
protected function preprocessForm(JForm $form, $data, $group = 'user')
|
||||
{
|
||||
parent::preprocessForm($form, $data, $group);
|
||||
}
|
||||
}
|
||||
@ -0,0 +1,15 @@
|
||||
{
|
||||
"finding_ref": "7272",
|
||||
"log_excerpt": "[quarantine] www.archlinexp.eu:components/com_users/models/login.php -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/components/com_users/models/login.php)",
|
||||
"original_sha256": "1bd545c9d69235efbd0ca01aa8e3fee5c0416f9d7e57647314f029d01c7bcb75",
|
||||
"original_stat": {
|
||||
"gid": 30037,
|
||||
"mtime": 1533967367,
|
||||
"size": 2737,
|
||||
"uid": 12425
|
||||
},
|
||||
"rel_path": "components/com_users/models/login.php",
|
||||
"result": "quarantined",
|
||||
"timestamp": "20260718T160204Z",
|
||||
"vhost": "www.archlinexp.eu"
|
||||
}
|
||||
@ -0,0 +1,445 @@
|
||||
<?php
|
||||
/**
|
||||
* @package Joomla.Site
|
||||
* @subpackage com_users
|
||||
*
|
||||
* @copyright Copyright (C) 2005 - 2018 Open Source Matters, Inc. All rights reserved.
|
||||
* @license GNU General Public License version 2 or later; see LICENSE.txt
|
||||
*/
|
||||
|
||||
defined('_JEXEC') or die;
|
||||
|
||||
use Joomla\Registry\Registry;
|
||||
|
||||
/**
|
||||
* Profile model class for Users.
|
||||
*
|
||||
* @since 1.6
|
||||
*/
|
||||
class UsersModelProfile extends JModelForm
|
||||
{
|
||||
/**
|
||||
* @var object The user profile data.
|
||||
* @since 1.6
|
||||
*/
|
||||
protected $data;
|
||||
|
||||
/**
|
||||
* Constructor
|
||||
*
|
||||
* @param array $config An array of configuration options (name, state, dbo, table_path, ignore_request).
|
||||
*
|
||||
* @since 3.2
|
||||
*
|
||||
* @throws Exception
|
||||
*/
|
||||
public function __construct($config = array())
|
||||
{
|
||||
$config = array_merge(
|
||||
array(
|
||||
'events_map' => array('validate' => 'user')
|
||||
), $config
|
||||
);
|
||||
|
||||
parent::__construct($config);
|
||||
|
||||
// Load the helper and model used for two factor authentication
|
||||
JLoader::register('UsersModelUser', JPATH_ADMINISTRATOR . '/components/com_users/models/user.php');
|
||||
JLoader::register('UsersHelper', JPATH_ADMINISTRATOR . '/components/com_users/helpers/users.php');
|
||||
}
|
||||
|
||||
/**
|
||||
* Method to check in a user.
|
||||
*
|
||||
* @param integer $userId The id of the row to check out.
|
||||
*
|
||||
* @return boolean True on success, false on failure.
|
||||
*
|
||||
* @since 1.6
|
||||
*/
|
||||
public function checkin($userId = null)
|
||||
{
|
||||
// Get the user id.
|
||||
$userId = (!empty($userId)) ? $userId : (int) $this->getState('user.id');
|
||||
|
||||
if ($userId)
|
||||
{
|
||||
// Initialise the table with JUser.
|
||||
$table = JTable::getInstance('User');
|
||||
|
||||
// Attempt to check the row in.
|
||||
if (!$table->checkin($userId))
|
||||
{
|
||||
$this->setError($table->getError());
|
||||
|
||||
return false;
|
||||
}
|
||||
}
|
||||
|
||||
return true;
|
||||
}
|
||||
|
||||
/**
|
||||
* Method to check out a user for editing.
|
||||
*
|
||||
* @param integer $userId The id of the row to check out.
|
||||
*
|
||||
* @return boolean True on success, false on failure.
|
||||
*
|
||||
* @since 1.6
|
||||
*/
|
||||
public function checkout($userId = null)
|
||||
{
|
||||
// Get the user id.
|
||||
$userId = (!empty($userId)) ? $userId : (int) $this->getState('user.id');
|
||||
|
||||
if ($userId)
|
||||
{
|
||||
// Initialise the table with JUser.
|
||||
$table = JTable::getInstance('User');
|
||||
|
||||
// Get the current user object.
|
||||
$user = JFactory::getUser();
|
||||
|
||||
// Attempt to check the row out.
|
||||
if (!$table->checkout($user->get('id'), $userId))
|
||||
{
|
||||
$this->setError($table->getError());
|
||||
|
||||
return false;
|
||||
}
|
||||
}
|
||||
|
||||
return true;
|
||||
}
|
||||
|
||||
/**
|
||||
* Method to get the profile form data.
|
||||
*
|
||||
* The base form data is loaded and then an event is fired
|
||||
* for users plugins to extend the data.
|
||||
*
|
||||
* @return mixed Data object on success, false on failure.
|
||||
*
|
||||
* @since 1.6
|
||||
*/
|
||||
public function getData()
|
||||
{
|
||||
if ($this->data === null)
|
||||
{
|
||||
$userId = $this->getState('user.id');
|
||||
|
||||
// Initialise the table with JUser.
|
||||
$this->data = new JUser($userId);
|
||||
|
||||
// Set the base user data.
|
||||
$this->data->email1 = $this->data->get('email');
|
||||
$this->data->email2 = $this->data->get('email');
|
||||
|
||||
// Override the base user data with any data in the session.
|
||||
$temp = (array) JFactory::getApplication()->getUserState('com_users.edit.profile.data', array());
|
||||
|
||||
foreach ($temp as $k => $v)
|
||||
{
|
||||
$this->data->$k = $v;
|
||||
}
|
||||
|
||||
// Unset the passwords.
|
||||
unset($this->data->password1, $this->data->password2);
|
||||
|
||||
$registry = new Registry($this->data->params);
|
||||
$this->data->params = $registry->toArray();
|
||||
}
|
||||
|
||||
return $this->data;
|
||||
}
|
||||
|
||||
/**
|
||||
* Method to get the profile form.
|
||||
*
|
||||
* The base form is loaded from XML and then an event is fired
|
||||
* for users plugins to extend the form with extra fields.
|
||||
*
|
||||
* @param array $data An optional array of data for the form to interogate.
|
||||
* @param boolean $loadData True if the form is to load its own data (default case), false if not.
|
||||
*
|
||||
* @return JForm A JForm object on success, false on failure
|
||||
*
|
||||
* @since 1.6
|
||||
*/
|
||||
public function getForm($data = array(), $loadData = true)
|
||||
{
|
||||
// Get the form.
|
||||
$form = $this->loadForm('com_users.profile', 'profile', array('control' => 'jform', 'load_data' => $loadData));
|
||||
|
||||
if (empty($form))
|
||||
{
|
||||
return false;
|
||||
}
|
||||
|
||||
// Check for username compliance and parameter set
|
||||
$isUsernameCompliant = true;
|
||||
$username = $loadData ? $form->getValue('username') : $this->loadFormData()->username;
|
||||
|
||||
if ($username)
|
||||
{
|
||||
$isUsernameCompliant = !(preg_match('#[<>"\'%;()&\\\\]|\\.\\./#', $username) || strlen(utf8_decode($username)) < 2
|
||||
|| trim($username) !== $username);
|
||||
}
|
||||
|
||||
$this->setState('user.username.compliant', $isUsernameCompliant);
|
||||
|
||||
if ($isUsernameCompliant && !JComponentHelper::getParams('com_users')->get('change_login_name'))
|
||||
{
|
||||
$form->setFieldAttribute('username', 'class', '');
|
||||
$form->setFieldAttribute('username', 'filter', '');
|
||||
$form->setFieldAttribute('username', 'description', 'COM_USERS_PROFILE_NOCHANGE_USERNAME_DESC');
|
||||
$form->setFieldAttribute('username', 'validate', '');
|
||||
$form->setFieldAttribute('username', 'message', '');
|
||||
$form->setFieldAttribute('username', 'readonly', 'true');
|
||||
$form->setFieldAttribute('username', 'required', 'false');
|
||||
}
|
||||
|
||||
// When multilanguage is set, a user's default site language should also be a Content Language
|
||||
if (JLanguageMultilang::isEnabled())
|
||||
{
|
||||
$form->setFieldAttribute('language', 'type', 'frontend_language', 'params');
|
||||
}
|
||||
|
||||
// If the user needs to change their password, mark the password fields as required
|
||||
if (JFactory::getUser()->requireReset)
|
||||
{
|
||||
$form->setFieldAttribute('password1', 'required', 'true');
|
||||
$form->setFieldAttribute('password2', 'required', 'true');
|
||||
}
|
||||
|
||||
return $form;
|
||||
}
|
||||
|
||||
/**
|
||||
* Method to get the data that should be injected in the form.
|
||||
*
|
||||
* @return mixed The data for the form.
|
||||
*
|
||||
* @since 1.6
|
||||
*/
|
||||
protected function loadFormData()
|
||||
{
|
||||
$data = $this->getData();
|
||||
|
||||
$this->preprocessData('com_users.profile', $data, 'user');
|
||||
|
||||
return $data;
|
||||
}
|
||||
|
||||
/**
|
||||
* Override preprocessForm to load the user plugin group instead of content.
|
||||
*
|
||||
* @param JForm $form A JForm object.
|
||||
* @param mixed $data The data expected for the form.
|
||||
* @param string $group The name of the plugin group to import (defaults to "content").
|
||||
*
|
||||
* @return void
|
||||
*
|
||||
* @throws Exception if there is an error in the form event.
|
||||
*
|
||||
* @since 1.6
|
||||
*/
|
||||
protected function preprocessForm(JForm $form, $data, $group = 'user')
|
||||
{
|
||||
if (JComponentHelper::getParams('com_users')->get('frontend_userparams'))
|
||||
{
|
||||
$form->loadFile('frontend', false);
|
||||
|
||||
if (JFactory::getUser()->authorise('core.login.admin'))
|
||||
{
|
||||
$form->loadFile('frontend_admin', false);
|
||||
}
|
||||
}
|
||||
|
||||
parent::preprocessForm($form, $data, $group);
|
||||
}
|
||||
|
||||
/**
|
||||
* Method to auto-populate the model state.
|
||||
*
|
||||
* Note. Calling getState in this method will result in recursion.
|
||||
*
|
||||
* @return void
|
||||
*
|
||||
* @since 1.6
|
||||
*/
|
||||
protected function populateState()
|
||||
{
|
||||
// Get the application object.
|
||||
$params = JFactory::getApplication()->getParams('com_users');
|
||||
|
||||
// Get the user id.
|
||||
$userId = JFactory::getApplication()->getUserState('com_users.edit.profile.id');
|
||||
$userId = !empty($userId) ? $userId : (int) JFactory::getUser()->get('id');
|
||||
|
||||
// Set the user id.
|
||||
$this->setState('user.id', $userId);
|
||||
|
||||
// Load the parameters.
|
||||
$this->setState('params', $params);
|
||||
}
|
||||
|
||||
/**
|
||||
* Method to save the form data.
|
||||
*
|
||||
* @param array $data The form data.
|
||||
*
|
||||
* @return mixed The user id on success, false on failure.
|
||||
*
|
||||
* @since 1.6
|
||||
*/
|
||||
public function save($data)
|
||||
{
|
||||
$userId = (!empty($data['id'])) ? $data['id'] : (int) $this->getState('user.id');
|
||||
|
||||
$user = new JUser($userId);
|
||||
|
||||
// Prepare the data for the user object.
|
||||
$data['email'] = JStringPunycode::emailToPunycode($data['email1']);
|
||||
$data['password'] = $data['password1'];
|
||||
|
||||
// Unset the username if it should not be overwritten
|
||||
$isUsernameCompliant = $this->getState('user.username.compliant');
|
||||
|
||||
if ($isUsernameCompliant && !JComponentHelper::getParams('com_users')->get('change_login_name'))
|
||||
{
|
||||
unset($data['username']);
|
||||
}
|
||||
|
||||
// Unset block and sendEmail so they do not get overwritten
|
||||
unset($data['block'], $data['sendEmail']);
|
||||
|
||||
// Handle the two factor authentication setup
|
||||
if (array_key_exists('twofactor', $data))
|
||||
{
|
||||
$model = new UsersModelUser;
|
||||
|
||||
$twoFactorMethod = $data['twofactor']['method'];
|
||||
|
||||
// Get the current One Time Password (two factor auth) configuration
|
||||
$otpConfig = $model->getOtpConfig($userId);
|
||||
|
||||
if ($twoFactorMethod !== 'none')
|
||||
{
|
||||
// Run the plugins
|
||||
FOFPlatform::getInstance()->importPlugin('twofactorauth');
|
||||
$otpConfigReplies = FOFPlatform::getInstance()->runPlugins('onUserTwofactorApplyConfiguration', array($twoFactorMethod));
|
||||
|
||||
// Look for a valid reply
|
||||
foreach ($otpConfigReplies as $reply)
|
||||
{
|
||||
if (!is_object($reply) || empty($reply->method) || ($reply->method != $twoFactorMethod))
|
||||
{
|
||||
continue;
|
||||
}
|
||||
|
||||
$otpConfig->method = $reply->method;
|
||||
$otpConfig->config = $reply->config;
|
||||
|
||||
break;
|
||||
}
|
||||
|
||||
// Save OTP configuration.
|
||||
$model->setOtpConfig($userId, $otpConfig);
|
||||
|
||||
// Generate one time emergency passwords if required (depleted or not set)
|
||||
if (empty($otpConfig->otep))
|
||||
{
|
||||
$model->generateOteps($userId);
|
||||
}
|
||||
}
|
||||
else
|
||||
{
|
||||
$otpConfig->method = 'none';
|
||||
$otpConfig->config = array();
|
||||
$model->setOtpConfig($userId, $otpConfig);
|
||||
}
|
||||
|
||||
// Unset the raw data
|
||||
unset($data['twofactor']);
|
||||
|
||||
// Reload the user record with the updated OTP configuration
|
||||
$user->load($userId);
|
||||
}
|
||||
|
||||
// Bind the data.
|
||||
if (!$user->bind($data))
|
||||
{
|
||||
$this->setError(JText::sprintf('COM_USERS_PROFILE_BIND_FAILED', $user->getError()));
|
||||
|
||||
return false;
|
||||
}
|
||||
|
||||
// Load the users plugin group.
|
||||
JPluginHelper::importPlugin('user');
|
||||
|
||||
// Retrieve the user groups so they don't get overwritten
|
||||
unset($user->groups);
|
||||
$user->groups = JAccess::getGroupsByUser($user->id, false);
|
||||
|
||||
// Store the data.
|
||||
if (!$user->save())
|
||||
{
|
||||
$this->setError($user->getError());
|
||||
|
||||
return false;
|
||||
}
|
||||
|
||||
// Some contexts may not use tags data at all, so we allow callers to disable loading tag data
|
||||
if ($this->getState('load_tags', true))
|
||||
{
|
||||
$user->tags = new JHelperTags;
|
||||
$user->tags->getTagIds($user->id, 'com_users.user');
|
||||
}
|
||||
|
||||
return $user->id;
|
||||
}
|
||||
|
||||
/**
|
||||
* Gets the configuration forms for all two-factor authentication methods
|
||||
* in an array.
|
||||
*
|
||||
* @param integer $user_id The user ID to load the forms for (optional)
|
||||
*
|
||||
* @return array
|
||||
*
|
||||
* @since 3.2
|
||||
*/
|
||||
public function getTwofactorform($user_id = null)
|
||||
{
|
||||
$user_id = (!empty($user_id)) ? $user_id : (int) $this->getState('user.id');
|
||||
|
||||
$model = new UsersModelUser;
|
||||
|
||||
$otpConfig = $model->getOtpConfig($user_id);
|
||||
|
||||
FOFPlatform::getInstance()->importPlugin('twofactorauth');
|
||||
|
||||
return FOFPlatform::getInstance()->runPlugins('onUserTwofactorShowConfiguration', array($otpConfig, $user_id));
|
||||
}
|
||||
|
||||
/**
|
||||
* Returns the one time password (OTP) – a.k.a. two factor authentication –
|
||||
* configuration for a particular user.
|
||||
*
|
||||
* @param integer $user_id The numeric ID of the user
|
||||
*
|
||||
* @return stdClass An object holding the OTP configuration for this user
|
||||
*
|
||||
* @since 3.2
|
||||
*/
|
||||
public function getOtpConfig($user_id = null)
|
||||
{
|
||||
$user_id = (!empty($user_id)) ? $user_id : (int) $this->getState('user.id');
|
||||
|
||||
$model = new UsersModelUser;
|
||||
|
||||
return $model->getOtpConfig($user_id);
|
||||
}
|
||||
}
|
||||
@ -0,0 +1,15 @@
|
||||
{
|
||||
"finding_ref": "7276",
|
||||
"log_excerpt": "[quarantine] www.archlinexp.eu:components/com_users/models/profile.php -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/components/com_users/models/profile.php)",
|
||||
"original_sha256": "9120583bc9b1fc6d5c5b7a81fdd14c2d18250715cc89c672b743038cd62f7682",
|
||||
"original_stat": {
|
||||
"gid": 30037,
|
||||
"mtime": 1533967367,
|
||||
"size": 11442,
|
||||
"uid": 12425
|
||||
},
|
||||
"rel_path": "components/com_users/models/profile.php",
|
||||
"result": "quarantined",
|
||||
"timestamp": "20260718T160204Z",
|
||||
"vhost": "www.archlinexp.eu"
|
||||
}
|
||||
@ -0,0 +1,773 @@
|
||||
<?php
|
||||
|
||||
/**
|
||||
* @package Joomla.Site
|
||||
* @subpackage com_users
|
||||
*
|
||||
* @copyright Copyright (C) 2005 - 2018 Open Source Matters, Inc. All rights reserved.
|
||||
* @license GNU General Public License version 2 or later; see LICENSE.txt
|
||||
*/
|
||||
|
||||
defined('_JEXEC') or die;
|
||||
|
||||
/**
|
||||
* Registration model class for Users.
|
||||
*
|
||||
* @since 1.6
|
||||
*/
|
||||
class UsersModelRegistration extends JModelForm
|
||||
{
|
||||
/**
|
||||
* @var object The user registration data.
|
||||
* @since 1.6
|
||||
*/
|
||||
protected $data;
|
||||
|
||||
/**
|
||||
* Constructor
|
||||
*
|
||||
* @param array $config An array of configuration options (name, state, dbo, table_path, ignore_request).
|
||||
*
|
||||
* @since 3.6
|
||||
*
|
||||
* @throws Exception
|
||||
*/
|
||||
public function __construct($config = array())
|
||||
{
|
||||
$config = array_merge(
|
||||
array(
|
||||
'events_map' => array('validate' => 'user')
|
||||
),
|
||||
$config
|
||||
);
|
||||
|
||||
parent::__construct($config);
|
||||
}
|
||||
|
||||
/**
|
||||
* Method to activate a user account.
|
||||
*
|
||||
* @param string $token The activation token.
|
||||
*
|
||||
* @return mixed False on failure, user object on success.
|
||||
*
|
||||
* @since 1.6
|
||||
*/
|
||||
public function activate($token)
|
||||
{
|
||||
$config = JFactory::getConfig();
|
||||
$userParams = JComponentHelper::getParams('com_users');
|
||||
$db = $this->getDbo();
|
||||
|
||||
// Get the user id based on the token.
|
||||
$query = $db->getQuery(true);
|
||||
$query->select($db->quoteName('id'))
|
||||
->from($db->quoteName('#__users'))
|
||||
->where($db->quoteName('activation') . ' = ' . $db->quote($token))
|
||||
->where($db->quoteName('block') . ' = ' . 1)
|
||||
->where($db->quoteName('lastvisitDate') . ' = ' . $db->quote($db->getNullDate()));
|
||||
$db->setQuery($query);
|
||||
|
||||
try {
|
||||
$userId = (int) $db->loadResult();
|
||||
} catch (RuntimeException $e) {
|
||||
$this->setError(JText::sprintf('COM_USERS_DATABASE_ERROR', $e->getMessage()), 500);
|
||||
|
||||
return false;
|
||||
}
|
||||
|
||||
// Check for a valid user id.
|
||||
if (!$userId) {
|
||||
$this->setError(JText::_('COM_USERS_ACTIVATION_TOKEN_NOT_FOUND'));
|
||||
|
||||
return false;
|
||||
}
|
||||
|
||||
// Load the users plugin group.
|
||||
JPluginHelper::importPlugin('user');
|
||||
|
||||
// Activate the user.
|
||||
$user = JFactory::getUser($userId);
|
||||
|
||||
// Admin activation is on and user is verifying their email
|
||||
if (($userParams->get('useractivation') == 2) && !$user->getParam('activate', 0)) {
|
||||
$uri = JUri::getInstance();
|
||||
|
||||
// Compile the admin notification mail values.
|
||||
$data = $user->getProperties();
|
||||
$data['activation'] = JApplicationHelper::getHash(JUserHelper::genRandomPassword());
|
||||
$user->set('activation', $data['activation']);
|
||||
$data['siteurl'] = JUri::base();
|
||||
$base = $uri->toString(array('scheme', 'user', 'pass', 'host', 'port'));
|
||||
$data['activate'] = $base . JRoute::_('index.php?option=com_users&task=registration.activate&token=' . $data['activation'], false);
|
||||
|
||||
// Remove administrator/ from activate URL in case this method is called from admin
|
||||
if (JFactory::getApplication()->isClient('administrator')) {
|
||||
$adminPos = strrpos($data['activate'], 'administrator/');
|
||||
$data['activate'] = substr_replace($data['activate'], '', $adminPos, 14);
|
||||
}
|
||||
|
||||
$data['fromname'] = $config->get('fromname');
|
||||
$data['mailfrom'] = $config->get('mailfrom');
|
||||
$data['sitename'] = $config->get('sitename');
|
||||
$user->setParam('activate', 1);
|
||||
$emailSubject = JText::sprintf(
|
||||
'COM_USERS_EMAIL_ACTIVATE_WITH_ADMIN_ACTIVATION_SUBJECT',
|
||||
$data['name'],
|
||||
$data['sitename']
|
||||
);
|
||||
|
||||
$emailBody = JText::sprintf(
|
||||
'COM_USERS_EMAIL_ACTIVATE_WITH_ADMIN_ACTIVATION_BODY',
|
||||
$data['sitename'],
|
||||
$data['name'],
|
||||
$data['email'],
|
||||
$data['username'],
|
||||
$data['activate']
|
||||
);
|
||||
|
||||
// Get all admin users
|
||||
$query->clear()
|
||||
->select($db->quoteName(array('name', 'email', 'sendEmail', 'id')))
|
||||
->from($db->quoteName('#__users'))
|
||||
->where($db->quoteName('sendEmail') . ' = 1')
|
||||
->where($db->quoteName('block') . ' = 0');
|
||||
|
||||
$db->setQuery($query);
|
||||
|
||||
try {
|
||||
$rows = $db->loadObjectList();
|
||||
} catch (RuntimeException $e) {
|
||||
$this->setError(JText::sprintf('COM_USERS_DATABASE_ERROR', $e->getMessage()), 500);
|
||||
|
||||
return false;
|
||||
}
|
||||
|
||||
// Send mail to all users with users creating permissions and receiving system emails
|
||||
foreach ($rows as $row) {
|
||||
$usercreator = JFactory::getUser($row->id);
|
||||
|
||||
if ($usercreator->authorise('core.create', 'com_users')) {
|
||||
$return = JFactory::getMailer()->sendMail($data['mailfrom'], $data['fromname'], $row->email, $emailSubject, $emailBody);
|
||||
|
||||
// Check for an error.
|
||||
if ($return !== true) {
|
||||
$this->setError(JText::_('COM_USERS_REGISTRATION_ACTIVATION_NOTIFY_SEND_MAIL_FAILED'));
|
||||
|
||||
return false;
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
// Admin activation is on and admin is activating the account
|
||||
elseif (($userParams->get('useractivation') == 2) && $user->getParam('activate', 0)) {
|
||||
$user->set('activation', '');
|
||||
$user->set('block', '0');
|
||||
|
||||
// Compile the user activated notification mail values.
|
||||
$data = $user->getProperties();
|
||||
$user->setParam('activate', 0);
|
||||
$data['fromname'] = $config->get('fromname');
|
||||
$data['mailfrom'] = $config->get('mailfrom');
|
||||
$data['sitename'] = $config->get('sitename');
|
||||
$data['siteurl'] = JUri::base();
|
||||
$emailSubject = JText::sprintf(
|
||||
'COM_USERS_EMAIL_ACTIVATED_BY_ADMIN_ACTIVATION_SUBJECT',
|
||||
$data['name'],
|
||||
$data['sitename']
|
||||
);
|
||||
|
||||
$emailBody = JText::sprintf(
|
||||
'COM_USERS_EMAIL_ACTIVATED_BY_ADMIN_ACTIVATION_BODY',
|
||||
$data['name'],
|
||||
$data['siteurl'],
|
||||
$data['username']
|
||||
);
|
||||
|
||||
$return = JFactory::getMailer()->sendMail($data['mailfrom'], $data['fromname'], $data['email'], $emailSubject, $emailBody);
|
||||
|
||||
// Check for an error.
|
||||
if ($return !== true) {
|
||||
$this->setError(JText::_('COM_USERS_REGISTRATION_ACTIVATION_NOTIFY_SEND_MAIL_FAILED'));
|
||||
|
||||
return false;
|
||||
}
|
||||
} else {
|
||||
$user->set('activation', '');
|
||||
$user->set('block', '0');
|
||||
}
|
||||
|
||||
// Store the user object.
|
||||
if (!$user->save()) {
|
||||
$this->setError(JText::sprintf('COM_USERS_REGISTRATION_ACTIVATION_SAVE_FAILED', $user->getError()));
|
||||
|
||||
return false;
|
||||
}
|
||||
|
||||
return $user;
|
||||
}
|
||||
|
||||
/**
|
||||
* Method to get the registration form data.
|
||||
*
|
||||
* The base form data is loaded and then an event is fired
|
||||
* for users plugins to extend the data.
|
||||
*
|
||||
* @return mixed Data object on success, false on failure.
|
||||
*
|
||||
* @since 1.6
|
||||
*/
|
||||
public function getData()
|
||||
{
|
||||
if ($this->data === null) {
|
||||
$this->data = new stdClass;
|
||||
$app = JFactory::getApplication();
|
||||
$params = JComponentHelper::getParams('com_users');
|
||||
|
||||
// Override the base user data with any data in the session.
|
||||
$temp = (array) $app->getUserState('com_users.registration.data', array());
|
||||
|
||||
// Don't load the data in this getForm call, or we'll call ourself
|
||||
$form = $this->getForm(array(), false);
|
||||
|
||||
foreach ($temp as $k => $v) {
|
||||
// Here we could have a grouped field, let's check it
|
||||
if (is_array($v)) {
|
||||
$this->data->$k = new stdClass;
|
||||
|
||||
foreach ($v as $key => $val) {
|
||||
if ($form->getField($key, $k) !== false) {
|
||||
$this->data->$k->$key = $val;
|
||||
}
|
||||
}
|
||||
}
|
||||
// Only merge the field if it exists in the form.
|
||||
elseif ($form->getField($k) !== false) {
|
||||
$this->data->$k = $v;
|
||||
}
|
||||
}
|
||||
|
||||
// Get the groups the user should be added to after registration.
|
||||
$this->data->groups = array();
|
||||
|
||||
// Get the default new user group, Registered if not specified.
|
||||
$system = $params->get('new_usertype', 2);
|
||||
|
||||
$this->data->groups[] = $system;
|
||||
|
||||
// Unset the passwords.
|
||||
unset($this->data->password1, $this->data->password2);
|
||||
|
||||
// Get the dispatcher and load the users plugins.
|
||||
$dispatcher = JEventDispatcher::getInstance();
|
||||
JPluginHelper::importPlugin('user');
|
||||
|
||||
// Trigger the data preparation event.
|
||||
$results = $dispatcher->trigger('onContentPrepareData', array('com_users.registration', $this->data));
|
||||
|
||||
// Check for errors encountered while preparing the data.
|
||||
if (count($results) && in_array(false, $results, true)) {
|
||||
$this->setError($dispatcher->getError());
|
||||
$this->data = false;
|
||||
}
|
||||
}
|
||||
|
||||
return $this->data;
|
||||
}
|
||||
|
||||
/**
|
||||
* Method to get the registration form.
|
||||
*
|
||||
* The base form is loaded from XML and then an event is fired
|
||||
* for users plugins to extend the form with extra fields.
|
||||
*
|
||||
* @param array $data An optional array of data for the form to interogate.
|
||||
* @param boolean $loadData True if the form is to load its own data (default case), false if not.
|
||||
*
|
||||
* @return JForm A JForm object on success, false on failure
|
||||
*
|
||||
* @since 1.6
|
||||
*/
|
||||
public function getForm($data = array(), $loadData = true)
|
||||
{
|
||||
// Get the form.
|
||||
$form = $this->loadForm('com_users.registration', 'registration', array('control' => 'jform', 'load_data' => $loadData));
|
||||
|
||||
if (empty($form)) {
|
||||
return false;
|
||||
}
|
||||
|
||||
// When multilanguage is set, a user's default site language should also be a Content Language
|
||||
if (JLanguageMultilang::isEnabled()) {
|
||||
$form->setFieldAttribute('language', 'type', 'frontend_language', 'params');
|
||||
}
|
||||
|
||||
return $form;
|
||||
}
|
||||
|
||||
/**
|
||||
* Method to get the data that should be injected in the form.
|
||||
*
|
||||
* @return mixed The data for the form.
|
||||
*
|
||||
* @since 1.6
|
||||
*/
|
||||
protected function loadFormData()
|
||||
{
|
||||
$data = $this->getData();
|
||||
|
||||
if (JLanguageMultilang::isEnabled() && empty($data->language)) {
|
||||
$data->language = JFactory::getLanguage()->getTag();
|
||||
}
|
||||
|
||||
$this->preprocessData('com_users.registration', $data);
|
||||
|
||||
return $data;
|
||||
}
|
||||
|
||||
/**
|
||||
* Override preprocessForm to load the user plugin group instead of content.
|
||||
*
|
||||
* @param JForm $form A JForm object.
|
||||
* @param mixed $data The data expected for the form.
|
||||
* @param string $group The name of the plugin group to import (defaults to "content").
|
||||
*
|
||||
* @return void
|
||||
*
|
||||
* @since 1.6
|
||||
* @throws Exception if there is an error in the form event.
|
||||
*/
|
||||
protected function preprocessForm(JForm $form, $data, $group = 'user')
|
||||
{
|
||||
$userParams = JComponentHelper::getParams('com_users');
|
||||
|
||||
// Add the choice for site language at registration time
|
||||
if ($userParams->get('site_language') == 1 && $userParams->get('frontend_userparams') == 1) {
|
||||
$form->loadFile('sitelang', false);
|
||||
}
|
||||
|
||||
parent::preprocessForm($form, $data, $group);
|
||||
}
|
||||
|
||||
/**
|
||||
* Method to auto-populate the model state.
|
||||
*
|
||||
* Note. Calling getState in this method will result in recursion.
|
||||
*
|
||||
* @return void
|
||||
*
|
||||
* @since 1.6
|
||||
*/
|
||||
protected function populateState()
|
||||
{
|
||||
// Get the application object.
|
||||
$app = JFactory::getApplication();
|
||||
$params = $app->getParams('com_users');
|
||||
|
||||
// Load the parameters.
|
||||
$this->setState('params', $params);
|
||||
}
|
||||
|
||||
/**
|
||||
* Method to save the form data.
|
||||
*
|
||||
* @param array $temp The form data.
|
||||
*
|
||||
* @return mixed The user id on success, false on failure.
|
||||
*
|
||||
* @since 1.6
|
||||
*/
|
||||
public function register($temp)
|
||||
{
|
||||
$params = JComponentHelper::getParams('com_users');
|
||||
|
||||
// Initialise the table with JUser.
|
||||
$user = new JUser;
|
||||
$data = (array) $this->getData();
|
||||
|
||||
// Merge in the registration data.
|
||||
foreach ($temp as $k => $v) {
|
||||
$data[$k] = $v;
|
||||
}
|
||||
|
||||
// Prepare the data for the user object.
|
||||
$data['email'] = JStringPunycode::emailToPunycode($data['email1']);
|
||||
$data['name'] = $data['firstname']; // N.M. Az új registration form miatt kellett. Az emailben kiküldött név nem úgy jelent meg, ahogy kéne
|
||||
$data['name'] .= ' ';
|
||||
$data['name'] .= $data['lastname'];
|
||||
$data['password'] = $data['password1'];
|
||||
$useractivation = $params->get('useractivation');
|
||||
$sendpassword = $params->get('sendpassword', 1);
|
||||
|
||||
// Check if the user needs to activate their account.
|
||||
if (($useractivation == 1) || ($useractivation == 2)) {
|
||||
$data['activation'] = JApplicationHelper::getHash(JUserHelper::genRandomPassword());
|
||||
$data['block'] = 1;
|
||||
}
|
||||
|
||||
// Bind the data.
|
||||
if (!$user->bind($data)) {
|
||||
$this->setError(JText::sprintf('COM_USERS_REGISTRATION_BIND_FAILED', $user->getError()));
|
||||
|
||||
return false;
|
||||
}
|
||||
|
||||
// Load the users plugin group.
|
||||
JPluginHelper::importPlugin('user');
|
||||
|
||||
// Store the data.
|
||||
if (!$user->save()) {
|
||||
$this->setError(JText::sprintf('COM_USERS_REGISTRATION_SAVE_FAILED', $user->getError()));
|
||||
|
||||
return false;
|
||||
}
|
||||
|
||||
$config = JFactory::getConfig();
|
||||
$db = $this->getDbo();
|
||||
$query = $db->getQuery(true);
|
||||
|
||||
// Compile the notification mail values.
|
||||
$data = $user->getProperties();
|
||||
$data['fromname'] = $config->get('fromname');
|
||||
$data['mailfrom'] = $config->get('mailfrom');
|
||||
$data['sitename'] = $config->get('sitename');
|
||||
$data['siteurl'] = JUri::root();
|
||||
|
||||
// Handle account activation/confirmation emails.
|
||||
if ($useractivation == 2) {
|
||||
// Set the link to confirm the user email.
|
||||
$uri = JUri::getInstance();
|
||||
$base = $uri->toString(array('scheme', 'user', 'pass', 'host', 'port'));
|
||||
$data['activate'] = $base . JRoute::_('index.php?option=com_users&task=registration.activate&token=' . $data['activation'], false);
|
||||
|
||||
// Remove administrator/ from activate URL in case this method is called from admin
|
||||
if (JFactory::getApplication()->isClient('administrator')) {
|
||||
$adminPos = strrpos($data['activate'], 'administrator/');
|
||||
$data['activate'] = substr_replace($data['activate'], '', $adminPos, 14);
|
||||
}
|
||||
|
||||
$emailSubject = JText::sprintf(
|
||||
'COM_USERS_EMAIL_ACCOUNT_DETAILS',
|
||||
$data['name'],
|
||||
$data['sitename']
|
||||
);
|
||||
|
||||
if ($sendpassword) {
|
||||
$emailBody = JText::sprintf(
|
||||
'COM_USERS_EMAIL_REGISTERED_WITH_ADMIN_ACTIVATION_BODY',
|
||||
$data['name'],
|
||||
$data['sitename'],
|
||||
$data['activate'],
|
||||
$data['siteurl'],
|
||||
$data['username'],
|
||||
$data['password_clear']
|
||||
);
|
||||
} else {
|
||||
$emailBody = JText::sprintf(
|
||||
'COM_USERS_EMAIL_REGISTERED_WITH_ADMIN_ACTIVATION_BODY_NOPW',
|
||||
$data['name'],
|
||||
$data['sitename'],
|
||||
$data['activate'],
|
||||
$data['siteurl'],
|
||||
$data['username']
|
||||
);
|
||||
}
|
||||
} elseif ($useractivation == 1) {
|
||||
// Set the link to activate the user account.
|
||||
$uri = JUri::getInstance();
|
||||
$base = $uri->toString(array('scheme', 'user', 'pass', 'host', 'port'));
|
||||
$data['activate'] = $base . JRoute::_('index.php?option=com_users&task=registration.activate&token=' . $data['activation'], false);
|
||||
|
||||
// Remove administrator/ from activate URL in case this method is called from admin
|
||||
if (JFactory::getApplication()->isClient('administrator')) {
|
||||
$adminPos = strrpos($data['activate'], 'administrator/');
|
||||
$data['activate'] = substr_replace($data['activate'], '', $adminPos, 14);
|
||||
}
|
||||
|
||||
$emailSubject = JText::sprintf(
|
||||
'COM_USERS_EMAIL_ACCOUNT_DETAILS',
|
||||
$data['name'],
|
||||
$data['sitename']
|
||||
);
|
||||
|
||||
if ($sendpassword) {
|
||||
$emailBody = JText::sprintf(
|
||||
'COM_USERS_EMAIL_REGISTERED_WITH_ACTIVATION_BODY',
|
||||
$data['name'],
|
||||
$data['sitename'],
|
||||
$data['activate'],
|
||||
$data['siteurl'],
|
||||
$data['username'],
|
||||
$data['password_clear']
|
||||
);
|
||||
} else {
|
||||
$emailBody = JText::sprintf(
|
||||
'COM_USERS_EMAIL_REGISTERED_WITH_ACTIVATION_BODY_NOPW',
|
||||
$data['name'],
|
||||
$data['sitename'],
|
||||
$data['activate'],
|
||||
$data['siteurl'],
|
||||
$data['username']
|
||||
);
|
||||
}
|
||||
} else {
|
||||
$emailSubject = JText::sprintf(
|
||||
'COM_USERS_EMAIL_ACCOUNT_DETAILS',
|
||||
$data['name'],
|
||||
$data['sitename']
|
||||
);
|
||||
|
||||
if ($sendpassword) {
|
||||
$emailBody = JText::sprintf(
|
||||
'COM_USERS_EMAIL_REGISTERED_BODY',
|
||||
$data['name'],
|
||||
$data['sitename'],
|
||||
$data['siteurl'],
|
||||
$data['username'],
|
||||
$data['password_clear']
|
||||
);
|
||||
} else {
|
||||
$emailBody = JText::sprintf(
|
||||
'COM_USERS_EMAIL_REGISTERED_BODY_NOPW',
|
||||
$data['name'],
|
||||
$data['sitename'],
|
||||
$data['siteurl']
|
||||
);
|
||||
}
|
||||
}
|
||||
|
||||
// Send the registration email.
|
||||
$return = JFactory::getMailer()->sendMail($data['mailfrom'], $data['fromname'], $data['email'], $emailSubject, $emailBody);
|
||||
|
||||
// Send Notification mail to administrators
|
||||
if (($params->get('useractivation') < 2) && ($params->get('mail_to_admin') == 1)) {
|
||||
$emailSubject = JText::sprintf(
|
||||
'COM_USERS_EMAIL_ACCOUNT_DETAILS',
|
||||
$data['name'],
|
||||
$data['sitename']
|
||||
);
|
||||
|
||||
$emailBodyAdmin = JText::sprintf(
|
||||
'COM_USERS_EMAIL_REGISTERED_NOTIFICATION_TO_ADMIN_BODY',
|
||||
$data['name'],
|
||||
$data['username'],
|
||||
$data['siteurl']
|
||||
);
|
||||
|
||||
// Get all admin users
|
||||
$query->clear()
|
||||
->select($db->quoteName(array('name', 'email', 'sendEmail')))
|
||||
->from($db->quoteName('#__users'))
|
||||
->where($db->quoteName('sendEmail') . ' = 1')
|
||||
->where($db->quoteName('block') . ' = 0');
|
||||
|
||||
$db->setQuery($query);
|
||||
|
||||
try {
|
||||
$rows = $db->loadObjectList();
|
||||
} catch (RuntimeException $e) {
|
||||
$this->setError(JText::sprintf('COM_USERS_DATABASE_ERROR', $e->getMessage()), 500);
|
||||
|
||||
return false;
|
||||
}
|
||||
|
||||
// Send mail to all superadministrators id
|
||||
foreach ($rows as $row) {
|
||||
$return = JFactory::getMailer()->sendMail($data['mailfrom'], $data['fromname'], $row->email, $emailSubject, $emailBodyAdmin);
|
||||
|
||||
// Check for an error.
|
||||
if ($return !== true) {
|
||||
$this->setError(JText::_('COM_USERS_REGISTRATION_ACTIVATION_NOTIFY_SEND_MAIL_FAILED'));
|
||||
|
||||
return false;
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
// Check for an error.
|
||||
if ($return !== true) {
|
||||
$this->setError(JText::_('COM_USERS_REGISTRATION_SEND_MAIL_FAILED'));
|
||||
|
||||
// Send a system message to administrators receiving system mails
|
||||
$db = $this->getDbo();
|
||||
$query->clear()
|
||||
->select($db->quoteName('id'))
|
||||
->from($db->quoteName('#__users'))
|
||||
->where($db->quoteName('block') . ' = ' . (int) 0)
|
||||
->where($db->quoteName('sendEmail') . ' = ' . (int) 1);
|
||||
$db->setQuery($query);
|
||||
|
||||
try {
|
||||
$userids = $db->loadColumn();
|
||||
} catch (RuntimeException $e) {
|
||||
$this->setError(JText::sprintf('COM_USERS_DATABASE_ERROR', $e->getMessage()), 500);
|
||||
|
||||
return false;
|
||||
}
|
||||
|
||||
if (count($userids) > 0) {
|
||||
$jdate = new JDate;
|
||||
|
||||
// Build the query to add the messages
|
||||
foreach ($userids as $userid) {
|
||||
$values = array(
|
||||
$db->quote($userid),
|
||||
$db->quote($userid),
|
||||
$db->quote($jdate->toSql()),
|
||||
$db->quote(JText::_('COM_USERS_MAIL_SEND_FAILURE_SUBJECT')),
|
||||
$db->quote(JText::sprintf('COM_USERS_MAIL_SEND_FAILURE_BODY', $return, $data['username']))
|
||||
);
|
||||
$query->clear()
|
||||
->insert($db->quoteName('#__messages'))
|
||||
->columns($db->quoteName(array('user_id_from', 'user_id_to', 'date_time', 'subject', 'message')))
|
||||
->values(implode(',', $values));
|
||||
$db->setQuery($query);
|
||||
|
||||
try {
|
||||
$db->execute();
|
||||
} catch (RuntimeException $e) {
|
||||
$this->setError(JText::sprintf('COM_USERS_DATABASE_ERROR', $e->getMessage()), 500);
|
||||
|
||||
return false;
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
return false;
|
||||
}
|
||||
|
||||
if ($useractivation == 1) {
|
||||
return 'useractivate';
|
||||
} elseif ($useractivation == 2) {
|
||||
return 'adminactivate';
|
||||
} else {
|
||||
return $user->id;
|
||||
}
|
||||
}
|
||||
|
||||
private function checkCaptcha($response)
|
||||
{
|
||||
$secret = '';
|
||||
|
||||
if ($_SERVER['SERVER_NAME'] == 'www.archline.hu')
|
||||
$secret = '6Lc8nh8TAAAAALeRGLDbjsr7Rh1qpQJkYXYO-P50';
|
||||
else
|
||||
$secret = '6LeqnB8TAAAAAJTatP1dt8npqwDfJLz4_i9-rbNg';
|
||||
|
||||
$post_data = http_build_query(
|
||||
array(
|
||||
'secret' => $secret,
|
||||
'response' => $response,
|
||||
'remoteip' => $_SERVER['REMOTE_ADDR']
|
||||
)
|
||||
);
|
||||
|
||||
$opts = array(
|
||||
'http' =>
|
||||
array(
|
||||
'method' => 'POST',
|
||||
'header' => 'Content-type: application/x-www-form-urlencoded',
|
||||
'content' => $post_data
|
||||
)
|
||||
);
|
||||
|
||||
$context = stream_context_create($opts);
|
||||
|
||||
$response = file_get_contents('https://www.google.com/recaptcha/api/siteverify', false, $context);
|
||||
$result = json_decode($response);
|
||||
|
||||
return $result->success;
|
||||
}
|
||||
|
||||
private function phoneCorrect(&$phone)
|
||||
{
|
||||
$phone = str_replace('-', '', $phone);
|
||||
$phone = str_replace(' ', '', $phone);
|
||||
$phone = str_replace('+', '', $phone);
|
||||
$phone = str_replace('/', '', $phone);
|
||||
$phone = str_replace('.', '', $phone);
|
||||
$phone = str_replace(' ', '', $phone);
|
||||
|
||||
return $phone;
|
||||
}
|
||||
|
||||
public function registerWithARCHLine($temp, &$message)
|
||||
{
|
||||
if (!class_exists('crm_hardlock')) require_once(JPATH_BASE . "/common_cadline_libraries/crm_hardlock.class.php");
|
||||
|
||||
$resource = new Resource($temp['country']);
|
||||
|
||||
$captchaResult = $this->checkCaptcha($temp['captcha']);
|
||||
|
||||
if (!$captchaResult) {
|
||||
$message = $resource->getDlgString('10947');
|
||||
return false;
|
||||
}
|
||||
|
||||
$query = "SELECT * FROM www_archline_hu.jml_users WHERE username = ? OR email = ?";
|
||||
Database::getInstance()->query($query, array('ss', $temp['email'], $temp['email']));
|
||||
$res = Database::getInstance()->fetchNext();
|
||||
|
||||
if (!empty($res)) {
|
||||
$message = $resource->getDlgString('10789');
|
||||
return false;
|
||||
}
|
||||
|
||||
if ($temp['password'] != $temp['password2']) {
|
||||
$message = $resource->getDlgString('10792');
|
||||
return false;
|
||||
}
|
||||
|
||||
// Initialise the table with JUser.
|
||||
$user = new JUser;
|
||||
$data = (array) $this->getData();
|
||||
|
||||
// Merge in the registration data.
|
||||
foreach ($temp as $k => $v) {
|
||||
$data[$k] = $v;
|
||||
}
|
||||
|
||||
$user->bind($data);
|
||||
|
||||
if (!$user->save()) {
|
||||
$message = JText::sprintf('COM_USERS_REGISTRATION_SAVE_FAILED', $user->getError());
|
||||
return false;
|
||||
}
|
||||
|
||||
$profile_phone = array(
|
||||
'user_id' => $user->id,
|
||||
'profile_key' => 'profile.phone',
|
||||
'profile_value' => $temp['phone'],
|
||||
'ordering' => 7
|
||||
);
|
||||
|
||||
$profile_country = array(
|
||||
'user_id' => $user->id,
|
||||
'profile_key' => 'profile.country',
|
||||
'profile_value' => $temp['country'],
|
||||
'ordering' => 5
|
||||
);
|
||||
|
||||
Database::getInstance()->insert('www_archline_hu.jml_user_profiles', $profile_phone, 'issi');
|
||||
Database::getInstance()->insert('www_archline_hu.jml_user_profiles', $profile_country, 'issi');
|
||||
|
||||
$this->phoneCorrect($temp['phone']);
|
||||
|
||||
$query = "SELECT * FROM www_archline_hu.jml_users WHERE id = ?";
|
||||
Database::getInstance()->query($query, array('i', $user->id));
|
||||
$jmlUser = Database::getInstance()->fetchNext();
|
||||
|
||||
Database::getInstance()->update(
|
||||
'cl_hlusers.users',
|
||||
array(
|
||||
'strTel' => $temp['phone'],
|
||||
'nCtrID' => $temp['country']
|
||||
),
|
||||
array('nUserID' => $jmlUser['nUserID']),
|
||||
'sii'
|
||||
);
|
||||
|
||||
$message = $resource->getDlgString('10793');
|
||||
return $user->id;
|
||||
}
|
||||
}
|
||||
@ -0,0 +1,15 @@
|
||||
{
|
||||
"finding_ref": "7275",
|
||||
"log_excerpt": "[quarantine] www.archlinexp.eu:components/com_users/models/registration.php -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/components/com_users/models/registration.php)",
|
||||
"original_sha256": "36f98683f5d734fd65acabfd638da4bff54196ce0f4fc2574c23ab9ef9b66ba6",
|
||||
"original_stat": {
|
||||
"gid": 30037,
|
||||
"mtime": 1658220713,
|
||||
"size": 22646,
|
||||
"uid": 12425
|
||||
},
|
||||
"rel_path": "components/com_users/models/registration.php",
|
||||
"result": "quarantined",
|
||||
"timestamp": "20260718T160204Z",
|
||||
"vhost": "www.archlinexp.eu"
|
||||
}
|
||||
@ -0,0 +1,198 @@
|
||||
<?php
|
||||
/**
|
||||
* @package Joomla.Site
|
||||
* @subpackage com_users
|
||||
*
|
||||
* @copyright Copyright (C) 2005 - 2018 Open Source Matters, Inc. All rights reserved.
|
||||
* @license GNU General Public License version 2 or later; see LICENSE.txt
|
||||
*/
|
||||
|
||||
defined('_JEXEC') or die;
|
||||
|
||||
use Joomla\Utilities\ArrayHelper;
|
||||
|
||||
/**
|
||||
* Remind model class for Users.
|
||||
*
|
||||
* @since 1.5
|
||||
*/
|
||||
class UsersModelRemind extends JModelForm
|
||||
{
|
||||
/**
|
||||
* Method to get the username remind request form.
|
||||
*
|
||||
* @param array $data An optional array of data for the form to interogate.
|
||||
* @param boolean $loadData True if the form is to load its own data (default case), false if not.
|
||||
*
|
||||
* @return JFor A JForm object on success, false on failure
|
||||
*
|
||||
* @since 1.6
|
||||
*/
|
||||
public function getForm($data = array(), $loadData = true)
|
||||
{
|
||||
// Get the form.
|
||||
$form = $this->loadForm('com_users.remind', 'remind', array('control' => 'jform', 'load_data' => $loadData));
|
||||
|
||||
if (empty($form))
|
||||
{
|
||||
return false;
|
||||
}
|
||||
|
||||
return $form;
|
||||
}
|
||||
|
||||
/**
|
||||
* Override preprocessForm to load the user plugin group instead of content.
|
||||
*
|
||||
* @param JForm $form A JForm object.
|
||||
* @param mixed $data The data expected for the form.
|
||||
* @param string $group The name of the plugin group to import (defaults to "content").
|
||||
*
|
||||
* @return void
|
||||
*
|
||||
* @throws Exception if there is an error in the form event.
|
||||
*
|
||||
* @since 1.6
|
||||
*/
|
||||
protected function preprocessForm(JForm $form, $data, $group = 'user')
|
||||
{
|
||||
parent::preprocessForm($form, $data, 'user');
|
||||
}
|
||||
|
||||
/**
|
||||
* Method to auto-populate the model state.
|
||||
*
|
||||
* Note. Calling getState in this method will result in recursion.
|
||||
*
|
||||
* @return void
|
||||
*
|
||||
* @since 1.6
|
||||
*/
|
||||
protected function populateState()
|
||||
{
|
||||
// Get the application object.
|
||||
$app = JFactory::getApplication();
|
||||
$params = $app->getParams('com_users');
|
||||
|
||||
// Load the parameters.
|
||||
$this->setState('params', $params);
|
||||
}
|
||||
|
||||
/**
|
||||
* Send the remind username email
|
||||
*
|
||||
* @param array $data Array with the data received from the form
|
||||
*
|
||||
* @return boolean
|
||||
*
|
||||
* @since 1.6
|
||||
*/
|
||||
public function processRemindRequest($data)
|
||||
{
|
||||
// Get the form.
|
||||
$form = $this->getForm();
|
||||
$data['email'] = JStringPunycode::emailToPunycode($data['email']);
|
||||
|
||||
// Check for an error.
|
||||
if (empty($form))
|
||||
{
|
||||
return false;
|
||||
}
|
||||
|
||||
// Validate the data.
|
||||
$data = $this->validate($form, $data);
|
||||
|
||||
// Check for an error.
|
||||
if ($data instanceof Exception)
|
||||
{
|
||||
return false;
|
||||
}
|
||||
|
||||
// Check the validation results.
|
||||
if ($data === false)
|
||||
{
|
||||
// Get the validation messages from the form.
|
||||
foreach ($form->getErrors() as $formError)
|
||||
{
|
||||
$this->setError($formError->getMessage());
|
||||
}
|
||||
|
||||
return false;
|
||||
}
|
||||
|
||||
// Find the user id for the given email address.
|
||||
$db = $this->getDbo();
|
||||
$query = $db->getQuery(true)
|
||||
->select('*')
|
||||
->from($db->quoteName('#__users'))
|
||||
->where($db->quoteName('email') . ' = ' . $db->quote($data['email']));
|
||||
|
||||
// Get the user id.
|
||||
$db->setQuery($query);
|
||||
|
||||
try
|
||||
{
|
||||
$user = $db->loadObject();
|
||||
}
|
||||
catch (RuntimeException $e)
|
||||
{
|
||||
$this->setError(JText::sprintf('COM_USERS_DATABASE_ERROR', $e->getMessage()), 500);
|
||||
|
||||
return false;
|
||||
}
|
||||
|
||||
// Check for a user.
|
||||
if (empty($user))
|
||||
{
|
||||
$this->setError(JText::_('COM_USERS_USER_NOT_FOUND'));
|
||||
|
||||
return false;
|
||||
}
|
||||
|
||||
// Make sure the user isn't blocked.
|
||||
if ($user->block)
|
||||
{
|
||||
$this->setError(JText::_('COM_USERS_USER_BLOCKED'));
|
||||
|
||||
return false;
|
||||
}
|
||||
|
||||
$config = JFactory::getConfig();
|
||||
|
||||
// Assemble the login link.
|
||||
$link = 'index.php?option=com_users&view=login';
|
||||
$mode = $config->get('force_ssl', 0) == 2 ? 1 : (-1);
|
||||
|
||||
// Put together the email template data.
|
||||
$data = ArrayHelper::fromObject($user);
|
||||
$data['fromname'] = $config->get('fromname');
|
||||
$data['mailfrom'] = $config->get('mailfrom');
|
||||
$data['sitename'] = $config->get('sitename');
|
||||
$data['link_text'] = JRoute::_($link, false, $mode);
|
||||
$data['link_html'] = JRoute::_($link, true, $mode);
|
||||
|
||||
$subject = JText::sprintf(
|
||||
'COM_USERS_EMAIL_USERNAME_REMINDER_SUBJECT',
|
||||
$data['sitename']
|
||||
);
|
||||
$body = JText::sprintf(
|
||||
'COM_USERS_EMAIL_USERNAME_REMINDER_BODY',
|
||||
$data['sitename'],
|
||||
$data['username'],
|
||||
$data['link_text']
|
||||
);
|
||||
|
||||
// Send the password reset request email.
|
||||
$return = JFactory::getMailer()->sendMail($data['mailfrom'], $data['fromname'], $user->email, $subject, $body);
|
||||
|
||||
// Check for an error.
|
||||
if ($return !== true)
|
||||
{
|
||||
$this->setError(JText::_('COM_USERS_MAIL_FAILED'), 500);
|
||||
|
||||
return false;
|
||||
}
|
||||
|
||||
return true;
|
||||
}
|
||||
}
|
||||
@ -0,0 +1,15 @@
|
||||
{
|
||||
"finding_ref": "7273",
|
||||
"log_excerpt": "[quarantine] www.archlinexp.eu:components/com_users/models/remind.php -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/components/com_users/models/remind.php)",
|
||||
"original_sha256": "25d8b3522b7b6fc0456dda7a2cc346c94e9b3889f4180d32f3e3101998791f1a",
|
||||
"original_stat": {
|
||||
"gid": 30037,
|
||||
"mtime": 1533967367,
|
||||
"size": 4537,
|
||||
"uid": 12425
|
||||
},
|
||||
"rel_path": "components/com_users/models/remind.php",
|
||||
"result": "quarantined",
|
||||
"timestamp": "20260718T160204Z",
|
||||
"vhost": "www.archlinexp.eu"
|
||||
}
|
||||
@ -0,0 +1,523 @@
|
||||
<?php
|
||||
/**
|
||||
* @package Joomla.Site
|
||||
* @subpackage com_users
|
||||
*
|
||||
* @copyright Copyright (C) 2005 - 2018 Open Source Matters, Inc. All rights reserved.
|
||||
* @license GNU General Public License version 2 or later; see LICENSE.txt
|
||||
*/
|
||||
|
||||
defined('_JEXEC') or die;
|
||||
|
||||
/**
|
||||
* Rest model class for Users.
|
||||
*
|
||||
* @since 1.5
|
||||
*/
|
||||
class UsersModelReset extends JModelForm
|
||||
{
|
||||
/**
|
||||
* Method to get the password reset request form.
|
||||
*
|
||||
* The base form is loaded from XML and then an event is fired
|
||||
* for users plugins to extend the form with extra fields.
|
||||
*
|
||||
* @param array $data An optional array of data for the form to interogate.
|
||||
* @param boolean $loadData True if the form is to load its own data (default case), false if not.
|
||||
*
|
||||
* @return JForm A JForm object on success, false on failure
|
||||
*
|
||||
* @since 1.6
|
||||
*/
|
||||
public function getForm($data = array(), $loadData = true)
|
||||
{
|
||||
// Get the form.
|
||||
$form = $this->loadForm('com_users.reset_request', 'reset_request', array('control' => 'jform', 'load_data' => $loadData));
|
||||
|
||||
if (empty($form))
|
||||
{
|
||||
return false;
|
||||
}
|
||||
|
||||
return $form;
|
||||
}
|
||||
|
||||
/**
|
||||
* Method to get the password reset complete form.
|
||||
*
|
||||
* @param array $data Data for the form.
|
||||
* @param boolean $loadData True if the form is to load its own data (default case), false if not.
|
||||
*
|
||||
* @return JForm A JForm object on success, false on failure
|
||||
*
|
||||
* @since 1.6
|
||||
*/
|
||||
public function getResetCompleteForm($data = array(), $loadData = true)
|
||||
{
|
||||
// Get the form.
|
||||
$form = $this->loadForm('com_users.reset_complete', 'reset_complete', $options = array('control' => 'jform'));
|
||||
|
||||
if (empty($form))
|
||||
{
|
||||
return false;
|
||||
}
|
||||
|
||||
return $form;
|
||||
}
|
||||
|
||||
/**
|
||||
* Method to get the password reset confirm form.
|
||||
*
|
||||
* @param array $data Data for the form.
|
||||
* @param boolean $loadData True if the form is to load its own data (default case), false if not.
|
||||
*
|
||||
* @return JForm A JForm object on success, false on failure
|
||||
*
|
||||
* @since 1.6
|
||||
*/
|
||||
public function getResetConfirmForm($data = array(), $loadData = true)
|
||||
{
|
||||
// Get the form.
|
||||
$form = $this->loadForm('com_users.reset_confirm', 'reset_confirm', $options = array('control' => 'jform'));
|
||||
|
||||
if (empty($form))
|
||||
{
|
||||
return false;
|
||||
}
|
||||
else
|
||||
{
|
||||
$form->setValue('token', '', JFactory::getApplication()->input->get('token'));
|
||||
}
|
||||
|
||||
return $form;
|
||||
}
|
||||
|
||||
/**
|
||||
* Override preprocessForm to load the user plugin group instead of content.
|
||||
*
|
||||
* @param JForm $form A JForm object.
|
||||
* @param mixed $data The data expected for the form.
|
||||
* @param string $group The name of the plugin group to import (defaults to "content").
|
||||
*
|
||||
* @return void
|
||||
*
|
||||
* @throws Exception if there is an error in the form event.
|
||||
*
|
||||
* @since 1.6
|
||||
*/
|
||||
protected function preprocessForm(JForm $form, $data, $group = 'user')
|
||||
{
|
||||
parent::preprocessForm($form, $data, $group);
|
||||
}
|
||||
|
||||
/**
|
||||
* Method to auto-populate the model state.
|
||||
*
|
||||
* Note. Calling getState in this method will result in recursion.
|
||||
*
|
||||
* @return void
|
||||
*
|
||||
* @since 1.6
|
||||
*/
|
||||
protected function populateState()
|
||||
{
|
||||
// Get the application object.
|
||||
$params = JFactory::getApplication()->getParams('com_users');
|
||||
|
||||
// Load the parameters.
|
||||
$this->setState('params', $params);
|
||||
}
|
||||
|
||||
/**
|
||||
* Save the new password after reset is done
|
||||
*
|
||||
* @param array $data The data expected for the form.
|
||||
*
|
||||
* @return mixed Exception | JException | boolean
|
||||
*
|
||||
* @since 1.6
|
||||
*/
|
||||
public function processResetComplete($data)
|
||||
{
|
||||
// Get the form.
|
||||
$form = $this->getResetCompleteForm();
|
||||
$data['email'] = JStringPunycode::emailToPunycode($data['email']);
|
||||
|
||||
// Check for an error.
|
||||
if ($form instanceof Exception)
|
||||
{
|
||||
return $form;
|
||||
}
|
||||
|
||||
// Filter and validate the form data.
|
||||
$data = $form->filter($data);
|
||||
$return = $form->validate($data);
|
||||
|
||||
// Check for an error.
|
||||
if ($return instanceof Exception)
|
||||
{
|
||||
return $return;
|
||||
}
|
||||
|
||||
// Check the validation results.
|
||||
if ($return === false)
|
||||
{
|
||||
// Get the validation messages from the form.
|
||||
foreach ($form->getErrors() as $formError)
|
||||
{
|
||||
$this->setError($formError->getMessage());
|
||||
}
|
||||
|
||||
return false;
|
||||
}
|
||||
|
||||
// Get the token and user id from the confirmation process.
|
||||
$app = JFactory::getApplication();
|
||||
$token = $app->getUserState('com_users.reset.token', null);
|
||||
$userId = $app->getUserState('com_users.reset.user', null);
|
||||
|
||||
// Check the token and user id.
|
||||
if (empty($token) || empty($userId))
|
||||
{
|
||||
return new JException(JText::_('COM_USERS_RESET_COMPLETE_TOKENS_MISSING'), 403);
|
||||
}
|
||||
|
||||
// Get the user object.
|
||||
$user = JUser::getInstance($userId);
|
||||
|
||||
// Check for a user and that the tokens match.
|
||||
if (empty($user) || $user->activation !== $token)
|
||||
{
|
||||
$this->setError(JText::_('COM_USERS_USER_NOT_FOUND'));
|
||||
|
||||
return false;
|
||||
}
|
||||
|
||||
// Make sure the user isn't blocked.
|
||||
if ($user->block)
|
||||
{
|
||||
$this->setError(JText::_('COM_USERS_USER_BLOCKED'));
|
||||
|
||||
return false;
|
||||
}
|
||||
|
||||
// Check if the user is reusing the current password if required to reset their password
|
||||
if ($user->requireReset == 1 && JUserHelper::verifyPassword($data['password1'], $user->password))
|
||||
{
|
||||
$this->setError(JText::_('JLIB_USER_ERROR_CANNOT_REUSE_PASSWORD'));
|
||||
|
||||
return false;
|
||||
}
|
||||
|
||||
// Update the user object.
|
||||
$user->password = JUserHelper::hashPassword($data['password1']);
|
||||
$user->activation = '';
|
||||
$user->password_clear = $data['password1'];
|
||||
|
||||
// Save the user to the database.
|
||||
if (!$user->save(true))
|
||||
{
|
||||
return new JException(JText::sprintf('COM_USERS_USER_SAVE_FAILED', $user->getError()), 500);
|
||||
}
|
||||
|
||||
// Flush the user data from the session.
|
||||
$app->setUserState('com_users.reset.token', null);
|
||||
$app->setUserState('com_users.reset.user', null);
|
||||
|
||||
return true;
|
||||
}
|
||||
|
||||
/**
|
||||
* Receive the reset password request
|
||||
*
|
||||
* @param array $data The data expected for the form.
|
||||
*
|
||||
* @return mixed Exception | JException | boolean
|
||||
*
|
||||
* @since 1.6
|
||||
*/
|
||||
public function processResetConfirm($data)
|
||||
{
|
||||
// Get the form.
|
||||
$form = $this->getResetConfirmForm();
|
||||
$data['email'] = JStringPunycode::emailToPunycode($data['email']);
|
||||
|
||||
// Check for an error.
|
||||
if ($form instanceof Exception)
|
||||
{
|
||||
return $form;
|
||||
}
|
||||
|
||||
// Filter and validate the form data.
|
||||
$data = $form->filter($data);
|
||||
$return = $form->validate($data);
|
||||
|
||||
// Check for an error.
|
||||
if ($return instanceof Exception)
|
||||
{
|
||||
return $return;
|
||||
}
|
||||
|
||||
// Check the validation results.
|
||||
if ($return === false)
|
||||
{
|
||||
// Get the validation messages from the form.
|
||||
foreach ($form->getErrors() as $formError)
|
||||
{
|
||||
$this->setError($formError->getMessage());
|
||||
}
|
||||
|
||||
return false;
|
||||
}
|
||||
|
||||
// Find the user id for the given token.
|
||||
$db = $this->getDbo();
|
||||
$query = $db->getQuery(true)
|
||||
->select('activation')
|
||||
->select('id')
|
||||
->select('block')
|
||||
->from($db->quoteName('#__users'))
|
||||
->where($db->quoteName('username') . ' = ' . $db->quote($data['username']));
|
||||
|
||||
// Get the user id.
|
||||
$db->setQuery($query);
|
||||
|
||||
try
|
||||
{
|
||||
$user = $db->loadObject();
|
||||
}
|
||||
catch (RuntimeException $e)
|
||||
{
|
||||
return new JException(JText::sprintf('COM_USERS_DATABASE_ERROR', $e->getMessage()), 500);
|
||||
}
|
||||
|
||||
// Check for a user.
|
||||
if (empty($user))
|
||||
{
|
||||
$this->setError(JText::_('COM_USERS_USER_NOT_FOUND'));
|
||||
|
||||
return false;
|
||||
}
|
||||
|
||||
if (!$user->activation)
|
||||
{
|
||||
$this->setError(JText::_('COM_USERS_USER_NOT_FOUND'));
|
||||
|
||||
return false;
|
||||
}
|
||||
|
||||
// Verify the token
|
||||
if (!JUserHelper::verifyPassword($data['token'], $user->activation))
|
||||
{
|
||||
$this->setError(JText::_('COM_USERS_USER_NOT_FOUND'));
|
||||
|
||||
return false;
|
||||
}
|
||||
|
||||
// Make sure the user isn't blocked.
|
||||
if ($user->block)
|
||||
{
|
||||
$this->setError(JText::_('COM_USERS_USER_BLOCKED'));
|
||||
|
||||
return false;
|
||||
}
|
||||
|
||||
// Push the user data into the session.
|
||||
$app = JFactory::getApplication();
|
||||
$app->setUserState('com_users.reset.token', $user->activation);
|
||||
$app->setUserState('com_users.reset.user', $user->id);
|
||||
|
||||
return true;
|
||||
}
|
||||
|
||||
/**
|
||||
* Method to start the password reset process.
|
||||
*
|
||||
* @param array $data The data expected for the form.
|
||||
*
|
||||
* @return mixed Exception | JException | boolean
|
||||
*
|
||||
* @since 1.6
|
||||
*/
|
||||
public function processResetRequest($data)
|
||||
{
|
||||
$config = JFactory::getConfig();
|
||||
|
||||
// Get the form.
|
||||
$form = $this->getForm();
|
||||
|
||||
$data['email'] = JStringPunycode::emailToPunycode($data['email']);
|
||||
|
||||
// Check for an error.
|
||||
if ($form instanceof Exception)
|
||||
{
|
||||
return $form;
|
||||
}
|
||||
|
||||
// Filter and validate the form data.
|
||||
$data = $form->filter($data);
|
||||
$return = $form->validate($data);
|
||||
|
||||
// Check for an error.
|
||||
if ($return instanceof Exception)
|
||||
{
|
||||
return $return;
|
||||
}
|
||||
|
||||
// Check the validation results.
|
||||
if ($return === false)
|
||||
{
|
||||
// Get the validation messages from the form.
|
||||
foreach ($form->getErrors() as $formError)
|
||||
{
|
||||
$this->setError($formError->getMessage());
|
||||
}
|
||||
|
||||
return false;
|
||||
}
|
||||
|
||||
// Find the user id for the given email address.
|
||||
$db = $this->getDbo();
|
||||
$query = $db->getQuery(true)
|
||||
->select('id')
|
||||
->from($db->quoteName('#__users'))
|
||||
->where($db->quoteName('email') . ' = ' . $db->quote($data['email']));
|
||||
|
||||
// Get the user object.
|
||||
$db->setQuery($query);
|
||||
|
||||
try
|
||||
{
|
||||
$userId = $db->loadResult();
|
||||
}
|
||||
catch (RuntimeException $e)
|
||||
{
|
||||
$this->setError(JText::sprintf('COM_USERS_DATABASE_ERROR', $e->getMessage()), 500);
|
||||
|
||||
return false;
|
||||
}
|
||||
|
||||
// Check for a user.
|
||||
if (empty($userId))
|
||||
{
|
||||
$this->setError(JText::_('COM_USERS_INVALID_EMAIL'));
|
||||
|
||||
return false;
|
||||
}
|
||||
|
||||
// Get the user object.
|
||||
$user = JUser::getInstance($userId);
|
||||
|
||||
// Make sure the user isn't blocked.
|
||||
if ($user->block)
|
||||
{
|
||||
$this->setError(JText::_('COM_USERS_USER_BLOCKED'));
|
||||
|
||||
return false;
|
||||
}
|
||||
|
||||
// Make sure the user isn't a Super Admin.
|
||||
if ($user->authorise('core.admin'))
|
||||
{
|
||||
$this->setError(JText::_('COM_USERS_REMIND_SUPERADMIN_ERROR'));
|
||||
|
||||
return false;
|
||||
}
|
||||
|
||||
// Make sure the user has not exceeded the reset limit
|
||||
if (!$this->checkResetLimit($user))
|
||||
{
|
||||
$resetLimit = (int) JFactory::getApplication()->getParams()->get('reset_time');
|
||||
$this->setError(JText::plural('COM_USERS_REMIND_LIMIT_ERROR_N_HOURS', $resetLimit));
|
||||
|
||||
return false;
|
||||
}
|
||||
|
||||
// Set the confirmation token.
|
||||
$token = JApplicationHelper::getHash(JUserHelper::genRandomPassword());
|
||||
$hashedToken = JUserHelper::hashPassword($token);
|
||||
|
||||
$user->activation = $hashedToken;
|
||||
|
||||
// Save the user to the database.
|
||||
if (!$user->save(true))
|
||||
{
|
||||
return new JException(JText::sprintf('COM_USERS_USER_SAVE_FAILED', $user->getError()), 500);
|
||||
}
|
||||
|
||||
// Assemble the password reset confirmation link.
|
||||
$mode = $config->get('force_ssl', 0) == 2 ? 1 : (-1);
|
||||
$link = 'index.php?option=com_users&view=reset&layout=confirm&token=' . $token;
|
||||
|
||||
// Put together the email template data.
|
||||
$data = $user->getProperties();
|
||||
$data['fromname'] = $config->get('fromname');
|
||||
$data['mailfrom'] = $config->get('mailfrom');
|
||||
$data['sitename'] = $config->get('sitename');
|
||||
$data['link_text'] = JRoute::_($link, false, $mode);
|
||||
$data['link_html'] = JRoute::_($link, true, $mode);
|
||||
$data['token'] = $token;
|
||||
|
||||
$subject = JText::sprintf(
|
||||
'COM_USERS_EMAIL_PASSWORD_RESET_SUBJECT',
|
||||
$data['sitename']
|
||||
);
|
||||
|
||||
$body = JText::sprintf(
|
||||
'COM_USERS_EMAIL_PASSWORD_RESET_BODY',
|
||||
$data['sitename'],
|
||||
$data['token'],
|
||||
$data['link_text']
|
||||
);
|
||||
|
||||
// Send the password reset request email.
|
||||
$return = JFactory::getMailer()->sendMail($data['mailfrom'], $data['fromname'], $user->email, $subject, $body);
|
||||
|
||||
// Check for an error.
|
||||
if ($return !== true)
|
||||
{
|
||||
return new JException(JText::_('COM_USERS_MAIL_FAILED'), 500);
|
||||
}
|
||||
|
||||
return true;
|
||||
}
|
||||
|
||||
/**
|
||||
* Method to check if user reset limit has been exceeded within the allowed time period.
|
||||
*
|
||||
* @param JUser $user User doing the password reset
|
||||
*
|
||||
* @return boolean true if user can do the reset, false if limit exceeded
|
||||
*
|
||||
* @since 2.5
|
||||
*/
|
||||
public function checkResetLimit($user)
|
||||
{
|
||||
$params = JFactory::getApplication()->getParams();
|
||||
$maxCount = (int) $params->get('reset_count');
|
||||
$resetHours = (int) $params->get('reset_time');
|
||||
$result = true;
|
||||
|
||||
$lastResetTime = strtotime($user->lastResetTime) ?: 0;
|
||||
$hoursSinceLastReset = (strtotime(JFactory::getDate()->toSql()) - $lastResetTime) / 3600;
|
||||
|
||||
if ($hoursSinceLastReset > $resetHours)
|
||||
{
|
||||
// If it's been long enough, start a new reset count
|
||||
$user->lastResetTime = JFactory::getDate()->toSql();
|
||||
$user->resetCount = 1;
|
||||
}
|
||||
elseif ($user->resetCount < $maxCount)
|
||||
{
|
||||
// If we are under the max count, just increment the counter
|
||||
++$user->resetCount;
|
||||
}
|
||||
else
|
||||
{
|
||||
// At this point, we know we have exceeded the maximum resets for the time period
|
||||
$result = false;
|
||||
}
|
||||
|
||||
return $result;
|
||||
}
|
||||
}
|
||||
@ -0,0 +1,15 @@
|
||||
{
|
||||
"finding_ref": "7274",
|
||||
"log_excerpt": "[quarantine] www.archlinexp.eu:components/com_users/models/reset.php -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/components/com_users/models/reset.php)",
|
||||
"original_sha256": "f948b6a494c8fe051b43bff9f12801d462e4d22f37607da2c5b3b6a7886dcd72",
|
||||
"original_stat": {
|
||||
"gid": 30037,
|
||||
"mtime": 1533967367,
|
||||
"size": 12692,
|
||||
"uid": 12425
|
||||
},
|
||||
"rel_path": "components/com_users/models/reset.php",
|
||||
"result": "quarantined",
|
||||
"timestamp": "20260718T160204Z",
|
||||
"vhost": "www.archlinexp.eu"
|
||||
}
|
||||
@ -0,0 +1,56 @@
|
||||
<?php
|
||||
/**
|
||||
* @package Joomla.Site
|
||||
* @subpackage com_users
|
||||
*
|
||||
* @copyright Copyright (C) 2005 - 2018 Open Source Matters, Inc. All rights reserved.
|
||||
* @license GNU General Public License version 2 or later; see LICENSE.txt
|
||||
*/
|
||||
|
||||
defined('JPATH_PLATFORM') or die;
|
||||
|
||||
use Joomla\Registry\Registry;
|
||||
|
||||
/**
|
||||
* JFormRule for com_users to be sure only one redirect login field has a value
|
||||
*
|
||||
* @since 3.6
|
||||
*/
|
||||
class JFormRuleLoginUniqueField extends JFormRule
|
||||
{
|
||||
/**
|
||||
* Method to test if two fields have a value in order to use only one field.
|
||||
* To use this rule, the form
|
||||
* XML needs a validate attribute of loginuniquefield and a field attribute
|
||||
* that is equal to the field to test against.
|
||||
*
|
||||
* @param SimpleXMLElement $element The SimpleXMLElement object representing the `<field>` tag for the form field object.
|
||||
* @param mixed $value The form field value to validate.
|
||||
* @param string $group The field name group control value. This acts as an array container for the field.
|
||||
* For example if the field has name="foo" and the group value is set to "bar" then the
|
||||
* full field name would end up being "bar[foo]".
|
||||
* @param Registry $input An optional Registry object with the entire data set to validate against the entire form.
|
||||
* @param JForm $form The form object for which the field is being tested.
|
||||
*
|
||||
* @return boolean True if the value is valid, false otherwise.
|
||||
*
|
||||
* @since 3.6
|
||||
*/
|
||||
public function test(SimpleXMLElement $element, $value, $group = null, Registry $input = null, JForm $form = null)
|
||||
{
|
||||
$loginRedirectUrl = $input['params']->login_redirect_url;
|
||||
$loginRedirectMenuitem = $input['params']->login_redirect_menuitem;
|
||||
|
||||
if ($form === null)
|
||||
{
|
||||
throw new InvalidArgumentException(sprintf('The value for $form must not be null in %s', get_class($this)));
|
||||
}
|
||||
|
||||
if ($input === null)
|
||||
{
|
||||
throw new InvalidArgumentException(sprintf('The value for $input must not be null in %s', get_class($this)));
|
||||
}
|
||||
|
||||
return true;
|
||||
}
|
||||
}
|
||||
@ -0,0 +1,15 @@
|
||||
{
|
||||
"finding_ref": "7279",
|
||||
"log_excerpt": "[quarantine] www.archlinexp.eu:components/com_users/models/rules/loginuniquefield.php -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/components/com_users/models/rules/loginuniquefield.php)",
|
||||
"original_sha256": "70dfe2a0662c32f12e612c1d5785006673319ec19766651ab15aefb880a2c5f2",
|
||||
"original_stat": {
|
||||
"gid": 30037,
|
||||
"mtime": 1533967367,
|
||||
"size": 2134,
|
||||
"uid": 12425
|
||||
},
|
||||
"rel_path": "components/com_users/models/rules/loginuniquefield.php",
|
||||
"result": "quarantined",
|
||||
"timestamp": "20260718T160204Z",
|
||||
"vhost": "www.archlinexp.eu"
|
||||
}
|
||||
@ -0,0 +1,56 @@
|
||||
<?php
|
||||
/**
|
||||
* @package Joomla.Site
|
||||
* @subpackage com_users
|
||||
*
|
||||
* @copyright Copyright (C) 2005 - 2018 Open Source Matters, Inc. All rights reserved.
|
||||
* @license GNU General Public License version 2 or later; see LICENSE.txt
|
||||
*/
|
||||
|
||||
defined('JPATH_PLATFORM') or die;
|
||||
|
||||
use Joomla\Registry\Registry;
|
||||
|
||||
/**
|
||||
* JFormRule for com_users to be sure only one redirect logout field has a value
|
||||
*
|
||||
* @since 3.6
|
||||
*/
|
||||
class JFormRuleLogoutUniqueField extends JFormRule
|
||||
{
|
||||
/**
|
||||
* Method to test if two fields have a value in order to use only one field.
|
||||
* To use this rule, the form
|
||||
* XML needs a validate attribute of logoutuniquefield and a field attribute
|
||||
* that is equal to the field to test against.
|
||||
*
|
||||
* @param SimpleXMLElement $element The SimpleXMLElement object representing the `<field>` tag for the form field object.
|
||||
* @param mixed $value The form field value to validate.
|
||||
* @param string $group The field name group control value. This acts as an array container for the field.
|
||||
* For example if the field has name="foo" and the group value is set to "bar" then the
|
||||
* full field name would end up being "bar[foo]".
|
||||
* @param Registry $input An optional Registry object with the entire data set to validate against the entire form.
|
||||
* @param JForm $form The form object for which the field is being tested.
|
||||
*
|
||||
* @return boolean True if the value is valid, false otherwise.
|
||||
*
|
||||
* @since 3.6
|
||||
*/
|
||||
public function test(SimpleXMLElement $element, $value, $group = null, Registry $input = null, JForm $form = null)
|
||||
{
|
||||
$logoutRedirectUrl = $input['params']->logout_redirect_url;
|
||||
$logoutRedirectMenuitem = $input['params']->logout_redirect_menuitem;
|
||||
|
||||
if ($form === null)
|
||||
{
|
||||
throw new InvalidArgumentException(sprintf('The value for $form must not be null in %s', get_class($this)));
|
||||
}
|
||||
|
||||
if ($input === null)
|
||||
{
|
||||
throw new InvalidArgumentException(sprintf('The value for $input must not be null in %s', get_class($this)));
|
||||
}
|
||||
|
||||
return true;
|
||||
}
|
||||
}
|
||||
@ -0,0 +1,15 @@
|
||||
{
|
||||
"finding_ref": "7280",
|
||||
"log_excerpt": "[quarantine] www.archlinexp.eu:components/com_users/models/rules/logoutuniquefield.php -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/components/com_users/models/rules/logoutuniquefield.php)",
|
||||
"original_sha256": "9bc602cb398ce792eafb70d3cba2fa732d6bffeb2bf88afc05de9e507334c095",
|
||||
"original_stat": {
|
||||
"gid": 30037,
|
||||
"mtime": 1533967367,
|
||||
"size": 2139,
|
||||
"uid": 12425
|
||||
},
|
||||
"rel_path": "components/com_users/models/rules/logoutuniquefield.php",
|
||||
"result": "quarantined",
|
||||
"timestamp": "20260718T160204Z",
|
||||
"vhost": "www.archlinexp.eu"
|
||||
}
|
||||
@ -0,0 +1,89 @@
|
||||
<?php
|
||||
/**
|
||||
* @package Joomla.Site
|
||||
* @subpackage com_users
|
||||
*
|
||||
* @copyright Copyright (C) 2005 - 2018 Open Source Matters, Inc. All rights reserved.
|
||||
* @license GNU General Public License version 2 or later; see LICENSE.txt
|
||||
*/
|
||||
|
||||
defined('_JEXEC') or die;
|
||||
|
||||
/**
|
||||
* Routing class from com_users
|
||||
*
|
||||
* @since 3.2
|
||||
*/
|
||||
class UsersRouter extends JComponentRouterView
|
||||
{
|
||||
/**
|
||||
* Users Component router constructor
|
||||
*
|
||||
* @param JApplicationCms $app The application object
|
||||
* @param JMenu $menu The menu object to work with
|
||||
*/
|
||||
public function __construct($app = null, $menu = null)
|
||||
{
|
||||
$this->registerView(new JComponentRouterViewconfiguration('login'));
|
||||
$profile = new JComponentRouterViewconfiguration('profile');
|
||||
$profile->addLayout('edit');
|
||||
$this->registerView($profile);
|
||||
$this->registerView(new JComponentRouterViewconfiguration('registration'));
|
||||
$this->registerView(new JComponentRouterViewconfiguration('remind'));
|
||||
$this->registerView(new JComponentRouterViewconfiguration('reset'));
|
||||
|
||||
parent::__construct($app, $menu);
|
||||
|
||||
$this->attachRule(new JComponentRouterRulesMenu($this));
|
||||
|
||||
$params = JComponentHelper::getParams('com_users');
|
||||
|
||||
if ($params->get('sef_advanced', 0))
|
||||
{
|
||||
$this->attachRule(new JComponentRouterRulesStandard($this));
|
||||
$this->attachRule(new JComponentRouterRulesNomenu($this));
|
||||
}
|
||||
else
|
||||
{
|
||||
JLoader::register('UsersRouterRulesLegacy', __DIR__ . '/helpers/legacyrouter.php');
|
||||
$this->attachRule(new UsersRouterRulesLegacy($this));
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
/**
|
||||
* Users router functions
|
||||
*
|
||||
* These functions are proxys for the new router interface
|
||||
* for old SEF extensions.
|
||||
*
|
||||
* @param array &$query REQUEST query
|
||||
*
|
||||
* @return array Segments of the SEF url
|
||||
*
|
||||
* @deprecated 4.0 Use Class based routers instead
|
||||
*/
|
||||
function usersBuildRoute(&$query)
|
||||
{
|
||||
$app = JFactory::getApplication();
|
||||
$router = new UsersRouter($app, $app->getMenu());
|
||||
|
||||
return $router->build($query);
|
||||
}
|
||||
|
||||
/**
|
||||
* Convert SEF URL segments into query variables
|
||||
*
|
||||
* @param array $segments Segments in the current URL
|
||||
*
|
||||
* @return array Query variables
|
||||
*
|
||||
* @deprecated 4.0 Use Class based routers instead
|
||||
*/
|
||||
function usersParseRoute($segments)
|
||||
{
|
||||
$app = JFactory::getApplication();
|
||||
$router = new UsersRouter($app, $app->getMenu());
|
||||
|
||||
return $router->parse($segments);
|
||||
}
|
||||
@ -0,0 +1,15 @@
|
||||
{
|
||||
"finding_ref": "7253",
|
||||
"log_excerpt": "[quarantine] www.archlinexp.eu:components/com_users/router.php -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/components/com_users/router.php)",
|
||||
"original_sha256": "2b9acf14b84908cd85f8ffface816d5c7124f3226088696dccec501054773253",
|
||||
"original_stat": {
|
||||
"gid": 30037,
|
||||
"mtime": 1533967367,
|
||||
"size": 2326,
|
||||
"uid": 12425
|
||||
},
|
||||
"rel_path": "components/com_users/router.php",
|
||||
"result": "quarantined",
|
||||
"timestamp": "20260718T160204Z",
|
||||
"vhost": "www.archlinexp.eu"
|
||||
}
|
||||
@ -0,0 +1,16 @@
|
||||
<?php
|
||||
/**
|
||||
* @package Joomla.Site
|
||||
* @subpackage com_users
|
||||
*
|
||||
* @copyright Copyright (C) 2005 - 2018 Open Source Matters, Inc. All rights reserved.
|
||||
* @license GNU General Public License version 2 or later; see LICENSE.txt
|
||||
*/
|
||||
|
||||
defined('_JEXEC') or die;
|
||||
|
||||
JLoader::register('UsersHelperRoute', JPATH_COMPONENT . '/helpers/route.php');
|
||||
|
||||
$controller = JControllerLegacy::getInstance('Users');
|
||||
$controller->execute(JFactory::getApplication()->input->get('task', 'display'));
|
||||
$controller->redirect();
|
||||
@ -0,0 +1,15 @@
|
||||
{
|
||||
"finding_ref": "7251",
|
||||
"log_excerpt": "[quarantine] www.archlinexp.eu:components/com_users/users.php -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/components/com_users/users.php)",
|
||||
"original_sha256": "6ed1fd07fc85fc4f09fd85926ce729ad711577f7cc3ceaf551c748b07dd2ae5c",
|
||||
"original_stat": {
|
||||
"gid": 30037,
|
||||
"mtime": 1533967367,
|
||||
"size": 508,
|
||||
"uid": 12425
|
||||
},
|
||||
"rel_path": "components/com_users/users.php",
|
||||
"result": "quarantined",
|
||||
"timestamp": "20260718T160204Z",
|
||||
"vhost": "www.archlinexp.eu"
|
||||
}
|
||||
@ -0,0 +1,23 @@
|
||||
<?php
|
||||
/**
|
||||
* @package Joomla.Site
|
||||
* @subpackage com_users
|
||||
*
|
||||
* @copyright Copyright (C) 2005 - 2018 Open Source Matters, Inc. All rights reserved.
|
||||
* @license GNU General Public License version 2 or later; see LICENSE.txt
|
||||
*/
|
||||
|
||||
defined('_JEXEC') or die;
|
||||
|
||||
$cookieLogin = $this->user->get('cookieLogin');
|
||||
|
||||
if (!empty($cookieLogin) || $this->user->get('guest'))
|
||||
{
|
||||
// The user is not logged in or needs to provide a password.
|
||||
echo $this->loadTemplate('login');
|
||||
}
|
||||
else
|
||||
{
|
||||
// The user is already logged in.
|
||||
echo $this->loadTemplate('logout');
|
||||
}
|
||||
@ -0,0 +1,15 @@
|
||||
{
|
||||
"finding_ref": "7269",
|
||||
"log_excerpt": "[quarantine] www.archlinexp.eu:components/com_users/views/login/tmpl/default.php -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/components/com_users/views/login/tmpl/default.php)",
|
||||
"original_sha256": "8dac9ace51133f1eea7a524ca6dd8de9fc5effedd7c5bb2b5f5562ccd2257efc",
|
||||
"original_stat": {
|
||||
"gid": 30037,
|
||||
"mtime": 1552900021,
|
||||
"size": 554,
|
||||
"uid": 12425
|
||||
},
|
||||
"rel_path": "components/com_users/views/login/tmpl/default.php",
|
||||
"result": "quarantined",
|
||||
"timestamp": "20260718T160204Z",
|
||||
"vhost": "www.archlinexp.eu"
|
||||
}
|
||||
@ -0,0 +1,166 @@
|
||||
<?xml version="1.0" encoding="utf-8"?>
|
||||
<metadata>
|
||||
<layout title="com_user_login_view_default_title" option="com_user_login_view_default_option">
|
||||
<help
|
||||
key = "JHELP_MENUS_MENU_ITEM_USER_LOGIN"
|
||||
/>
|
||||
<message>
|
||||
<![CDATA[COM_USER_LOGIN_VIEW_DEFAULT_DESC]]>
|
||||
</message>
|
||||
</layout>
|
||||
|
||||
<!-- Add fields to the parameters object for the layout. -->
|
||||
<fields name="params">
|
||||
|
||||
<!-- Basic options. -->
|
||||
<fieldset name="basic" addrulepath="components/com_users/models/rules" label="COM_MENUS_BASIC_FIELDSET_LABEL">
|
||||
|
||||
<field
|
||||
name="loginredirectchoice"
|
||||
type="radio"
|
||||
label="COM_USERS_FIELD_LOGIN_REDIRECT_CHOICE_LABEL"
|
||||
description="COM_USERS_FIELD_LOGIN_REDIRECT_CHOICE_DESC"
|
||||
class="btn-group btn-group-yesno"
|
||||
default="1"
|
||||
>
|
||||
<option value="1">COM_USERS_FIELD_LOGIN_MENUITEM</option>
|
||||
<option value="0">COM_USERS_FIELD_LOGIN_URL</option>
|
||||
</field>
|
||||
|
||||
<field
|
||||
name="login_redirect_url"
|
||||
type="text"
|
||||
label="JFIELD_LOGIN_REDIRECT_URL_LABEL"
|
||||
description="JFIELD_LOGIN_REDIRECT_URL_DESC"
|
||||
class="inputbox"
|
||||
validate="loginuniquefield"
|
||||
field="login_redirect_menuitem"
|
||||
hint="COM_USERS_FIELD_LOGIN_REDIRECT_PLACEHOLDER"
|
||||
message="COM_USERS_FIELD_LOGIN_REDIRECT_ERROR"
|
||||
showon="loginredirectchoice:0"
|
||||
/>
|
||||
|
||||
<field
|
||||
name="login_redirect_menuitem"
|
||||
type="modal_menu"
|
||||
label="COM_USERS_FIELD_LOGIN_REDIRECTMENU_LABEL"
|
||||
description="COM_USERS_FIELD_LOGIN_REDIRECTMENU_DESC"
|
||||
disable="separator,alias,heading,url"
|
||||
showon="loginredirectchoice:1"
|
||||
select="true"
|
||||
new="true"
|
||||
edit="true"
|
||||
clear="true"
|
||||
>
|
||||
<option value="">JDEFAULT</option>
|
||||
</field>
|
||||
|
||||
<field
|
||||
name="logindescription_show"
|
||||
type="list"
|
||||
label="JFIELD_BASIS_LOGIN_DESCRIPTION_SHOW_LABEL"
|
||||
description="JFIELD_BASIS_LOGIN_DESCRIPTION_SHOW_DESC"
|
||||
default="1"
|
||||
class="chzn-color"
|
||||
>
|
||||
<option value="0">JHIDE</option>
|
||||
<option value="1">JSHOW</option>
|
||||
</field>
|
||||
|
||||
<field
|
||||
name="login_description"
|
||||
type="textarea"
|
||||
label="JFIELD_BASIS_LOGIN_DESCRIPTION_LABEL"
|
||||
description="JFIELD_BASIS_LOGIN_DESCRIPTION_DESC"
|
||||
rows="3"
|
||||
cols="40"
|
||||
filter="safehtml"
|
||||
showon="logindescription_show:1"
|
||||
/>
|
||||
|
||||
<field
|
||||
name="login_image"
|
||||
type="media"
|
||||
label="JFIELD_LOGIN_IMAGE_LABEL"
|
||||
description="JFIELD_LOGIN_IMAGE_DESC"
|
||||
/>
|
||||
|
||||
<field
|
||||
name="spacer1"
|
||||
type="spacer"
|
||||
hr="true"
|
||||
/>
|
||||
|
||||
<field
|
||||
name="logoutredirectchoice"
|
||||
type="radio"
|
||||
label="COM_USERS_FIELD_LOGOUT_REDIRECT_CHOICE_LABEL"
|
||||
description="COM_USERS_FIELD_LOGIN_REDIRECT_CHOICE_DESC"
|
||||
class="btn-group btn-group-yesno"
|
||||
default="1"
|
||||
>
|
||||
<option value="1">COM_USERS_FIELD_LOGIN_MENUITEM</option>
|
||||
<option value="0">COM_USERS_FIELD_LOGIN_URL</option>
|
||||
</field>
|
||||
|
||||
<field
|
||||
name="logout_redirect_url"
|
||||
type="text"
|
||||
label="JFIELD_LOGOUT_REDIRECT_URL_LABEL"
|
||||
description="JFIELD_LOGOUT_REDIRECT_URL_DESC"
|
||||
class="inputbox"
|
||||
field="logout_redirect_menuitem"
|
||||
validate="logoutuniquefield"
|
||||
hint="COM_USERS_FIELD_LOGIN_REDIRECT_PLACEHOLDER"
|
||||
message="COM_USERS_FIELD_LOGOUT_REDIRECT_ERROR"
|
||||
showon="logoutredirectchoice:0"
|
||||
/>
|
||||
|
||||
<field
|
||||
name="logout_redirect_menuitem"
|
||||
type="modal_menu"
|
||||
label="COM_USERS_FIELD_LOGOUT_REDIRECTMENU_LABEL"
|
||||
description="COM_USERS_FIELD_LOGOUT_REDIRECTMENU_DESC"
|
||||
disable="separator,alias,heading,url"
|
||||
showon="logoutredirectchoice:1"
|
||||
select="true"
|
||||
new="true"
|
||||
edit="true"
|
||||
clear="true"
|
||||
>
|
||||
<option value="">JDEFAULT</option>
|
||||
</field>
|
||||
|
||||
<field
|
||||
name="logoutdescription_show"
|
||||
type="list"
|
||||
label="JFIELD_BASIS_LOGOUT_DESCRIPTION_SHOW_LABEL"
|
||||
description="JFIELD_BASIS_LOGOUT_DESCRIPTION_SHOW_DESC"
|
||||
default="1"
|
||||
class="chzn-color"
|
||||
>
|
||||
<option value="0">JHIDE</option>
|
||||
<option value="1">JSHOW</option>
|
||||
</field>
|
||||
|
||||
<field
|
||||
name="logout_description"
|
||||
type="textarea"
|
||||
label="JFIELD_BASIS_LOGOUT_DESCRIPTION_LABEL"
|
||||
description="JFIELD_BASIS_LOGOUT_DESCRIPTION_DESC"
|
||||
rows="3"
|
||||
cols="40"
|
||||
filter="safehtml"
|
||||
showon="logoutdescription_show:1"
|
||||
/>
|
||||
|
||||
<field
|
||||
name="logout_image"
|
||||
type="media"
|
||||
label="JFIELD_LOGOUT_IMAGE_LABEL"
|
||||
description="JFIELD_LOGOUT_IMAGE_DESC"
|
||||
/>
|
||||
|
||||
</fieldset>
|
||||
</fields>
|
||||
</metadata>
|
||||
@ -0,0 +1,15 @@
|
||||
{
|
||||
"finding_ref": "7270",
|
||||
"log_excerpt": "[quarantine] www.archlinexp.eu:components/com_users/views/login/tmpl/default.xml -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/components/com_users/views/login/tmpl/default.xml)",
|
||||
"original_sha256": "1e40888b8d147a0130bca03085edf7f94e97da2ed09e2aa4b6dfe41282162ecc",
|
||||
"original_stat": {
|
||||
"gid": 30037,
|
||||
"mtime": 1533967367,
|
||||
"size": 4166,
|
||||
"uid": 12425
|
||||
},
|
||||
"rel_path": "components/com_users/views/login/tmpl/default.xml",
|
||||
"result": "quarantined",
|
||||
"timestamp": "20260718T160204Z",
|
||||
"vhost": "www.archlinexp.eu"
|
||||
}
|
||||
@ -0,0 +1,106 @@
|
||||
<?php
|
||||
/**
|
||||
* @package Joomla.Site
|
||||
* @subpackage com_users
|
||||
*
|
||||
* @copyright Copyright (C) 2005 - 2018 Open Source Matters, Inc. All rights reserved.
|
||||
* @license GNU General Public License version 2 or later; see LICENSE.txt
|
||||
*/
|
||||
|
||||
defined('_JEXEC') or die;
|
||||
|
||||
JHtml::_('behavior.keepalive');
|
||||
JHtml::_('behavior.formvalidator');
|
||||
|
||||
?>
|
||||
<div class="login<?php echo $this->pageclass_sfx; ?>">
|
||||
<?php if ($this->params->get('show_page_heading')) : ?>
|
||||
<div class="page-header">
|
||||
<h1>
|
||||
<?php echo $this->escape($this->params->get('page_heading')); ?>
|
||||
</h1>
|
||||
</div>
|
||||
<?php endif; ?>
|
||||
<?php if (($this->params->get('logindescription_show') == 1 && str_replace(' ', '', $this->params->get('login_description')) != '') || $this->params->get('login_image') != '') : ?>
|
||||
<div class="login-description">
|
||||
<?php endif; ?>
|
||||
<?php if ($this->params->get('logindescription_show') == 1) : ?>
|
||||
<?php echo $this->params->get('login_description'); ?>
|
||||
<?php endif; ?>
|
||||
<?php if ($this->params->get('login_image') != '') : ?>
|
||||
<img src="<?php echo $this->escape($this->params->get('login_image')); ?>" class="login-image" alt="<?php echo JText::_('COM_USERS_LOGIN_IMAGE_ALT'); ?>" />
|
||||
<?php endif; ?>
|
||||
<?php if (($this->params->get('logindescription_show') == 1 && str_replace(' ', '', $this->params->get('login_description')) != '') || $this->params->get('login_image') != '') : ?>
|
||||
</div>
|
||||
<?php endif; ?>
|
||||
<form action="<?php echo JRoute::_('index.php?option=com_users&task=user.login'); ?>" method="post" class="form-validate form-horizontal well">
|
||||
<fieldset>
|
||||
<?php foreach ($this->form->getFieldset('credentials') as $field) : ?>
|
||||
<?php if (!$field->hidden) : ?>
|
||||
<div class="control-group">
|
||||
<div class="control-label">
|
||||
<?php echo $field->label; ?>
|
||||
</div>
|
||||
<div class="controls">
|
||||
<?php echo $field->input; ?>
|
||||
</div>
|
||||
</div>
|
||||
<?php endif; ?>
|
||||
<?php endforeach; ?>
|
||||
<?php if ($this->tfa) : ?>
|
||||
<div class="control-group">
|
||||
<div class="control-label">
|
||||
<?php echo $this->form->getField('secretkey')->label; ?>
|
||||
</div>
|
||||
<div class="controls">
|
||||
<?php echo $this->form->getField('secretkey')->input; ?>
|
||||
</div>
|
||||
</div>
|
||||
<?php endif; ?>
|
||||
<?php if (JPluginHelper::isEnabled('system', 'remember')) : ?>
|
||||
<div class="control-group">
|
||||
<div class="control-label">
|
||||
<label for="remember">
|
||||
<?php echo JText::_('COM_USERS_LOGIN_REMEMBER_ME'); ?>
|
||||
</label>
|
||||
</div>
|
||||
<div class="controls">
|
||||
<input id="remember" type="checkbox" name="remember" class="inputbox" value="yes" />
|
||||
</div>
|
||||
</div>
|
||||
<?php endif; ?>
|
||||
<div class="control-group">
|
||||
<div class="controls">
|
||||
<button type="submit" class="btn btn-primary">
|
||||
<?php echo JText::_('JLOGIN'); ?>
|
||||
</button>
|
||||
</div>
|
||||
</div>
|
||||
<?php $return = $this->form->getValue('return', '', $this->params->get('login_redirect_url', $this->params->get('login_redirect_menuitem'))); ?>
|
||||
<input type="hidden" name="return" value="<?php echo base64_encode($return); ?>" />
|
||||
<?php echo JHtml::_('form.token'); ?>
|
||||
</fieldset>
|
||||
</form>
|
||||
</div>
|
||||
<div>
|
||||
<ul class="nav nav-tabs nav-stacked">
|
||||
<li>
|
||||
<a href="<?php echo JRoute::_('index.php?option=com_users&view=reset'); ?>">
|
||||
<?php echo JText::_('COM_USERS_LOGIN_RESET'); ?>
|
||||
</a>
|
||||
</li>
|
||||
<li>
|
||||
<a href="<?php echo JRoute::_('index.php?option=com_users&view=remind'); ?>">
|
||||
<?php echo JText::_('COM_USERS_LOGIN_REMIND'); ?>
|
||||
</a>
|
||||
</li>
|
||||
<?php $usersConfig = JComponentHelper::getParams('com_users'); ?>
|
||||
<?php if ($usersConfig->get('allowUserRegistration')) : ?>
|
||||
<li>
|
||||
<a href="<?php echo JRoute::_('index.php?option=com_users&view=registration'); ?>">
|
||||
<?php echo JText::_('COM_USERS_LOGIN_REGISTER'); ?>
|
||||
</a>
|
||||
</li>
|
||||
<?php endif; ?>
|
||||
</ul>
|
||||
</div>
|
||||
@ -0,0 +1,15 @@
|
||||
{
|
||||
"finding_ref": "7271",
|
||||
"log_excerpt": "[quarantine] www.archlinexp.eu:components/com_users/views/login/tmpl/default_login.php -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/components/com_users/views/login/tmpl/default_login.php)",
|
||||
"original_sha256": "f619bd9d8abc8c0b2766659057d744280be80ff87f1705b5c23c9e74a8f6d6ed",
|
||||
"original_stat": {
|
||||
"gid": 30037,
|
||||
"mtime": 1565006708,
|
||||
"size": 3818,
|
||||
"uid": 12425
|
||||
},
|
||||
"rel_path": "components/com_users/views/login/tmpl/default_login.php",
|
||||
"result": "quarantined",
|
||||
"timestamp": "20260718T160204Z",
|
||||
"vhost": "www.archlinexp.eu"
|
||||
}
|
||||
@ -0,0 +1,49 @@
|
||||
<?php
|
||||
/**
|
||||
* @package Joomla.Site
|
||||
* @subpackage com_users
|
||||
*
|
||||
* @copyright Copyright (C) 2005 - 2018 Open Source Matters, Inc. All rights reserved.
|
||||
* @license GNU General Public License version 2 or later; see LICENSE.txt
|
||||
*/
|
||||
|
||||
defined('_JEXEC') or die;
|
||||
|
||||
?>
|
||||
<div class="logout<?php echo $this->pageclass_sfx; ?>">
|
||||
<?php if ($this->params->get('show_page_heading')) : ?>
|
||||
<div class="page-header">
|
||||
<h1>
|
||||
<?php echo $this->escape($this->params->get('page_heading')); ?>
|
||||
</h1>
|
||||
</div>
|
||||
<?php endif; ?>
|
||||
<?php if (($this->params->get('logoutdescription_show') == 1 && str_replace(' ', '', $this->params->get('logout_description')) != '')|| $this->params->get('logout_image') != '') : ?>
|
||||
<div class="logout-description">
|
||||
<?php endif; ?>
|
||||
<?php if ($this->params->get('logoutdescription_show') == 1) : ?>
|
||||
<?php echo $this->params->get('logout_description'); ?>
|
||||
<?php endif; ?>
|
||||
<?php if ($this->params->get('logout_image') != '') : ?>
|
||||
<img src="<?php echo $this->escape($this->params->get('logout_image')); ?>" class="thumbnail pull-right logout-image" alt="<?php echo JText::_('COM_USER_LOGOUT_IMAGE_ALT'); ?>" />
|
||||
<?php endif; ?>
|
||||
<?php if (($this->params->get('logoutdescription_show') == 1 && str_replace(' ', '', $this->params->get('logout_description')) != '')|| $this->params->get('logout_image') != '') : ?>
|
||||
</div>
|
||||
<?php endif; ?>
|
||||
<form action="<?php echo JRoute::_('index.php?option=com_users&task=user.logout'); ?>" method="post" class="form-horizontal well">
|
||||
<div class="control-group">
|
||||
<div class="controls">
|
||||
<button type="submit" class="btn btn-primary">
|
||||
<span class="icon-arrow-left icon-white"></span>
|
||||
<?php echo JText::_('JLOGOUT'); ?>
|
||||
</button>
|
||||
</div>
|
||||
</div>
|
||||
<?php if ($this->params->get('logout_redirect_url')) : ?>
|
||||
<input type="hidden" name="return" value="<?php echo base64_encode($this->params->get('logout_redirect_url', $this->form->getValue('return'))); ?>" />
|
||||
<?php else : ?>
|
||||
<input type="hidden" name="return" value="<?php echo base64_encode($this->params->get('logout_redirect_menuitem', $this->form->getValue('return'))); ?>" />
|
||||
<?php endif; ?>
|
||||
<?php echo JHtml::_('form.token'); ?>
|
||||
</form>
|
||||
</div>
|
||||
@ -0,0 +1,15 @@
|
||||
{
|
||||
"finding_ref": "7268",
|
||||
"log_excerpt": "[quarantine] www.archlinexp.eu:components/com_users/views/login/tmpl/default_logout.php -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/components/com_users/views/login/tmpl/default_logout.php)",
|
||||
"original_sha256": "17b5b52ed420d182ca4d96cdc494e204f3dfe024955ae4d91eaf68537daf1f52",
|
||||
"original_stat": {
|
||||
"gid": 30037,
|
||||
"mtime": 1533967367,
|
||||
"size": 2199,
|
||||
"uid": 12425
|
||||
},
|
||||
"rel_path": "components/com_users/views/login/tmpl/default_logout.php",
|
||||
"result": "quarantined",
|
||||
"timestamp": "20260718T160204Z",
|
||||
"vhost": "www.archlinexp.eu"
|
||||
}
|
||||
@ -0,0 +1,131 @@
|
||||
<?php
|
||||
/**
|
||||
* @package Joomla.Site
|
||||
* @subpackage com_users
|
||||
*
|
||||
* @copyright Copyright (C) 2005 - 2018 Open Source Matters, Inc. All rights reserved.
|
||||
* @license GNU General Public License version 2 or later; see LICENSE.txt
|
||||
*/
|
||||
|
||||
defined('_JEXEC') or die;
|
||||
|
||||
/**
|
||||
* Login view class for Users.
|
||||
*
|
||||
* @since 1.5
|
||||
*/
|
||||
class UsersViewLogin extends JViewLegacy
|
||||
{
|
||||
protected $form;
|
||||
|
||||
protected $params;
|
||||
|
||||
protected $state;
|
||||
|
||||
protected $user;
|
||||
|
||||
/**
|
||||
* Method to display the view.
|
||||
*
|
||||
* @param string $tpl The name of the template file to parse; automatically searches through the template paths.
|
||||
*
|
||||
* @return mixed A string if successful, otherwise an Error object.
|
||||
*
|
||||
* @since 1.5
|
||||
*/
|
||||
public function display($tpl = null)
|
||||
{
|
||||
// Get the view data.
|
||||
$this->user = JFactory::getUser();
|
||||
$this->form = $this->get('Form');
|
||||
$this->state = $this->get('State');
|
||||
$this->params = $this->state->get('params');
|
||||
|
||||
// Check for errors.
|
||||
if (count($errors = $this->get('Errors')))
|
||||
{
|
||||
JError::raiseError(500, implode('<br />', $errors));
|
||||
|
||||
return false;
|
||||
}
|
||||
|
||||
// Check for layout override
|
||||
$active = JFactory::getApplication()->getMenu()->getActive();
|
||||
|
||||
if (isset($active->query['layout']))
|
||||
{
|
||||
$this->setLayout($active->query['layout']);
|
||||
}
|
||||
|
||||
$tfa = JAuthenticationHelper::getTwoFactorMethods();
|
||||
$this->tfa = is_array($tfa) && count($tfa) > 1;
|
||||
|
||||
// Escape strings for HTML output
|
||||
$this->pageclass_sfx = htmlspecialchars($this->params->get('pageclass_sfx'), ENT_COMPAT, 'UTF-8');
|
||||
|
||||
$this->prepareDocument();
|
||||
|
||||
parent::display($tpl);
|
||||
}
|
||||
|
||||
/**
|
||||
* Prepares the document
|
||||
*
|
||||
* @return void
|
||||
*
|
||||
* @since 1.6
|
||||
*/
|
||||
protected function prepareDocument()
|
||||
{
|
||||
$app = JFactory::getApplication();
|
||||
$menus = $app->getMenu();
|
||||
$user = JFactory::getUser();
|
||||
$login = $user->get('guest') ? true : false;
|
||||
$title = null;
|
||||
|
||||
// Because the application sets a default page title,
|
||||
// we need to get it from the menu item itself
|
||||
$menu = $menus->getActive();
|
||||
|
||||
if ($menu)
|
||||
{
|
||||
$this->params->def('page_heading', $this->params->get('page_title', $menu->title));
|
||||
}
|
||||
else
|
||||
{
|
||||
$this->params->def('page_heading', $login ? JText::_('JLOGIN') : JText::_('JLOGOUT'));
|
||||
}
|
||||
|
||||
$title = $this->params->get('page_title', '');
|
||||
|
||||
if (empty($title))
|
||||
{
|
||||
$title = $app->get('sitename');
|
||||
}
|
||||
elseif ($app->get('sitename_pagetitles', 0) == 1)
|
||||
{
|
||||
$title = JText::sprintf('JPAGETITLE', $app->get('sitename'), $title);
|
||||
}
|
||||
elseif ($app->get('sitename_pagetitles', 0) == 2)
|
||||
{
|
||||
$title = JText::sprintf('JPAGETITLE', $title, $app->get('sitename'));
|
||||
}
|
||||
|
||||
$this->document->setTitle($title);
|
||||
|
||||
if ($this->params->get('menu-meta_description'))
|
||||
{
|
||||
$this->document->setDescription($this->params->get('menu-meta_description'));
|
||||
}
|
||||
|
||||
if ($this->params->get('menu-meta_keywords'))
|
||||
{
|
||||
$this->document->setMetadata('keywords', $this->params->get('menu-meta_keywords'));
|
||||
}
|
||||
|
||||
if ($this->params->get('robots'))
|
||||
{
|
||||
$this->document->setMetadata('robots', $this->params->get('robots'));
|
||||
}
|
||||
}
|
||||
}
|
||||
@ -0,0 +1,15 @@
|
||||
{
|
||||
"finding_ref": "7267",
|
||||
"log_excerpt": "[quarantine] www.archlinexp.eu:components/com_users/views/login/view.html.php -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/components/com_users/views/login/view.html.php)",
|
||||
"original_sha256": "81388b133b1d59d485333ab97724d1a1d3616606f055d863da72bc0a9f0fbea3",
|
||||
"original_stat": {
|
||||
"gid": 30037,
|
||||
"mtime": 1533967367,
|
||||
"size": 3040,
|
||||
"uid": 12425
|
||||
},
|
||||
"rel_path": "components/com_users/views/login/view.html.php",
|
||||
"result": "quarantined",
|
||||
"timestamp": "20260718T160204Z",
|
||||
"vhost": "www.archlinexp.eu"
|
||||
}
|
||||
@ -0,0 +1,34 @@
|
||||
<?php
|
||||
/**
|
||||
* @package Joomla.Site
|
||||
* @subpackage com_users
|
||||
*
|
||||
* @copyright Copyright (C) 2005 - 2018 Open Source Matters, Inc. All rights reserved.
|
||||
* @license GNU General Public License version 2 or later; see LICENSE.txt
|
||||
*/
|
||||
|
||||
defined('_JEXEC') or die;
|
||||
|
||||
?>
|
||||
<div class="profile<?php echo $this->pageclass_sfx; ?>">
|
||||
<?php if ($this->params->get('show_page_heading')) : ?>
|
||||
<div class="page-header">
|
||||
<h1>
|
||||
<?php echo $this->escape($this->params->get('page_heading')); ?>
|
||||
</h1>
|
||||
</div>
|
||||
<?php endif; ?>
|
||||
<?php if (JFactory::getUser()->id == $this->data->id) : ?>
|
||||
<ul class="btn-toolbar pull-right">
|
||||
<li class="btn-group">
|
||||
<a class="btn" href="<?php echo JRoute::_('index.php?option=com_users&task=profile.edit&user_id=' . (int) $this->data->id); ?>">
|
||||
<span class="icon-user"></span>
|
||||
<?php echo JText::_('COM_USERS_EDIT_PROFILE'); ?>
|
||||
</a>
|
||||
</li>
|
||||
</ul>
|
||||
<?php endif; ?>
|
||||
<?php echo $this->loadTemplate('core'); ?>
|
||||
<?php echo $this->loadTemplate('params'); ?>
|
||||
<?php echo $this->loadTemplate('custom'); ?>
|
||||
</div>
|
||||
@ -0,0 +1,15 @@
|
||||
{
|
||||
"finding_ref": "7260",
|
||||
"log_excerpt": "[quarantine] www.archlinexp.eu:components/com_users/views/profile/tmpl/default.php -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/components/com_users/views/profile/tmpl/default.php)",
|
||||
"original_sha256": "d4133100827716d2da1eb9c60343fb744f2183367c917139a1767681ac200b17",
|
||||
"original_stat": {
|
||||
"gid": 30037,
|
||||
"mtime": 1533967367,
|
||||
"size": 1059,
|
||||
"uid": 12425
|
||||
},
|
||||
"rel_path": "components/com_users/views/profile/tmpl/default.php",
|
||||
"result": "quarantined",
|
||||
"timestamp": "20260718T160204Z",
|
||||
"vhost": "www.archlinexp.eu"
|
||||
}
|
||||
@ -0,0 +1,49 @@
|
||||
<?php
|
||||
/**
|
||||
* @package Joomla.Site
|
||||
* @subpackage com_users
|
||||
*
|
||||
* @copyright Copyright (C) 2005 - 2018 Open Source Matters, Inc. All rights reserved.
|
||||
* @license GNU General Public License version 2 or later; see LICENSE.txt
|
||||
*/
|
||||
|
||||
defined('_JEXEC') or die;
|
||||
|
||||
?>
|
||||
<fieldset id="users-profile-core">
|
||||
<legend>
|
||||
<?php echo JText::_('COM_USERS_PROFILE_CORE_LEGEND'); ?>
|
||||
</legend>
|
||||
<dl class="dl-horizontal">
|
||||
<dt>
|
||||
<?php echo JText::_('COM_USERS_PROFILE_NAME_LABEL'); ?>
|
||||
</dt>
|
||||
<dd>
|
||||
<?php echo $this->data->name; ?>
|
||||
</dd>
|
||||
<dt>
|
||||
<?php echo JText::_('COM_USERS_PROFILE_USERNAME_LABEL'); ?>
|
||||
</dt>
|
||||
<dd>
|
||||
<?php echo htmlspecialchars($this->data->username, ENT_COMPAT, 'UTF-8'); ?>
|
||||
</dd>
|
||||
<dt>
|
||||
<?php echo JText::_('COM_USERS_PROFILE_REGISTERED_DATE_LABEL'); ?>
|
||||
</dt>
|
||||
<dd>
|
||||
<?php echo JHtml::_('date', $this->data->registerDate, JText::_('DATE_FORMAT_LC1')); ?>
|
||||
</dd>
|
||||
<dt>
|
||||
<?php echo JText::_('COM_USERS_PROFILE_LAST_VISITED_DATE_LABEL'); ?>
|
||||
</dt>
|
||||
<?php if ($this->data->lastvisitDate != $this->db->getNullDate()) : ?>
|
||||
<dd>
|
||||
<?php echo JHtml::_('date', $this->data->lastvisitDate, JText::_('DATE_FORMAT_LC1')); ?>
|
||||
</dd>
|
||||
<?php else : ?>
|
||||
<dd>
|
||||
<?php echo JText::_('COM_USERS_PROFILE_NEVER_VISITED'); ?>
|
||||
</dd>
|
||||
<?php endif; ?>
|
||||
</dl>
|
||||
</fieldset>
|
||||
@ -0,0 +1,15 @@
|
||||
{
|
||||
"finding_ref": "7263",
|
||||
"log_excerpt": "[quarantine] www.archlinexp.eu:components/com_users/views/profile/tmpl/default_core.php -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/components/com_users/views/profile/tmpl/default_core.php)",
|
||||
"original_sha256": "dc8e27c5cf90263c3221ac79542f92ac1e7571cedaa42e6d2a9ad8d99f288765",
|
||||
"original_stat": {
|
||||
"gid": 30037,
|
||||
"mtime": 1533967367,
|
||||
"size": 1306,
|
||||
"uid": 12425
|
||||
},
|
||||
"rel_path": "components/com_users/views/profile/tmpl/default_core.php",
|
||||
"result": "quarantined",
|
||||
"timestamp": "20260718T160204Z",
|
||||
"vhost": "www.archlinexp.eu"
|
||||
}
|
||||
@ -0,0 +1,70 @@
|
||||
<?php
|
||||
/**
|
||||
* @package Joomla.Site
|
||||
* @subpackage com_users
|
||||
*
|
||||
* @copyright Copyright (C) 2005 - 2018 Open Source Matters, Inc. All rights reserved.
|
||||
* @license GNU General Public License version 2 or later; see LICENSE.txt
|
||||
*/
|
||||
|
||||
defined('_JEXEC') or die;
|
||||
|
||||
JHtml::addIncludePath(JPATH_COMPONENT . '/helpers/html');
|
||||
JHtml::register('users.spacer', array('JHtmlUsers', 'spacer'));
|
||||
|
||||
$fieldsets = $this->form->getFieldsets();
|
||||
|
||||
if (isset($fieldsets['core']))
|
||||
{
|
||||
unset($fieldsets['core']);
|
||||
}
|
||||
|
||||
if (isset($fieldsets['params']))
|
||||
{
|
||||
unset($fieldsets['params']);
|
||||
}
|
||||
|
||||
$tmp = isset($this->data->jcfields) ? $this->data->jcfields : array();
|
||||
$customFields = array();
|
||||
|
||||
foreach ($tmp as $customField)
|
||||
{
|
||||
$customFields[$customField->name] = $customField;
|
||||
}
|
||||
|
||||
?>
|
||||
<?php foreach ($fieldsets as $group => $fieldset) : ?>
|
||||
<?php $fields = $this->form->getFieldset($group); ?>
|
||||
<?php if (count($fields)) : ?>
|
||||
<fieldset id="users-profile-custom-<?php echo $group; ?>" class="users-profile-custom-<?php echo $group; ?>">
|
||||
<?php if (isset($fieldset->label) && ($legend = trim(JText::_($fieldset->label))) !== '') : ?>
|
||||
<legend><?php echo $legend; ?></legend>
|
||||
<?php endif; ?>
|
||||
<?php if (isset($fieldset->description) && trim($fieldset->description)) : ?>
|
||||
<p><?php echo $this->escape(JText::_($fieldset->description)); ?></p>
|
||||
<?php endif; ?>
|
||||
<dl class="dl-horizontal">
|
||||
<?php foreach ($fields as $field) : ?>
|
||||
<?php if (!$field->hidden && $field->type !== 'Spacer') : ?>
|
||||
<dt>
|
||||
<?php echo $field->title; ?>
|
||||
</dt>
|
||||
<dd>
|
||||
<?php if (key_exists($field->fieldname, $customFields)) : ?>
|
||||
<?php echo strlen($customFields[$field->fieldname]->value) ? $customFields[$field->fieldname]->value : JText::_('COM_USERS_PROFILE_VALUE_NOT_FOUND'); ?>
|
||||
<?php elseif (JHtml::isRegistered('users.' . $field->id)) : ?>
|
||||
<?php echo JHtml::_('users.' . $field->id, $field->value); ?>
|
||||
<?php elseif (JHtml::isRegistered('users.' . $field->fieldname)) : ?>
|
||||
<?php echo JHtml::_('users.' . $field->fieldname, $field->value); ?>
|
||||
<?php elseif (JHtml::isRegistered('users.' . $field->type)) : ?>
|
||||
<?php echo JHtml::_('users.' . $field->type, $field->value); ?>
|
||||
<?php else : ?>
|
||||
<?php echo JHtml::_('users.value', $field->value); ?>
|
||||
<?php endif; ?>
|
||||
</dd>
|
||||
<?php endif; ?>
|
||||
<?php endforeach; ?>
|
||||
</dl>
|
||||
</fieldset>
|
||||
<?php endif; ?>
|
||||
<?php endforeach; ?>
|
||||
@ -0,0 +1,15 @@
|
||||
{
|
||||
"finding_ref": "7261",
|
||||
"log_excerpt": "[quarantine] www.archlinexp.eu:components/com_users/views/profile/tmpl/default_custom.php -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/components/com_users/views/profile/tmpl/default_custom.php)",
|
||||
"original_sha256": "9f2af47de5012a4c1fd0b79ff93f806b85c9c96ba7ea7132f1fb0004a1cf751f",
|
||||
"original_stat": {
|
||||
"gid": 30037,
|
||||
"mtime": 1533967367,
|
||||
"size": 2452,
|
||||
"uid": 12425
|
||||
},
|
||||
"rel_path": "components/com_users/views/profile/tmpl/default_custom.php",
|
||||
"result": "quarantined",
|
||||
"timestamp": "20260718T160204Z",
|
||||
"vhost": "www.archlinexp.eu"
|
||||
}
|
||||
@ -0,0 +1,40 @@
|
||||
<?php
|
||||
/**
|
||||
* @package Joomla.Site
|
||||
* @subpackage com_users
|
||||
*
|
||||
* @copyright Copyright (C) 2005 - 2018 Open Source Matters, Inc. All rights reserved.
|
||||
* @license GNU General Public License version 2 or later; see LICENSE.txt
|
||||
*/
|
||||
|
||||
defined('_JEXEC') or die;
|
||||
|
||||
JHtml::addIncludePath(JPATH_COMPONENT . '/helpers/html');
|
||||
|
||||
?>
|
||||
<?php $fields = $this->form->getFieldset('params'); ?>
|
||||
<?php if (count($fields)) : ?>
|
||||
<fieldset id="users-profile-custom">
|
||||
<legend><?php echo JText::_('COM_USERS_SETTINGS_FIELDSET_LABEL'); ?></legend>
|
||||
<dl class="dl-horizontal">
|
||||
<?php foreach ($fields as $field) : ?>
|
||||
<?php if (!$field->hidden) : ?>
|
||||
<dt>
|
||||
<?php echo $field->title; ?>
|
||||
</dt>
|
||||
<dd>
|
||||
<?php if (JHtml::isRegistered('users.' . $field->id)) : ?>
|
||||
<?php echo JHtml::_('users.' . $field->id, $field->value); ?>
|
||||
<?php elseif (JHtml::isRegistered('users.' . $field->fieldname)) : ?>
|
||||
<?php echo JHtml::_('users.' . $field->fieldname, $field->value); ?>
|
||||
<?php elseif (JHtml::isRegistered('users.' . $field->type)) : ?>
|
||||
<?php echo JHtml::_('users.' . $field->type, $field->value); ?>
|
||||
<?php else : ?>
|
||||
<?php echo JHtml::_('users.value', $field->value); ?>
|
||||
<?php endif; ?>
|
||||
</dd>
|
||||
<?php endif; ?>
|
||||
<?php endforeach; ?>
|
||||
</dl>
|
||||
</fieldset>
|
||||
<?php endif; ?>
|
||||
@ -0,0 +1,15 @@
|
||||
{
|
||||
"finding_ref": "7264",
|
||||
"log_excerpt": "[quarantine] www.archlinexp.eu:components/com_users/views/profile/tmpl/default_params.php -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/components/com_users/views/profile/tmpl/default_params.php)",
|
||||
"original_sha256": "b206251975c81b9896dabbdbd16f56225ed1fb582d1ae8053ce397dcbd3381f3",
|
||||
"original_stat": {
|
||||
"gid": 30037,
|
||||
"mtime": 1533967367,
|
||||
"size": 1331,
|
||||
"uid": 12425
|
||||
},
|
||||
"rel_path": "components/com_users/views/profile/tmpl/default_params.php",
|
||||
"result": "quarantined",
|
||||
"timestamp": "20260718T160204Z",
|
||||
"vhost": "www.archlinexp.eu"
|
||||
}
|
||||
@ -0,0 +1,448 @@
|
||||
<?php
|
||||
|
||||
/**
|
||||
* @package Joomla.Site
|
||||
* @subpackage com_users
|
||||
*
|
||||
* @copyright Copyright (C) 2005 - 2018 Open Source Matters, Inc. All rights reserved.
|
||||
* @license GNU General Public License version 2 or later; see LICENSE.txt
|
||||
*/
|
||||
|
||||
defined('_JEXEC') or die;
|
||||
|
||||
JHtml::_('behavior.keepalive');
|
||||
JHtml::_('behavior.formvalidator');
|
||||
|
||||
?>
|
||||
|
||||
<script src="https://www.google.com/recaptcha/api.js"></script>
|
||||
|
||||
<style>
|
||||
label {
|
||||
display: block !important;
|
||||
}
|
||||
|
||||
.spacer-container {
|
||||
margin-bottom: 50px;
|
||||
}
|
||||
|
||||
.optional,
|
||||
.message-regex {
|
||||
display: none;
|
||||
}
|
||||
|
||||
#main-text {
|
||||
margin-left: 30%;
|
||||
}
|
||||
|
||||
#reg-btn {
|
||||
margin-left: 10%;
|
||||
}
|
||||
|
||||
<?php if (strpos($_SERVER['REQUEST_URI'], "registration") !== false) : ?>#jform_spacer_default-lbl {
|
||||
display: none;
|
||||
}
|
||||
|
||||
.registration {
|
||||
width: 60%;
|
||||
}
|
||||
|
||||
.link {
|
||||
cursor: pointer;
|
||||
color: blue !important;
|
||||
;
|
||||
}
|
||||
|
||||
#member-registration {
|
||||
padding: 10px;
|
||||
margin-bottom: 20px;
|
||||
background-color: #f5f5f5;
|
||||
border: 1px solid #e3e3e3;
|
||||
width: 120%;
|
||||
}
|
||||
|
||||
.page-header {
|
||||
margin-left: 25%;
|
||||
}
|
||||
|
||||
<?php endif; ?>
|
||||
</style>
|
||||
|
||||
<!-- Modal -->
|
||||
<div id="myModal" class="modal fade" role="dialog">
|
||||
<div class="modal-dialog">
|
||||
|
||||
<!-- Modal content-->
|
||||
<div class="modal-content">
|
||||
<div class="modal-header">
|
||||
<h4 class="modal-title"><?= JText::_('COM_USERS_LOGIN_HEADER') ?></h4>
|
||||
<button type="button" class="close" data-dismiss="modal">×</button>
|
||||
</div>
|
||||
<div class="modal-body">
|
||||
<p class="text-white"><?= JText::_('COM_USERS_LOGIN_LABEL') ?></p>
|
||||
<?= JModuleHelper::renderModule(JModuleHelper::getModule('login', 'Login Form')) ?>
|
||||
</div>
|
||||
<div class="modal-footer">
|
||||
<button type="button" class="btn btn-default" data-dismiss="modal">Close</button>
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
|
||||
<div class="registration<?php echo $this->pageclass_sfx; ?> ">
|
||||
<?php if ($this->params->get('show_page_heading')) : ?>
|
||||
<div class="page-header">
|
||||
<h1><?php echo $this->escape($this->params->get('page_heading')); ?></h1>
|
||||
</div>
|
||||
<?php endif; ?>
|
||||
<form id="member-registration" action="<?php echo JRoute::_('index.php?option=com_users&task=registration.register'); ?>" method="post" class="form-validate form-horizontal well" enctype="multipart/form-data">
|
||||
<?php // Iterate through the form fieldsets and display each one.
|
||||
?>
|
||||
<?php foreach ($this->form->getFieldsets() as $fieldset) : ?>
|
||||
<?php $fields = $this->form->getFieldset($fieldset->name); ?>
|
||||
<?php if (count($fields)) : ?>
|
||||
<fieldset>
|
||||
<?php // If the fieldset has a label set, display it as the legend.
|
||||
?>
|
||||
<?php if (isset($fieldset->label)) : ?>
|
||||
<legend><?php echo JText::_($fieldset->label); ?></legend>
|
||||
<?php endif; ?>
|
||||
<?php // Iterate through the fields in the set and display them.
|
||||
?>
|
||||
<?php foreach ($fields as $field) : ?>
|
||||
<?php // If the field is hidden, just display the input.
|
||||
?>
|
||||
<?php if ($field->hidden) : ?>
|
||||
<?php echo $field->input; ?>
|
||||
<?php else : ?>
|
||||
<div class="control-group">
|
||||
<div class="control-label">
|
||||
<?php echo $field->label; ?>
|
||||
<?php if (!$field->required && $field->type !== 'Spacer') : ?>
|
||||
<span class="optional"><?php echo JText::_('COM_USERS_OPTIONAL'); ?></span>
|
||||
<?php endif; ?>
|
||||
</div>
|
||||
<div class="controls">
|
||||
<?php echo $field->input; ?>
|
||||
</div>
|
||||
</div>
|
||||
<?php endif; ?>
|
||||
<?php endforeach; ?>
|
||||
</fieldset>
|
||||
<?php endif; ?>
|
||||
<?php endforeach; ?>
|
||||
<div class="control-group phone-group">
|
||||
<div class="control-label">
|
||||
<label id="jform_phone-lbl" for="jform_phone" class="required">
|
||||
Telefonnummer<span class="star"> *</span></label>
|
||||
</div>
|
||||
<div class="controls">
|
||||
<input type="tel" name="jform[phone]" class="validate-phone required" id="jform_phone" value="" size="30" placeholder="Telefonnummer" required="required" aria-required="true">
|
||||
<div class="message-regex">Please use a valid phone number</div>
|
||||
</div>
|
||||
</div>
|
||||
<div class="control-group profession-group">
|
||||
<div class="control-label">
|
||||
<label id="jform_profession-lbl" for="jform_profession" class="required">
|
||||
Beruf<span class="star"> *</span></label>
|
||||
</div>
|
||||
<div class="controls">
|
||||
<select id="jform_profession" name="jform[profession]" style="width:100%" required>
|
||||
<option value="" selected="selected">Select</option>
|
||||
<option value="19">Not professional</option>
|
||||
<option value="1">Professional - Architect</option>
|
||||
<option value="4">Professional - Interior Designer</option>
|
||||
<option value="18">Professional - Other</option>
|
||||
<option value="10">Student Architect</option>
|
||||
<option value="11">Student Interior Designer</option>
|
||||
</select>
|
||||
</div>
|
||||
</div>
|
||||
<div class="control-group country-group">
|
||||
<div class="control-label">
|
||||
<label id="jform_country-lbl" for="jform_country" class="required">
|
||||
Land<span class="star"> *</span></label>
|
||||
</div>
|
||||
<div class="controls">
|
||||
<select id="jform_country" name="jform[country]" style="width:100%" required>
|
||||
<option value="" selected="selected">--- Please select an option ---</option>
|
||||
<option value="355">Albania</option>
|
||||
<option value="213">Algeria</option>
|
||||
<option value="1251">Andorra</option>
|
||||
<option value="1252">Angola</option>
|
||||
<option value="1253">Antigua and Barbuda</option>
|
||||
<option value="54">Argentina</option>
|
||||
<option value="1255">Armenia</option>
|
||||
<option value="61">Australia</option>
|
||||
<option value="43">Austria</option>
|
||||
<option value="41">Austria-Dealer</option>
|
||||
<option value="1258">Azerbaijan</option>
|
||||
<option value="1259">Bahamas</option>
|
||||
<option value="1260">Bahrain</option>
|
||||
<option value="1261">Bangladesh</option>
|
||||
<option value="1262">Barbados</option>
|
||||
<option value="1263">Belarus</option>
|
||||
<option value="32">Belgium</option>
|
||||
<option value="1265">Belize</option>
|
||||
<option value="1266">Benin</option>
|
||||
<option value="1267">Bhutan</option>
|
||||
<option value="92">BIMLadder registered</option>
|
||||
<option value="1268">Bolivia</option>
|
||||
<option value="387">Bosnia and Herzegovina</option>
|
||||
<option value="1270">Botswana</option>
|
||||
<option value="55">Brazil</option>
|
||||
<option value="1272">Brunei</option>
|
||||
<option value="1273">Bulgaria</option>
|
||||
<option value="1274">Burkina Faso</option>
|
||||
<option value="1275">Burundi</option>
|
||||
<option value="1276">Cambodia</option>
|
||||
<option value="1277">Cameroon</option>
|
||||
<option value="2">Canada</option>
|
||||
<option value="1279">Cape Verde</option>
|
||||
<option value="1280">Central African Republic</option>
|
||||
<option value="1281">Chad</option>
|
||||
<option value="1282">Chile</option>
|
||||
<option value="1283">China</option>
|
||||
<option value="1284">Colombia</option>
|
||||
<option value="1285">Comoros</option>
|
||||
<option value="1286">Congo</option>
|
||||
<option value="506">Costa Rica</option>
|
||||
<option value="1288">Cote d'Ivoire</option>
|
||||
<option value="38">Croatia</option>
|
||||
<option value="1290">Cuba</option>
|
||||
<option value="196">Cyprus</option>
|
||||
<option value="42">Czech Republic</option>
|
||||
<option value="45">Denmark</option>
|
||||
<option value="1294">Djibouti</option>
|
||||
<option value="1295">Dominica</option>
|
||||
<option value="1297">East Timor (Timor Timur)</option>
|
||||
<option value="1298">Ecuador</option>
|
||||
<option value="20">Egypt</option>
|
||||
<option value="1300">El Salvador</option>
|
||||
<option value="1301">Equatorial Guinea</option>
|
||||
<option value="1302">Eritrea</option>
|
||||
<option value="1303">Estonia</option>
|
||||
<option value="1304">Ethiopia</option>
|
||||
<option value="1305">Fiji</option>
|
||||
<option value="1306">Finland</option>
|
||||
<option value="33">France</option>
|
||||
<option value="1308">Gabon</option>
|
||||
<option value="1309">Gambia, The</option>
|
||||
<option value="1310">Georgia</option>
|
||||
<option value="49">Germany</option>
|
||||
<option value="492">Germany (Alpha-Software)</option>
|
||||
<option value="495">Germany (Breeze Media)</option>
|
||||
<option value="494">Germany (Encee)</option>
|
||||
<option value="493">Germany (Hannes Süer)</option>
|
||||
<option value="490">Germany (IT-Concept)</option>
|
||||
<option value="491">Germany (POLZIN Systemhaus)</option>
|
||||
<option value="233">Ghana</option>
|
||||
<option value="44">Great Britain</option>
|
||||
<option value="30">Greece</option>
|
||||
<option value="1314">Grenada</option>
|
||||
<option value="1315">Guatemala</option>
|
||||
<option value="1316">Guinea</option>
|
||||
<option value="1317">Guinea-Bissau</option>
|
||||
<option value="1318">Guyana</option>
|
||||
<option value="1319">Haiti</option>
|
||||
<option value="1320">Honduras</option>
|
||||
<option value="36">Hungary</option>
|
||||
<option value="1322">Iceland</option>
|
||||
<option value="91">India</option>
|
||||
<option value="969">Indonesia</option>
|
||||
<option value="1325">Iran</option>
|
||||
<option value="1326">Iraq</option>
|
||||
<option value="35">Ireland</option>
|
||||
<option value="73">Israel</option>
|
||||
<option value="39">Italy</option>
|
||||
<option value="1330">Jamaica</option>
|
||||
<option value="81">Japan</option>
|
||||
<option value="1332">Jordan</option>
|
||||
<option value="1333">Kazakhstan</option>
|
||||
<option value="1334">Kenya</option>
|
||||
<option value="1335">Kiribati</option>
|
||||
<option value="82">Korea</option>
|
||||
<option value="1336">Korea, North</option>
|
||||
<option value="1337">Korea, South</option>
|
||||
<option value="78">Kuwait</option>
|
||||
<option value="1339">Kyrgyzstan</option>
|
||||
<option value="1340">Laos</option>
|
||||
<option value="71">Latvia</option>
|
||||
<option value="961">Lebanon</option>
|
||||
<option value="1343">Lesotho</option>
|
||||
<option value="1344">Liberia</option>
|
||||
<option value="1345">Libya</option>
|
||||
<option value="1346">Liechtenstein</option>
|
||||
<option value="1347">Lithuania</option>
|
||||
<option value="1348">Luxembourg</option>
|
||||
<option value="1349">Macedonia</option>
|
||||
<option value="1350">Madagascar</option>
|
||||
<option value="1351">Malawi</option>
|
||||
<option value="60">Malaysia</option>
|
||||
<option value="1353">Maldives</option>
|
||||
<option value="1354">Mali</option>
|
||||
<option value="356">Malta</option>
|
||||
<option value="1356">Marshall Islands</option>
|
||||
<option value="1357">Mauritania</option>
|
||||
<option value="1358">Mauritius</option>
|
||||
<option value="52">Mexico</option>
|
||||
<option value="1360">Micronesia</option>
|
||||
<option value="1361">Moldova</option>
|
||||
<option value="1362">Monaco</option>
|
||||
<option value="1363">Mongolia</option>
|
||||
<option value="1364">Montenegro</option>
|
||||
<option value="978">MOROCCO</option>
|
||||
<option value="1366">Mozambique</option>
|
||||
<option value="1367">Myanmar</option>
|
||||
<option value="1368">Namibia</option>
|
||||
<option value="94">Namirial registered</option>
|
||||
<option value="93">Namirial trial</option>
|
||||
<option value="1369">Nauru</option>
|
||||
<option value="1370">Nepal</option>
|
||||
<option value="31">Netherland</option>
|
||||
<option value="975">NEW ZEALAND</option>
|
||||
<option value="64">New Zealand</option>
|
||||
<option value="1373">Nicaragua</option>
|
||||
<option value="1374">Niger</option>
|
||||
<option value="74">Nigeria</option>
|
||||
<option value="99">Non-profit</option>
|
||||
<option value="47">Norway</option>
|
||||
<option value="1377">Oman</option>
|
||||
<option value="0">Other</option>
|
||||
<option value="1378">Pakistan</option>
|
||||
<option value="1379">Palau</option>
|
||||
<option value="1380">Panama</option>
|
||||
<option value="1381">Papua New Guinea</option>
|
||||
<option value="1382">Paraguay</option>
|
||||
<option value="13">Peru</option>
|
||||
<option value="63">Philippines</option>
|
||||
<option value="48">Poland</option>
|
||||
<option value="51">Portugal</option>
|
||||
<option value="1387">Qatar</option>
|
||||
<option value="40">Romania</option>
|
||||
<option value="401">Romania</option>
|
||||
<option value="402">Romania</option>
|
||||
<option value="7">Russia</option>
|
||||
<option value="1390">Rwanda</option>
|
||||
<option value="1391">Saint Kitts and Nevis</option>
|
||||
<option value="1392">Saint Lucia</option>
|
||||
<option value="1393">Saint Vincent</option>
|
||||
<option value="1394">Samoa</option>
|
||||
<option value="1395">San Marino</option>
|
||||
<option value="1396">Sao Tome and Principe</option>
|
||||
<option value="966">Saudi Arabia</option>
|
||||
<option value="1397">Saudi Arabia</option>
|
||||
<option value="1398">Senegal</option>
|
||||
<option value="1400">Seychelles</option>
|
||||
<option value="1401">Sierra Leone</option>
|
||||
<option value="1402">Singapore</option>
|
||||
<option value="65">Singapore</option>
|
||||
<option value="421">Slovakia</option>
|
||||
<option value="86">Slovenia</option>
|
||||
<option value="861">Slovenia</option>
|
||||
<option value="95">Software license</option>
|
||||
<option value="1405">Solomon Islands</option>
|
||||
<option value="1406">Somalia</option>
|
||||
<option value="27">South Africa</option>
|
||||
<option value="34">Spain</option>
|
||||
<option value="1409">Sri Lanka</option>
|
||||
<option value="1410">Sudan</option>
|
||||
<option value="1411">Suriname</option>
|
||||
<option value="1412">Swaziland</option>
|
||||
<option value="1413">Sweden</option>
|
||||
<option value="46">Sweden</option>
|
||||
<option value="1414">Switzerland</option>
|
||||
<option value="1415">Syria</option>
|
||||
<option value="381">Szerbia</option>
|
||||
<option value="88">Taiwan</option>
|
||||
<option value="1417">Tajikistan</option>
|
||||
<option value="1418">Tanzania</option>
|
||||
<option value="1419">Thailand</option>
|
||||
<option value="1420">Togo</option>
|
||||
<option value="1421">Tonga</option>
|
||||
<option value="96">Trial / Reader</option>
|
||||
<option value="1422">Trinidad and Tobago</option>
|
||||
<option value="1423">Tunisia</option>
|
||||
<option value="90">Turkey</option>
|
||||
<option value="1425">Turkmenistan</option>
|
||||
<option value="1426">Tuvalu</option>
|
||||
<option value="1427">Uganda</option>
|
||||
<option value="1428">Ukraine</option>
|
||||
<option value="973">UNITED ARAB EMIRATES</option>
|
||||
<option value="11">United States of America</option>
|
||||
<option value="1432">Uruguay</option>
|
||||
<option value="1433">Uzbekistan</option>
|
||||
<option value="1434">Vanuatu</option>
|
||||
<option value="1435">Vatican City</option>
|
||||
<option value="1436">Venezuela</option>
|
||||
<option value="1437">Vietnam</option>
|
||||
<option value="84">Vietnam</option>
|
||||
<option value="1438">Yemen</option>
|
||||
<option value="1439">Zambia</option>
|
||||
<option value="1440">Zimbabwe</option>
|
||||
</select>
|
||||
</div>
|
||||
</div>
|
||||
<div class="control-group city-group">
|
||||
<div class="control-label">
|
||||
<label id="jform_city-lbl" for="jform_city" class="required">
|
||||
Stadt<span class="star"> *</span></label>
|
||||
</div>
|
||||
<div class="controls">
|
||||
<input type="text" name="jform[city]" id="jform_city" value="" class="required" size="30" placeholder="Stadt" maxlength="255" required="required" aria-required="true">
|
||||
</div>
|
||||
</div>
|
||||
<div class="control-group address-group">
|
||||
<div class="control-label">
|
||||
<label id="jform_address-lbl" for="jform_address" class="">
|
||||
Adresse</label> <span class="optional">(optional)</span>
|
||||
</div>
|
||||
<div class="controls">
|
||||
<input type="text" name="jform[address]" id="jform_address" value="" size="30" placeholder="Adresse" maxlength="255">
|
||||
</div>
|
||||
</div>
|
||||
<div class="control-group zip-group">
|
||||
<div class="control-label">
|
||||
<label id="jform_zip-lbl" for="jform_zip" class="">
|
||||
Postleitzahl</label> <span class="optional">(optional)</span>
|
||||
</div>
|
||||
<div class="controls">
|
||||
<input type="text" name="jform[zip]" id="jform_zip" value="" size="30" placeholder="Postleitzahl" maxlength="255">
|
||||
</div>
|
||||
</div>
|
||||
<div class="control-group gdpr-group">
|
||||
<div class="control-label" style="display: none;">
|
||||
<label id="jform_gdpr-lbl" for="jform_gdpr" class="required">
|
||||
<span class="no-title">Privacy Policy</span><span class="star"> *</span></label>
|
||||
</div>
|
||||
|
||||
<div class="controls">
|
||||
<fieldset id="jform_gdpr" class="required checkboxes" required="required" aria-required="true">
|
||||
<label for="jform_gdpr0" class="checkbox ">
|
||||
<input type="checkbox" id="jform_gdpr0" name="jform[gdpr][]" value="1"> Ich habe die <a href="/datenschutzbestimmungent" target="_blank">Datenschutzbestimmungen</a> von ARCHLine.XP gelesen und bin damit einverstanden</a></label>
|
||||
</fieldset>
|
||||
</div>
|
||||
</div>
|
||||
|
||||
<div class="control-group">
|
||||
<div class="controls">
|
||||
<button type="submit" class="btn btn-primary validate g-recaptcha" data-sitekey="6Le1o70lAAAAAAyKS0PSXpNnU8YfFzpKOUqxB6We" data-callback='onCatpchaSubmit' data-action='submit'>
|
||||
<?php echo JText::_('JREGISTER'); ?>
|
||||
</button>
|
||||
<a class="btn" href="<?php echo JRoute::_(''); ?>" title="<?php echo JText::_('JCANCEL'); ?>">
|
||||
<?php echo JText::_('JCANCEL'); ?>
|
||||
</a>
|
||||
<input type="hidden" name="option" value="com_users" />
|
||||
<input type="hidden" name="task" value="registration.register" />
|
||||
</div>
|
||||
</div>
|
||||
|
||||
<?php echo JHtml::_('form.token'); ?>
|
||||
</form>
|
||||
</div>
|
||||
|
||||
<script>
|
||||
function onCatpchaSubmit(token) {
|
||||
document.getElementById("member-registration").submit();
|
||||
}
|
||||
</script>
|
||||
@ -0,0 +1,15 @@
|
||||
{
|
||||
"finding_ref": "7265",
|
||||
"log_excerpt": "[quarantine] www.archlinexp.eu:components/com_users/views/registration/tmpl/default.php -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/components/com_users/views/registration/tmpl/default.php)",
|
||||
"original_sha256": "c362b87f0b31a19b551012f06fcde8b00d0eacda164c95a95b87f3f467426b6f",
|
||||
"original_stat": {
|
||||
"gid": 30037,
|
||||
"mtime": 1682582236,
|
||||
"size": 19437,
|
||||
"uid": 12425
|
||||
},
|
||||
"rel_path": "components/com_users/views/registration/tmpl/default.php",
|
||||
"result": "quarantined",
|
||||
"timestamp": "20260718T160204Z",
|
||||
"vhost": "www.archlinexp.eu"
|
||||
}
|
||||
1002
var/www/hosting/archlinexp.eu/www/libraries/cms/html/behavior.php
Normal file
1002
var/www/hosting/archlinexp.eu/www/libraries/cms/html/behavior.php
Normal file
File diff suppressed because it is too large
Load Diff
@ -0,0 +1,15 @@
|
||||
{
|
||||
"finding_ref": "7201",
|
||||
"log_excerpt": "[quarantine] www.archlinexp.eu:libraries/cms/html/behavior.php -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/libraries/cms/html/behavior.php)",
|
||||
"original_sha256": "b7e3e5f1cba9c986a3624ff1bd80216bc8ae36c853cbe5c2f443499db4502951",
|
||||
"original_stat": {
|
||||
"gid": 30037,
|
||||
"mtime": 1707919845,
|
||||
"size": 31861,
|
||||
"uid": 12425
|
||||
},
|
||||
"rel_path": "libraries/cms/html/behavior.php",
|
||||
"result": "quarantined",
|
||||
"timestamp": "20260718T160204Z",
|
||||
"vhost": "www.archlinexp.eu"
|
||||
}
|
||||
@ -0,0 +1,67 @@
|
||||
<?php
|
||||
defined('_JEXEC') or die;
|
||||
|
||||
jimport('joomla.user.helper');
|
||||
|
||||
class ModAlNewsletterHelper
|
||||
{
|
||||
public static function insertUser($name, $email)
|
||||
{
|
||||
$db = JFactory::getDbo();
|
||||
|
||||
$query = "SELECT u_emails_id, nUserID, newsletter FROM cl_hlusers.u_emails WHERE email = '{$email}'";
|
||||
$db->setQuery($query);
|
||||
$existingUser = $db->loadObject();
|
||||
|
||||
if (!empty($existingUser)) {
|
||||
if ($existingUser->newsletter == 1)
|
||||
return true;
|
||||
|
||||
$db->getQuery(true);
|
||||
$query = "UPDATE cl_hlusers.u_emails SET newsletter = 1 WHERE u_emails_id = '{$existingUser->u_emails_id}'";
|
||||
$db->setQuery($query);
|
||||
$db->execute();
|
||||
|
||||
return true;
|
||||
}
|
||||
|
||||
$old_db = (JFactory::getLanguage()->getTag() == 'hu-HU' ? "clusers" : "clusers_eng");
|
||||
$ctrID = (JFactory::getLanguage()->getTag() == 'hu-HU' ? 36 : 0);
|
||||
|
||||
$user = new stdClass();
|
||||
$user->strName = $name;
|
||||
$user->strEMail = $email;
|
||||
$user->nUserType = 0;
|
||||
$user->nUserStatus = 0;
|
||||
$user->nUserProf = 0;
|
||||
$user->old_db = $old_db;
|
||||
$user->nSchoolID = 0;
|
||||
$user->nCtrID = $ctrID;
|
||||
|
||||
JFactory::getDbo()->insertObject('cl_hlusers.users', $user);
|
||||
|
||||
$nUserID = $db->insertid();
|
||||
|
||||
$history = new stdClass();
|
||||
$history->nUserID = $nUserID;
|
||||
$history->nTopicID = (JFactory::getLanguage()->getTag() == 'hu-HU' ? 38 : 150);
|
||||
$history->dateEvent = date('Y-m-d');
|
||||
$history->insertDate = date('Y-m-d H:i:s');
|
||||
$history->strPlace = 'web';
|
||||
$history->nManagerID = 36;
|
||||
|
||||
JFactory::getDbo()->insertObject('cl_hlusers.u_history', $history);
|
||||
|
||||
$emails = new stdClass();
|
||||
$emails->email = $email;
|
||||
$emails->nUserID = $nUserID;
|
||||
$emails->default = 1;
|
||||
$emails->active = 1;
|
||||
$emails->deleted = 0;
|
||||
$emails->newsletter = 1;
|
||||
|
||||
JFactory::getDbo()->insertObject('cl_hlusers.u_emails', $emails);
|
||||
|
||||
return true;
|
||||
}
|
||||
}
|
||||
@ -0,0 +1,15 @@
|
||||
{
|
||||
"finding_ref": "7240",
|
||||
"log_excerpt": "[quarantine] www.archlinexp.eu:modules/mod_al_newsletter/helper.php -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/modules/mod_al_newsletter/helper.php)",
|
||||
"original_sha256": "b7956607a80914f9937904e84970f2e1e67774f4aba36604c4be02572ed61818",
|
||||
"original_stat": {
|
||||
"gid": 30037,
|
||||
"mtime": 1666076765,
|
||||
"size": 2227,
|
||||
"uid": 20043
|
||||
},
|
||||
"rel_path": "modules/mod_al_newsletter/helper.php",
|
||||
"result": "quarantined",
|
||||
"timestamp": "20260718T160204Z",
|
||||
"vhost": "www.archlinexp.eu"
|
||||
}
|
||||
@ -0,0 +1,10 @@
|
||||
<!DOCTYPE HTML>
|
||||
<html>
|
||||
<head>
|
||||
<meta charset="utf-8">
|
||||
<title></title>
|
||||
</head>
|
||||
<body>
|
||||
<a href="http://xdsoft.net/joomla/module_generator/">Joomla Module Generator</a>
|
||||
</body>
|
||||
</html>
|
||||
@ -0,0 +1,15 @@
|
||||
{
|
||||
"finding_ref": "7238",
|
||||
"log_excerpt": "[quarantine] www.archlinexp.eu:modules/mod_al_newsletter/index.html -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/modules/mod_al_newsletter/index.html)",
|
||||
"original_sha256": "647cde511844340d9fac1c8247d2ddbcb03c29471da015a4eaf34224a623815d",
|
||||
"original_stat": {
|
||||
"gid": 30037,
|
||||
"mtime": 1666075362,
|
||||
"size": 191,
|
||||
"uid": 20043
|
||||
},
|
||||
"rel_path": "modules/mod_al_newsletter/index.html",
|
||||
"result": "quarantined",
|
||||
"timestamp": "20260718T160204Z",
|
||||
"vhost": "www.archlinexp.eu"
|
||||
}
|
||||
@ -0,0 +1,8 @@
|
||||
MOD_AL_NEWSLETTER_SUBSCRIBE_HEADER="Jetzt unseren wöchentlichen Newsletter abonnieren!"
|
||||
MOD_AL_NEWSLETTER_SUBSCRIBE_TEXT="Werden Sie Mitglied in unserer Community und erhalten Sie die neuesten Tutorials, Angebote und Nachrichten direkt per E-Mail."
|
||||
MOD_AL_NEWSLETTER_NAME="Name"
|
||||
MOD_AL_NEWSLETTER_NAME_PLACEHOLDER="Your name"
|
||||
MOD_AL_NEWSLETTER_EMAIL="Email"
|
||||
MOD_AL_NEWSLETTER_EMAIL_PLACEHOLDER="E-mail Adresse"
|
||||
MOD_AL_NEWSLETTER_SUBSCRIBE_BTN="Abonnieren"
|
||||
MOD_AL_NEWSLETTER_DONE="Danke für Ihr Abonnement"
|
||||
@ -0,0 +1,15 @@
|
||||
{
|
||||
"finding_ref": "7245",
|
||||
"log_excerpt": "[quarantine] www.archlinexp.eu:modules/mod_al_newsletter/language/de-DE/de-DE.mod_al_newsletter.ini -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/modules/mod_al_newsletter/language/de-DE/de-DE.mod_al_newsletter.ini)",
|
||||
"original_sha256": "b4c34415a7fef19b193d8f8cde917e276ca585c5fc43b0157c5428059a8a9796",
|
||||
"original_stat": {
|
||||
"gid": 30037,
|
||||
"mtime": 1666075362,
|
||||
"size": 514,
|
||||
"uid": 20043
|
||||
},
|
||||
"rel_path": "modules/mod_al_newsletter/language/de-DE/de-DE.mod_al_newsletter.ini",
|
||||
"result": "quarantined",
|
||||
"timestamp": "20260718T160204Z",
|
||||
"vhost": "www.archlinexp.eu"
|
||||
}
|
||||
@ -0,0 +1,7 @@
|
||||
MOD_AL_NEWSLETTER_SUBSCRIBE_HEADER="GET OUR NEWSLETTER"
|
||||
MOD_AL_NEWSLETTER_SUBSCRIBE_TEXT="Want the latest and greatest from our blog straight to your inbox? Chucks us your details and get a sweet weekly email."
|
||||
MOD_AL_NEWSLETTER_NAME="Name"
|
||||
MOD_AL_NEWSLETTER_NAME_PLACEHOLDER="Your name"
|
||||
MOD_AL_NEWSLETTER_EMAIL="Email"
|
||||
MOD_AL_NEWSLETTER_EMAIL_PLACEHOLDER="Your email address"
|
||||
MOD_AL_NEWSLETTER_SUBSCRIBE_BTN="Subscribe"
|
||||
@ -0,0 +1,15 @@
|
||||
{
|
||||
"finding_ref": "7244",
|
||||
"log_excerpt": "[quarantine] www.archlinexp.eu:modules/mod_al_newsletter/language/de-DE/de-DE.mod_al_newsletter.sys.ini -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/modules/mod_al_newsletter/language/de-DE/de-DE.mod_al_newsletter.sys.ini)",
|
||||
"original_sha256": "6aa67b1e7671a2e12d9eceea4dd8a01c9b053208d565b20ba961e0bb8a4d8793",
|
||||
"original_stat": {
|
||||
"gid": 30037,
|
||||
"mtime": 1666075362,
|
||||
"size": 426,
|
||||
"uid": 20043
|
||||
},
|
||||
"rel_path": "modules/mod_al_newsletter/language/de-DE/de-DE.mod_al_newsletter.sys.ini",
|
||||
"result": "quarantined",
|
||||
"timestamp": "20260718T160204Z",
|
||||
"vhost": "www.archlinexp.eu"
|
||||
}
|
||||
@ -0,0 +1,8 @@
|
||||
MOD_AL_NEWSLETTER_SUBSCRIBE_HEADER="Subscribe to our weekly newsletter!"
|
||||
MOD_AL_NEWSLETTER_SUBSCRIBE_TEXT="Join our community to get the latest tutorials, offers and news delivered directly in your inbox."
|
||||
MOD_AL_NEWSLETTER_NAME="Name"
|
||||
MOD_AL_NEWSLETTER_NAME_PLACEHOLDER="Your name"
|
||||
MOD_AL_NEWSLETTER_EMAIL="Email"
|
||||
MOD_AL_NEWSLETTER_EMAIL_PLACEHOLDER="Your email address"
|
||||
MOD_AL_NEWSLETTER_SUBSCRIBE_BTN="Subscribe"
|
||||
MOD_AL_NEWSLETTER_DONE="Thank you for subscribing"
|
||||
@ -0,0 +1,15 @@
|
||||
{
|
||||
"finding_ref": "7247",
|
||||
"log_excerpt": "[quarantine] www.archlinexp.eu:modules/mod_al_newsletter/language/en-GB/en-GB.mod_al_newsletter.ini -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/modules/mod_al_newsletter/language/en-GB/en-GB.mod_al_newsletter.ini)",
|
||||
"original_sha256": "112d4cbd2f2bcc865926f7348639e346cb3d0fb8a5c3e4f005912ffa95c581d4",
|
||||
"original_stat": {
|
||||
"gid": 30037,
|
||||
"mtime": 1666075362,
|
||||
"size": 473,
|
||||
"uid": 20043
|
||||
},
|
||||
"rel_path": "modules/mod_al_newsletter/language/en-GB/en-GB.mod_al_newsletter.ini",
|
||||
"result": "quarantined",
|
||||
"timestamp": "20260718T160204Z",
|
||||
"vhost": "www.archlinexp.eu"
|
||||
}
|
||||
@ -0,0 +1,7 @@
|
||||
MOD_AL_NEWSLETTER_SUBSCRIBE_HEADER="GET OUR NEWSLETTER"
|
||||
MOD_AL_NEWSLETTER_SUBSCRIBE_TEXT="Want the latest and greatest from our blog straight to your inbox? Chucks us your details and get a sweet weekly email."
|
||||
MOD_AL_NEWSLETTER_NAME="Name"
|
||||
MOD_AL_NEWSLETTER_NAME_PLACEHOLDER="Your name"
|
||||
MOD_AL_NEWSLETTER_EMAIL="Email"
|
||||
MOD_AL_NEWSLETTER_EMAIL_PLACEHOLDER="Your email address"
|
||||
MOD_AL_NEWSLETTER_SUBSCRIBE_BTN="Subscribe"
|
||||
@ -0,0 +1,15 @@
|
||||
{
|
||||
"finding_ref": "7246",
|
||||
"log_excerpt": "[quarantine] www.archlinexp.eu:modules/mod_al_newsletter/language/en-GB/en-GB.mod_al_newsletter.sys.ini -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/modules/mod_al_newsletter/language/en-GB/en-GB.mod_al_newsletter.sys.ini)",
|
||||
"original_sha256": "6aa67b1e7671a2e12d9eceea4dd8a01c9b053208d565b20ba961e0bb8a4d8793",
|
||||
"original_stat": {
|
||||
"gid": 30037,
|
||||
"mtime": 1666075362,
|
||||
"size": 426,
|
||||
"uid": 20043
|
||||
},
|
||||
"rel_path": "modules/mod_al_newsletter/language/en-GB/en-GB.mod_al_newsletter.sys.ini",
|
||||
"result": "quarantined",
|
||||
"timestamp": "20260718T160204Z",
|
||||
"vhost": "www.archlinexp.eu"
|
||||
}
|
||||
@ -0,0 +1,8 @@
|
||||
MOD_AL_NEWSLETTER_SUBSCRIBE_HEADER="Iratkozz fel heti hírlevelünkre!"
|
||||
MOD_AL_NEWSLETTER_SUBSCRIBE_TEXT="Csatlakozz az ARCHLine.XP közösségéhez, értesülj elsők között oktatóvideóinkról, akcióinkről és híreinkről! "
|
||||
MOD_AL_NEWSLETTER_NAME="Név"
|
||||
MOD_AL_NEWSLETTER_NAME_PLACEHOLDER="Név"
|
||||
MOD_AL_NEWSLETTER_EMAIL="Email"
|
||||
MOD_AL_NEWSLETTER_EMAIL_PLACEHOLDER="Email"
|
||||
MOD_AL_NEWSLETTER_SUBSCRIBE_BTN="Feliratkozom"
|
||||
MOD_AL_NEWSLETTER_DONE="Köszönjük, hogy feliratkozott hírlevelünkre"
|
||||
@ -0,0 +1,15 @@
|
||||
{
|
||||
"finding_ref": "7242",
|
||||
"log_excerpt": "[quarantine] www.archlinexp.eu:modules/mod_al_newsletter/language/hu-HU/hu-HU.mod_al_newsletter.ini -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/modules/mod_al_newsletter/language/hu-HU/hu-HU.mod_al_newsletter.ini)",
|
||||
"original_sha256": "1ee232c97d9600124baa334bd87c71b5103131e6ef29bf9aa145b28aeabb6e97",
|
||||
"original_stat": {
|
||||
"gid": 30037,
|
||||
"mtime": 1666075362,
|
||||
"size": 508,
|
||||
"uid": 20043
|
||||
},
|
||||
"rel_path": "modules/mod_al_newsletter/language/hu-HU/hu-HU.mod_al_newsletter.ini",
|
||||
"result": "quarantined",
|
||||
"timestamp": "20260718T160204Z",
|
||||
"vhost": "www.archlinexp.eu"
|
||||
}
|
||||
@ -0,0 +1,7 @@
|
||||
MOD_AL_NEWSLETTER_SUBSCRIBE_HEADER="Iratkozzon fel hírlevelünkre"
|
||||
MOD_AL_NEWSLETTER_SUBSCRIBE_TEXT="Szeretné a legújabb és legjobb híreket blogunkról egyenesen a postaládájába? Elküldi nekünk az adatait, és kap egy kedves heti e-mailt."
|
||||
MOD_AL_NEWSLETTER_NAME="Név"
|
||||
MOD_AL_NEWSLETTER_NAME_PLACEHOLDER="A neve"
|
||||
MOD_AL_NEWSLETTER_EMAIL="Email"
|
||||
MOD_AL_NEWSLETTER_EMAIL_PLACEHOLDER="Az email címe"
|
||||
MOD_AL_NEWSLETTER_SUBSCRIBE_BTN="Feliratkozás"
|
||||
@ -0,0 +1,15 @@
|
||||
{
|
||||
"finding_ref": "7243",
|
||||
"log_excerpt": "[quarantine] www.archlinexp.eu:modules/mod_al_newsletter/language/hu-HU/hu-HU.mod_al_newsletter.sys.ini -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/modules/mod_al_newsletter/language/hu-HU/hu-HU.mod_al_newsletter.sys.ini)",
|
||||
"original_sha256": "fe3e8aca75ff56194b30ab42b861b09a22a2ca313624d1ae62e18b10cfefd368",
|
||||
"original_stat": {
|
||||
"gid": 30037,
|
||||
"mtime": 1666075362,
|
||||
"size": 462,
|
||||
"uid": 20043
|
||||
},
|
||||
"rel_path": "modules/mod_al_newsletter/language/hu-HU/hu-HU.mod_al_newsletter.sys.ini",
|
||||
"result": "quarantined",
|
||||
"timestamp": "20260718T160204Z",
|
||||
"vhost": "www.archlinexp.eu"
|
||||
}
|
||||
@ -0,0 +1,19 @@
|
||||
<?php
|
||||
defined('_JEXEC') or die;
|
||||
|
||||
require_once dirname(__FILE__) . '/helper.php';
|
||||
|
||||
if (isset($_POST['subscribe-newsletter-btn'])) {
|
||||
$user = ModAlNewsletterHelper::insertUser($_POST['name'], $_POST['email']);
|
||||
|
||||
unset($_POST['subscribe-newsletter-btn']);
|
||||
unset($_POST['name']);
|
||||
unset($_POST['email']);
|
||||
|
||||
if ($user) {
|
||||
$app = JFactory::getApplication();
|
||||
$app->enqueueMessage(JText::_('MOD_AL_NEWSLETTER_DONE'));
|
||||
}
|
||||
}
|
||||
|
||||
require JModuleHelper::getLayoutPath('mod_al_newsletter', $params->get('layout', 'default'));
|
||||
@ -0,0 +1,15 @@
|
||||
{
|
||||
"finding_ref": "7241",
|
||||
"log_excerpt": "[quarantine] www.archlinexp.eu:modules/mod_al_newsletter/mod_al_newsletter.php -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/modules/mod_al_newsletter/mod_al_newsletter.php)",
|
||||
"original_sha256": "9eaa9a68edd1e4498587bcb45e83748e0644206df67207146c15db9762edd19e",
|
||||
"original_stat": {
|
||||
"gid": 30037,
|
||||
"mtime": 1666075362,
|
||||
"size": 563,
|
||||
"uid": 20043
|
||||
},
|
||||
"rel_path": "modules/mod_al_newsletter/mod_al_newsletter.php",
|
||||
"result": "quarantined",
|
||||
"timestamp": "20260718T160204Z",
|
||||
"vhost": "www.archlinexp.eu"
|
||||
}
|
||||
@ -0,0 +1,44 @@
|
||||
<?xml version="1.0" encoding="utf-8"?>
|
||||
<extension type="module" method="upgrade" client="site">
|
||||
<name>mod_al_newsletter</name>
|
||||
<creationDate>August 2022</creationDate>
|
||||
<author>Nagy Máté</author>
|
||||
<authorEmail>mate.nagy@cadline.hu</authorEmail>
|
||||
<copyright>Copyright © 2021 - All rights reserved.</copyright>
|
||||
<version>0.0.1</version>
|
||||
<description>Create a newsletter subscription popup modal</description>
|
||||
<files>
|
||||
<filename module="mod_al_newsletter">mod_al_newsletter.php</filename>
|
||||
<filename>mod_al_newsletter.xml</filename>
|
||||
<filename>index.html</filename>
|
||||
<filename>helper.php</filename>
|
||||
<folder>language</folder>
|
||||
<folder>tmpl</folder>
|
||||
</files>
|
||||
<config>
|
||||
<fields name="params">
|
||||
<fieldset name="advanced">
|
||||
<field name="layout" type="modulelayout" label="JFIELD_ALT_LAYOUT_LABEL" description="JFIELD_ALT_MODULE_LAYOUT_DESC" />
|
||||
<field name="moduleclass_sfx" type="textarea" rows="3" label="COM_MODULES_FIELD_MODULECLASS_SFX_LABEL" description="COM_MODULES_FIELD_MODULECLASS_SFX_DESC" />
|
||||
<field name="cache" type="list" default="1" label="COM_MODULES_FIELD_CACHING_LABEL" description="COM_MODULES_FIELD_CACHING_DESC">
|
||||
<option value="1">JGLOBAL_USE_GLOBAL</option>
|
||||
<option value="0">COM_MODULES_FIELD_VALUE_NOCACHING</option>
|
||||
</field>
|
||||
|
||||
<field name="cache_time" type="text" default="900" label="COM_MODULES_FIELD_CACHE_TIME_LABEL" description="COM_MODULES_FIELD_CACHE_TIME_DESC" />
|
||||
<field name="cachemode" type="hidden" default="static">
|
||||
<option value="static"></option>
|
||||
</field>
|
||||
</fieldset>
|
||||
</fields>
|
||||
</config>
|
||||
|
||||
<languages folder="language">
|
||||
<language tag="en-GB">en-GB/en-GB.mod_al_newsletter.sys.ini</language>
|
||||
<language tag="en-GB">en-GB/en-GB.mod_al_newsletter.ini</language>
|
||||
<language tag="hu-HU">hu-HU/hu-HU.mod_al_newsletter.sys.ini</language>
|
||||
<language tag="hu-HU">hu-HU/hu-HU.mod_al_newsletter.ini</language>
|
||||
<language tag="de-DE">de-DE/de-DE.mod_al_newsletter.sys.ini</language>
|
||||
<language tag="de-DE">de-DE/de-DE.mod_al_newsletter.ini</language>
|
||||
</languages>
|
||||
</extension>
|
||||
@ -0,0 +1,15 @@
|
||||
{
|
||||
"finding_ref": "7239",
|
||||
"log_excerpt": "[quarantine] www.archlinexp.eu:modules/mod_al_newsletter/mod_al_newsletter.xml -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/modules/mod_al_newsletter/mod_al_newsletter.xml)",
|
||||
"original_sha256": "63093cd4600619b21a0b611c46f598ec3074df45ec183860c0ff6119897ea0ce",
|
||||
"original_stat": {
|
||||
"gid": 30037,
|
||||
"mtime": 1666075362,
|
||||
"size": 2115,
|
||||
"uid": 20043
|
||||
},
|
||||
"rel_path": "modules/mod_al_newsletter/mod_al_newsletter.xml",
|
||||
"result": "quarantined",
|
||||
"timestamp": "20260718T160204Z",
|
||||
"vhost": "www.archlinexp.eu"
|
||||
}
|
||||
@ -0,0 +1,49 @@
|
||||
<?php defined('_JEXEC') or die; ?>
|
||||
|
||||
<!-- Modal -->
|
||||
<div class="modal" id="newsLetterSubscribeModal" tabindex="-1" role="dialog" aria-labelledby="termsModalLabel" aria-hidden="true">
|
||||
<div class="modal-dialog" role="document">
|
||||
<!-- Modal content-->
|
||||
<div class="modal-content">
|
||||
<div class="modal-header">
|
||||
<h4 class="modal-title"><?= JText::_('MOD_AL_NEWSLETTER_SUBSCRIBE_HEADER') ?></h4>
|
||||
<button type="button" class="close" data-dismiss="modal" aria-label="Close">
|
||||
<span aria-hidden="true">×</span>
|
||||
</button>
|
||||
</div>
|
||||
<div class="modal-body">
|
||||
<p><?= JText::_('MOD_AL_NEWSLETTER_SUBSCRIBE_TEXT') ?></p>
|
||||
<hr>
|
||||
|
||||
<form action="" method="post">
|
||||
<div class="form-group">
|
||||
<label for="name"><b><?= JText::_('MOD_AL_NEWSLETTER_NAME') ?>:</b></label>
|
||||
<input type="text" class="form-control" id="name" placeholder="<?= JText::_('MOD_AL_NEWSLETTER_NAME_PLACEHOLDER') ?>" name="name" required>
|
||||
</div>
|
||||
|
||||
<div class="form-group">
|
||||
<label for="email"><b><?= JText::_('MOD_AL_NEWSLETTER_EMAIL') ?>:</b></label>
|
||||
<input type="email" class="form-control" id="email" placeholder="<?= JText::_('MOD_AL_NEWSLETTER_EMAIL_PLACEHOLDER') ?>" name="email" required>
|
||||
</div>
|
||||
<br>
|
||||
|
||||
<button type="submit" name="subscribe-newsletter-btn" class="btn btn-primary"><?= JText::_('MOD_AL_NEWSLETTER_SUBSCRIBE_BTN') ?></button>
|
||||
</form>
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
|
||||
<script>
|
||||
jQuery(document).ready(function() {
|
||||
jQuery('#alNewsletterBtn').after('<button class="btn btn-primary" data-toggle="modal" data-target="#newsLetterSubscribeModal">Abonnieren</button>');
|
||||
|
||||
/*if (localStorage.getItem('al_newsletter') == null)
|
||||
jQuery("#newsLetterSubscribeModal").modal();*/
|
||||
|
||||
jQuery('#newsLetterSubscribeModal').on('shown.bs.modal', function(e) {
|
||||
if (localStorage.getItem('al_newsletter') == null)
|
||||
localStorage.setItem('al_newsletter', true);
|
||||
});
|
||||
});
|
||||
</script>
|
||||
@ -0,0 +1,15 @@
|
||||
{
|
||||
"finding_ref": "7249",
|
||||
"log_excerpt": "[quarantine] www.archlinexp.eu:modules/mod_al_newsletter/tmpl/default.php -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/modules/mod_al_newsletter/tmpl/default.php)",
|
||||
"original_sha256": "647148d53fa91736b4f4e5afa5e5f90987320636c0e8dbf132e02af872714b6e",
|
||||
"original_stat": {
|
||||
"gid": 30037,
|
||||
"mtime": 1673448300,
|
||||
"size": 2360,
|
||||
"uid": 20043
|
||||
},
|
||||
"rel_path": "modules/mod_al_newsletter/tmpl/default.php",
|
||||
"result": "quarantined",
|
||||
"timestamp": "20260718T160204Z",
|
||||
"vhost": "www.archlinexp.eu"
|
||||
}
|
||||
@ -0,0 +1,10 @@
|
||||
<!DOCTYPE HTML>
|
||||
<html>
|
||||
<head>
|
||||
<meta charset="utf-8">
|
||||
<title></title>
|
||||
</head>
|
||||
<body>
|
||||
<a href="http://xdsoft.net/joomla/module_generator/">Joomla Module Generator</a>
|
||||
</body>
|
||||
</html>
|
||||
@ -0,0 +1,15 @@
|
||||
{
|
||||
"finding_ref": "7248",
|
||||
"log_excerpt": "[quarantine] www.archlinexp.eu:modules/mod_al_newsletter/tmpl/index.html -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/modules/mod_al_newsletter/tmpl/index.html)",
|
||||
"original_sha256": "647cde511844340d9fac1c8247d2ddbcb03c29471da015a4eaf34224a623815d",
|
||||
"original_stat": {
|
||||
"gid": 30037,
|
||||
"mtime": 1666075362,
|
||||
"size": 191,
|
||||
"uid": 20043
|
||||
},
|
||||
"rel_path": "modules/mod_al_newsletter/tmpl/index.html",
|
||||
"result": "quarantined",
|
||||
"timestamp": "20260718T160204Z",
|
||||
"vhost": "www.archlinexp.eu"
|
||||
}
|
||||
149
var/www/hosting/archlinexp.eu/www/modules/mod_al_vote/helper.php
Normal file
149
var/www/hosting/archlinexp.eu/www/modules/mod_al_vote/helper.php
Normal file
@ -0,0 +1,149 @@
|
||||
<?php
|
||||
defined('_JEXEC') or die;
|
||||
|
||||
jimport('joomla.user.helper');
|
||||
|
||||
class ModAlVoteHelper
|
||||
{
|
||||
public static function getItem()
|
||||
{
|
||||
$result = array();
|
||||
|
||||
$user = JFactory::getUser();
|
||||
|
||||
$albumId = 4;
|
||||
|
||||
try {
|
||||
$db = JFactory::getDbo();
|
||||
$query = $db->getQuery(true)
|
||||
->select('a.*')
|
||||
->from('www_archline_hu.jml_speasyimagegallery_albums as a')
|
||||
->where('a.id = ' . (int) $albumId);
|
||||
|
||||
$query->select('l.title AS language_title')
|
||||
->leftJoin($db->quoteName('#__languages') . ' AS l ON l.lang_code = a.language');
|
||||
|
||||
$query->select('ua.name AS author_name')
|
||||
->leftJoin('#__users AS ua ON ua.id = a.created_by');
|
||||
|
||||
// Filter by published state.
|
||||
$query->where('a.published = 1');
|
||||
|
||||
$db->setQuery($query);
|
||||
$data = $db->loadObject();
|
||||
|
||||
if (isset($data->id) && $data->id) {
|
||||
$data->images = self::getImages($data->id);
|
||||
}
|
||||
|
||||
if (empty($data)) {
|
||||
return JError::raiseError(404, JText::_('COM_SPEASYIMAGEGALLERY_ERROR_ALBUM_NOT_FOUND'));
|
||||
}
|
||||
|
||||
$user = JFactory::getUser();
|
||||
$groups = $user->getAuthorisedViewLevels();
|
||||
if (!in_array($data->access, $groups)) {
|
||||
return JError::raiseError(404, JText::_('COM_SPEASYIMAGEGALLERY_ERROR_ALBUM_NOT_AUTHORISED'));
|
||||
}
|
||||
|
||||
$result[$albumId] = $data;
|
||||
} catch (Exception $e) {
|
||||
if ($e->getCode() == 404) {
|
||||
JError::raiseError(404, $e->getMessage());
|
||||
} else {
|
||||
$result[$albumId] = false;
|
||||
}
|
||||
}
|
||||
|
||||
return $result[$albumId];
|
||||
}
|
||||
|
||||
public static function isVoted($pictureId, $albumId, $userId)
|
||||
{
|
||||
$db = JFactory::getDbo();
|
||||
|
||||
$query = "SELECT id FROM www_archline_hu.al_picture_vote
|
||||
WHERE picture_id = {$pictureId} AND album_id = {$albumId} AND nUserID = {$userId}";
|
||||
$db->setQuery($query);
|
||||
$existingVote = $db->loadObject();
|
||||
|
||||
return !empty($existingVote);
|
||||
}
|
||||
|
||||
public static function getImages($album_id)
|
||||
{
|
||||
$db = JFactory::getDbo();
|
||||
$query = $db->getQuery(true);
|
||||
$query->select(array('a.*', 'b.picture_id', 'count(b.userID) AS voteCount'));
|
||||
$query->from($db->quoteName('www_archline_hu.jml_speasyimagegallery_images', 'a'));
|
||||
$query->join('LEFT', $db->quoteName('www_archline_hu.al_picture_vote', 'b') . ' ON ' . $db->quoteName('a.id') . ' = ' . $db->quoteName('b.picture_id'));
|
||||
$query->where($db->quoteName('a.album_id') . ' = ' . $db->quote($album_id));
|
||||
$query->where($db->quoteName('a.state') . ' = ' . $db->quote(1));
|
||||
$query->order('a.title ASC');
|
||||
$query->group($db->quoteName('a.id'));
|
||||
$db->setQuery($query);
|
||||
return $db->loadObjectList();
|
||||
}
|
||||
|
||||
public static function votePicture($pictureId, $albumId, $userId, $nUserID)
|
||||
{
|
||||
$db = JFactory::getDbo();
|
||||
|
||||
$query = "SELECT id FROM www_archline_hu.al_picture_vote
|
||||
WHERE picture_id = {$pictureId} AND album_id = {$albumId} AND nUserID = {$nUserID}";
|
||||
$db->setQuery($query);
|
||||
$existingVote = $db->loadObject();
|
||||
|
||||
if (!empty($existingVote))
|
||||
return false;
|
||||
|
||||
$vote = new stdClass();
|
||||
$vote->picture_id = $pictureId;
|
||||
$vote->album_id = $albumId;
|
||||
$vote->userID = $userId;
|
||||
$vote->nUserID = $nUserID;
|
||||
JFactory::getDbo()->insertObject('www_archline_hu.al_picture_vote', $vote);
|
||||
|
||||
if ($nUserID != null && $nUserID != '') {
|
||||
$topic = (JFactory::getLanguage()->getTag() == 'hu-HU' ? 322 : 153);
|
||||
|
||||
$query = "SELECT * FROM cl_hlusers.u_history
|
||||
WHERE nUserID = {$nUserID} AND nTopicID = {$topic} AND strPlace = 'Rendering pályázat 2023 szavazás'";
|
||||
$db->setQuery($query);
|
||||
$existingVote = $db->loadObject();
|
||||
|
||||
if (empty($existingVote)) {
|
||||
$history = new stdClass();
|
||||
$history->nUserID = $nUserID;
|
||||
$history->nTopicID = $topic;
|
||||
$history->dateEvent = date('Y-m-d');
|
||||
$history->strPlace = 'Rendering pályázat 2023 szavazás';
|
||||
$history->strInfo = 'Rendering pályázat 2023 szavazás';
|
||||
$history->nManagerID = 36;
|
||||
JFactory::getDbo()->insertObject('cl_hlusers.u_history', $history);
|
||||
}
|
||||
}
|
||||
|
||||
return true;
|
||||
}
|
||||
|
||||
public static function getWinnerPictures($album_id)
|
||||
{
|
||||
$db = JFactory::getDbo();
|
||||
$query = $db->getQuery(true);
|
||||
$query->select(array('a.*', 'b.*', 'count(b.userID) AS voteCount'));
|
||||
$query->from($db->quoteName('www_archline_hu.jml_speasyimagegallery_images', 'a'));
|
||||
$query->join('LEFT', $db->quoteName('www_archline_hu.al_picture_vote', 'b') . ' ON ' . $db->quoteName('a.id') . ' = ' . $db->quoteName('b.picture_id'));
|
||||
$query->where($db->quoteName('a.album_id') . ' = ' . $db->quote($album_id));
|
||||
$query->where($db->quoteName('a.state') . ' = ' . $db->quote(1));
|
||||
$query->order('count(b.userID) DESC');
|
||||
$query->group($db->quoteName('a.id'));
|
||||
$db->setQuery($query);
|
||||
$winners = $db->loadObjectList();
|
||||
|
||||
for ($i = 0; $i < count($winners); $i++)
|
||||
$winners[$i]->source = json_decode($winners[$i]->images);
|
||||
|
||||
return $winners;
|
||||
}
|
||||
}
|
||||
@ -0,0 +1,15 @@
|
||||
{
|
||||
"finding_ref": "7218",
|
||||
"log_excerpt": "[quarantine] www.archlinexp.eu:modules/mod_al_vote/helper.php -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/modules/mod_al_vote/helper.php)",
|
||||
"original_sha256": "0b5c924a705ef20a151755d51cc1ec0f6a14259dc95fe8275999c9fd5ccef384",
|
||||
"original_stat": {
|
||||
"gid": 30037,
|
||||
"mtime": 1676369734,
|
||||
"size": 5750,
|
||||
"uid": 20043
|
||||
},
|
||||
"rel_path": "modules/mod_al_vote/helper.php",
|
||||
"result": "quarantined",
|
||||
"timestamp": "20260718T160204Z",
|
||||
"vhost": "www.archlinexp.eu"
|
||||
}
|
||||
@ -0,0 +1,10 @@
|
||||
<!DOCTYPE HTML>
|
||||
<html>
|
||||
<head>
|
||||
<meta charset="utf-8">
|
||||
<title></title>
|
||||
</head>
|
||||
<body>
|
||||
<a href="http://xdsoft.net/joomla/module_generator/">Joomla Module Generator</a>
|
||||
</body>
|
||||
</html>
|
||||
@ -0,0 +1,15 @@
|
||||
{
|
||||
"finding_ref": "7216",
|
||||
"log_excerpt": "[quarantine] www.archlinexp.eu:modules/mod_al_vote/index.html -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/modules/mod_al_vote/index.html)",
|
||||
"original_sha256": "647cde511844340d9fac1c8247d2ddbcb03c29471da015a4eaf34224a623815d",
|
||||
"original_stat": {
|
||||
"gid": 30037,
|
||||
"mtime": 1676012882,
|
||||
"size": 191,
|
||||
"uid": 20043
|
||||
},
|
||||
"rel_path": "modules/mod_al_vote/index.html",
|
||||
"result": "quarantined",
|
||||
"timestamp": "20260718T160204Z",
|
||||
"vhost": "www.archlinexp.eu"
|
||||
}
|
||||
@ -0,0 +1,4 @@
|
||||
MOD_AL_VOTE_SUCCESS="Thank you for participating in the poll, your vote was valid. <br>
|
||||
Best regards, CadLine Kft."
|
||||
MOD_AL_VOTE_VOTE="Vote"
|
||||
MOD_AL_VOTE_VOTE_2="I vote"
|
||||
@ -0,0 +1,15 @@
|
||||
{
|
||||
"finding_ref": "7223",
|
||||
"log_excerpt": "[quarantine] www.archlinexp.eu:modules/mod_al_vote/language/de-DE/de-DE.mod_al_vote.ini -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/modules/mod_al_vote/language/de-DE/de-DE.mod_al_vote.ini)",
|
||||
"original_sha256": "b14f757d445fe29447b213ad3834a6485924704e56e103c95a0ddcf6a5d86b9b",
|
||||
"original_stat": {
|
||||
"gid": 30037,
|
||||
"mtime": 1676012882,
|
||||
"size": 170,
|
||||
"uid": 20043
|
||||
},
|
||||
"rel_path": "modules/mod_al_vote/language/de-DE/de-DE.mod_al_vote.ini",
|
||||
"result": "quarantined",
|
||||
"timestamp": "20260718T160204Z",
|
||||
"vhost": "www.archlinexp.eu"
|
||||
}
|
||||
@ -0,0 +1,7 @@
|
||||
MOD_AL_NEWSLETTER_SUBSCRIBE_HEADER="GET OUR NEWSLETTER"
|
||||
MOD_AL_NEWSLETTER_SUBSCRIBE_TEXT="Want the latest and greatest from our blog straight to your inbox? Chucks us your details and get a sweet weekly email."
|
||||
MOD_AL_NEWSLETTER_NAME="Name"
|
||||
MOD_AL_NEWSLETTER_NAME_PLACEHOLDER="Your name"
|
||||
MOD_AL_NEWSLETTER_EMAIL="Email"
|
||||
MOD_AL_NEWSLETTER_EMAIL_PLACEHOLDER="Your email address"
|
||||
MOD_AL_NEWSLETTER_SUBSCRIBE_BTN="Subscribe"
|
||||
@ -0,0 +1,15 @@
|
||||
{
|
||||
"finding_ref": "7222",
|
||||
"log_excerpt": "[quarantine] www.archlinexp.eu:modules/mod_al_vote/language/de-DE/de-DE.mod_al_vote.sys.ini -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/modules/mod_al_vote/language/de-DE/de-DE.mod_al_vote.sys.ini)",
|
||||
"original_sha256": "6aa67b1e7671a2e12d9eceea4dd8a01c9b053208d565b20ba961e0bb8a4d8793",
|
||||
"original_stat": {
|
||||
"gid": 30037,
|
||||
"mtime": 1676012882,
|
||||
"size": 426,
|
||||
"uid": 20043
|
||||
},
|
||||
"rel_path": "modules/mod_al_vote/language/de-DE/de-DE.mod_al_vote.sys.ini",
|
||||
"result": "quarantined",
|
||||
"timestamp": "20260718T160204Z",
|
||||
"vhost": "www.archlinexp.eu"
|
||||
}
|
||||
@ -0,0 +1,4 @@
|
||||
MOD_AL_VOTE_SUCCESS="Thank you for participating in the poll, your vote was valid. <br>
|
||||
Best regards, CadLine Kft."
|
||||
MOD_AL_VOTE_VOTE="Vote"
|
||||
MOD_AL_VOTE_VOTE_2="I vote"
|
||||
@ -0,0 +1,15 @@
|
||||
{
|
||||
"finding_ref": "7225",
|
||||
"log_excerpt": "[quarantine] www.archlinexp.eu:modules/mod_al_vote/language/en-GB/en-GB.mod_al_vote.ini -> quarantined (dest=/var/lib/web-hids/quarantine/var/www/hosting/archlinexp.eu/www/modules/mod_al_vote/language/en-GB/en-GB.mod_al_vote.ini)",
|
||||
"original_sha256": "b14f757d445fe29447b213ad3834a6485924704e56e103c95a0ddcf6a5d86b9b",
|
||||
"original_stat": {
|
||||
"gid": 30037,
|
||||
"mtime": 1676012882,
|
||||
"size": 170,
|
||||
"uid": 20043
|
||||
},
|
||||
"rel_path": "modules/mod_al_vote/language/en-GB/en-GB.mod_al_vote.ini",
|
||||
"result": "quarantined",
|
||||
"timestamp": "20260718T160204Z",
|
||||
"vhost": "www.archlinexp.eu"
|
||||
}
|
||||
Some files were not shown because too many files have changed in this diff Show More
Loading…
Reference in New Issue
Block a user