Page 1 of 1

Security Issue

PostPosted: 06 Apr 2016, 22:58
by falcodj
I had a problem to upload images for photo listings and I contacted my web host propvider. He replied


The application does not conform to security standards and it was triggering a ModSecurity rule, (OWASP 960010 Request content type is not allowed by policy)

I have disabled this rule (not ideal solution)

This is now working.

I believe that this causes a security problem

Re: Security Issue

PostPosted: 07 Apr 2016, 08:10
by Xpycm
You may enable mod_security2.so and send us your domain and ftp access data (via contact form : https://monoray.net/contact). we will try to fix the problem and add changes in product

Re: Security Issue

PostPosted: 27 Jun 2016, 19:50
by Xpycm
UPD:

Put this:
SecFilterEngine Off
in the .htaccess.

LINKS:
http://pumastudios.com/2009/05/file-upl ... in-ajaxphp