JEvents 2.0 was launched over 2 years ago and the latest stable version is version 2.2 which will run on Joomla 1.5 and Joomla 2.5. JEvents 1.5 is therefore no longer actively supported - you should upgrade to JEvents 2.2+ as soon as possible.
Please include as much detail in any test or bug reports for JEvents 1.5 as possible.
First of all, check if you are running the latest available version of Joomla! and JEvents. Posts for issues, where both systems are not updated, will be ignored.
We need the following at least:
* PHP version (e.g. 5.2.5). Note: Support for PHP4 is discontinued.
* Joomla! version
* JEvents version
* Web Server software (Apache or IIS with version number if possible)
* Server Operating system (e.g. Linux, Windows, Solaris, Darwin ...)
* Database version
* memory_limit from your phpinfo
* Web browser and version
Please enable error reporting and include any error messages in your posting. You do this via the Joomla Configuration - set "error reporting" to "maximum" on the Server tab.
Finally, please describe the steps required to recreate the problem and also please enable error reporting and give us any error messages generated.
After a recent site hack I have installed Admin Tools Pro across all my Joomla sites and have noticed it is picking up a lot of attempts aimed at JEvents, e.g.
These are classed as template= in URL attacks, not to sure what that means?
I am not too concerned at these attempts but does anyone know what they are trying to do by doing this?
I have the latest version of Joomla (1.5.25) and JEvents (2.0.11)
- Posts: 5
- Joined: Wed May 26, 2010 9:24 am
They might be trying to use the XSS ( Cross Site Scripting ) security bug that was found in JEvents 1.5.5 and prior and iirc 2.0.10 and prior.
However, you are running 2.0.11 so safe
Feel free to PM me if you would like Custom Installs or Joomla! related work for a competitive quote.
- Team Staff
- Posts: 23698
- Joined: Tue Oct 12, 2010 9:12 pm
- Location: Isle of Man
This is not a hack attempt - it is a typo in the code.
In the file components/com_jevents/libraries/jeventcal.php line 627 should read
- Code: Select all
$link = "index.php?option=".JEV_COM_COMPONENT."&task=icals.$task&tmpl=component&evid=".$this->id()
- Code: Select all
$link = "index.php?option=".JEV_COM_COMPONENT."&task=icals.$task&template=component&evid=".$this->id()
Version 2.1.6 will incorporate this change.
- Posts: 42795
- Joined: Fri Feb 15, 2008 6:14 pm
Return to JEvents 1.5 (No longer actively supported)