makaraci Posted September 28, 2010 Share Posted September 28, 2010 Hello,When http://www.mysitename.com/modules/ is written on the firefox,anyone can access my module files and download them.It is also same for /img, /themes, and every folder.So everyone can download my source file.I want to prevent it.When you write http://www.mysitename.com/modules/, you shouldnt go to modules files.When can i do it ? Link to comment Share on other sites More sharing options...
rocky Posted September 29, 2010 Share Posted September 29, 2010 I don't understand why that is happening. PrestaShop has an index.php file in the modules directory to prevent the folder's contents being listed. Did you upload modules/index.php to your server? Link to comment Share on other sites More sharing options...
makaraci Posted October 2, 2010 Author Share Posted October 2, 2010 Thanks Rocky.That file was missing .I just upload it and the problem is fixed.It was a securtiy hole ?And do i have to update to 1.3.2 ? I currently use 1.3.1 .Besy regards Link to comment Share on other sites More sharing options...
rocky Posted October 3, 2010 Share Posted October 3, 2010 I don't think it was a security hole, though it means anyone could see what modules you have on your server. If the individual module directories were also missing index.php files, then anyone would be able to download the module, including its PHP files. I don't think it would let anyone modify the files though.PrestaShop v1.3.2 is a bug fix release, so it is a good idea to upgrade. It may be difficult to upgrade depending on how many files you have modified. You can download just the files that were modified in my post here. If you haven't modified any of the files that were changed, it should be easy to upgrade. Link to comment Share on other sites More sharing options...
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now