(REMOVED BY KLEMEN)
Nemanja, thanks for bringing this to my attention. I removed your post from here to avoid any misuse. This indeed seems to be an issue if the server is not configured to force mime headers properly, will have a look at it ASAP and post the results.
Regards,
Klemen
Serious XSS vulnerability (in v.0.94)
Moderator: mkoch227
This issue has been fixed. I strongly recommend anyone using Hesk 0.94 to update to 0.94.1. You can get it from here:
http://www.phpjunkyard.com/free-helpdesk-software.php
Update is quick and easy and you won't loose any current settings/tickets.
http://www.phpjunkyard.com/free-helpdesk-software.php
Update is quick and easy and you won't loose any current settings/tickets.
Klemen, creator of HESK and PHPJunkyardWas this helpful? You can buy me a drink here 
You should follow me on Twitter here
Help desk software | Cloud help desk | Guestbook | Link manager | Click counter | more PHP Scripts ...
Also browse for php hosting companies, read php books, find php resources and use webmaster tools


Help desk software | Cloud help desk | Guestbook | Link manager | Click counter | more PHP Scripts ...
Also browse for php hosting companies, read php books, find php resources and use webmaster tools
if you are upgrading from 0.94 you shouldn't lose the header.txt if you follow readme instructions 

Klemen, creator of HESK and PHPJunkyardWas this helpful? You can buy me a drink here 
You should follow me on Twitter here
Help desk software | Cloud help desk | Guestbook | Link manager | Click counter | more PHP Scripts ...
Also browse for php hosting companies, read php books, find php resources and use webmaster tools


Help desk software | Cloud help desk | Guestbook | Link manager | Click counter | more PHP Scripts ...
Also browse for php hosting companies, read php books, find php resources and use webmaster tools
Just FYI, I discovered a couple things that the upgrade did "break", but they were customizations to fields contained tickets that we talked about in the following posts (where you gave me the instructions):
viewtopic.php?p=5914&highlight=#5896
viewtopic.php?p=5914&highlight=#5909
Going to try to re-apply them shortly and see if they work again.
EDIT - applied the instructions again, works fine, you rock!
viewtopic.php?p=5914&highlight=#5896
viewtopic.php?p=5914&highlight=#5909
Going to try to re-apply them shortly and see if they work again.
EDIT - applied the instructions again, works fine, you rock!

Last edited by DigiMon on Mon Oct 29, 2007 11:55 pm, edited 1 time in total.
Yeah, didn't include any other edits or anything with this release, just the patch. Fixes should still work, just line numbers can be different.
I will probably release a bigger update with new functionality in the next few months.
I will probably release a bigger update with new functionality in the next few months.
Klemen, creator of HESK and PHPJunkyardWas this helpful? You can buy me a drink here 
You should follow me on Twitter here
Help desk software | Cloud help desk | Guestbook | Link manager | Click counter | more PHP Scripts ...
Also browse for php hosting companies, read php books, find php resources and use webmaster tools


Help desk software | Cloud help desk | Guestbook | Link manager | Click counter | more PHP Scripts ...
Also browse for php hosting companies, read php books, find php resources and use webmaster tools