####################### # chillyCMS changelog # ####################### Legend: ####### ! Security issue * Bugfixing + Update of functionality & Database update % Optimizing - Removal @ Design # 1.3.1 ################################################################################ 12.03.13 # + added conditional display of submodules & added 3 new columns to site_modules * fixed bug in form class /fieldset ! removed template upload from admin/design.php. has to be done from ftp for security reasons ! added die() after header-redirects in session class and session include files - removed botdetection email because of spam from old versions # 1.3.0 ################################################################################ 07.10.11 # + now using ckeditor 3.6.2 @ restyled installation process * fixed double db installation bug % now using phpmailer for the contact form * fixed language bugs in contact/login * fixed language issues in frontendpage.class.php,tools.include.php * fixed language style issues in blue.css,backend.css + changed the following files: credits.include.php * fixed a little language bug in frontendpage.class concerning the logout * updated bugtrap language files + made a readme file + extended webuser class + added spanish language file * fixed guestbook doubleentry error + made demo content in installer optional + updated ckeditor to the newest version * fixed issue with url when chillycms runs in maindir of webspace * fixed display of subcontents bug * fixed bug with $myuser right after login * fixed module upload bug * fixed saving bug concerning menus (depth=1) ! restricted access to includes and classes + added form.class, formelement.class in core so all forms have integrated tokens. yay! % used the form classes for the installation routine % optimized the backup installation routine * fixed menu css current bug (also in template css) % noticed E_ALL had turned off at a os reinstall. Changed it and eliminated lots of noticed - again. + added the recaptchalib to the chilly core. thank you guys! * worked on (backup-)installation routines. just one bug left (try 2 times at recovery) * fixed content subitem filtering (active/access/specialaccess) * install.site.php missing a / # 1.2.1 ################################################################################ 21.11.10 # * fixed modules upload bug (core/module.class.php) * fixed display of inactive content items (core/frontendpage.class.php) * fixed display bug with too long names (admin/(insertpictures,insertfiles,internallink).include.php) @ changed button margins (style/css/backend.css) + updated language files % deleted admin/menu.include.php % got rid of show.site.php and made all the changes (admin/core/various modules) @ made the default (blue) template better + extended installation routine for automatic module installation * made special routine for updating updater # 1.2.0 ################################################################################ 05.10.10 # + finished basic functions of debug mode % removed db_query functions, so each query is made by the page object - removed core/html.include.php, core/site.class.php and admin/menu.include.php + generating description metatag now from content * fixed save bug (parentid=0) * fixed subarticle display options bug % optimized number of database queries * fixed backendstyle switching delay + extended debug mode + added update tool * fixed saving bug for new content ! fixed issue found here: http://www.exploit-db.com/exploits/14897/ thank you! * worked an the backup installer @ made the blue backend style much cooler # 1.1.3 ################################################################################ 22.06.10 # + titles of articles are now linked to the article + allowed center html tag * fixed missing metatags in frontend + modified javascript display toggle ! fixed blind sql injection in editprofile (thank you evilsocket!) + updated .htaccess file ! now asking for the old password when changing an admin password ! changed hash algorithm to SHA512 for password hashes * now telling the user if backup creation was not successful * fixed backup zip error * discovered error_reporting(E_ALL) and made the code better :) & added debug_mode to site_settings % made classes page, backendpage and frontendpage for better oo programming style + made a debug mode for further optimization & renamed writerights in system_groups to write # 1.1.2 ################################################################################ 30.04.10 # * fixed tablesort-form bug * fixed delete file bug in media manager * fixed reload bug in content and user edit page * fixed get/post mainmod-bug in content edit page + hid last login/number of logins from everybody except admins * prevented session transfer from frontend to backend % beautified the content overview page (backend) * fixed special access bug in menu module + added backend link to login module for authorized users * fixed writeaccess in content page * fixed missing metatags bug # 1.1.1 ################################################################################ 20.04.10 # * fixed problems with file class in media manager + moved mimetype array to seperate file core/mime.php * fixed display of feedback in tools * fixed double visitor counting bug ! fixed security issue in frontend login module * fixed backup bug in zipper class * repaired add/kickout menu in groupform ! moved most of the GET forms and links to POST + removed counting of most of the bots in the site class # 1.1.0 ################################################################################ 29.03.10 # & removed prev & next values from site_content & site_modules & renamed system_users status to active & added order to site_content & site_modules % now using nested lists instead of doubly linked lists for site_content and site_modules * fixed bug with multiple "inactive" modules + Made it possible to have a depth>2 + changing parent of content is now possible * fixed site_visitors percentage bug ! fixed security issue in template manager + added tmp dir for temporary files + added module/template update functionality % removed old zip library, now using ZipArchive & added advanced settings and rewrote db_settings table * fixed content saving error bug + added a maintenance mode + added readon links + added various content display options + updated ckeditor to version 3.2 * admins can now be in a group (eg for receiving newsletters) % using now divs in media manager instead of a table * fixed permissions bug in content/edit + added "File" class + made demodata for "full" installer # 1.0.3 ########################################################################################### + extended backup to module tables * fixed errors in backup installer + added country support to the webstats + added webstats to backend & converted database tables to innodb engine * backend specialaccess for admins only! * fixed customer feedback form bug + added dofirst support for modules % optimized backendtemplates (concerning images) + added feedback to analysis tool * fixed dropdown bug in menu module + added change access links for modules # 1.0.2 ########################################################################################### ! made the session management more secure * fixed copy&paste errors in output + updated language files & added getnewsletter field to system_users + made new backend template "blue" * fixed bug in content edit + added newsletter functionality # 1.0.1 ########################################################################################### ! fixed security issue in media manager * fixed bug with login messages + made newsletter gui + languages now choosable per user * fixed admin password bug ###################################################################################################