Well I was just going to top the thread but.... I just installed a fresh FC2, Updated it, and since I now have a build machine decided to build FC2 packages to hopefully help resolve this weird issue..
Instead I have duplicated it
PHP Version 4.3.10
Linux FC2builder 2.6.10-1.770_FC2 #1 Sat Feb 26 21:40:22 EST 2005 i686
Apache Version Apache/2.0.51 (Fedora)
Your MySQL server version: 3.23.58
Apache error log
Code: Select all
[Sat Mar 19 20:21:20 2005] [error] [client 192.168.10.10] Premature end of script headers: zms, referer: http://192.168.10.35/zm/index.php?view=watchfeed&mode=&mid=1&scale=100
[client 192.168.10.10] PHP Notice: import_request_variables(): No prefix specified - possible security hazard in /usr/lib/zm/html/zm.php on line 21, referer: http://192.168.10.35/zm/index.php?view=watchstatus&mid=1
Error, insufficient privileges for requested action
[client 192.168.10.10] PHP Notice: import_request_variables(): No prefix specified - possible security hazard in /usr/lib/zm/html/zm.php on line 21, referer: http://192.168.10.35/zm/index.php?view=watchstatus&mid=1&last_status=
[root@FC2builder root]# ls -l /usr/lib |grep zm
drwxr-xr-x 7 apache apache 4096 Mar 19 17:26 zm
[root@FC2builder root]# ls -l /usr/lib/zm
total 20
drwxr-xr-x 2 apache apache 4096 Mar 19 17:26 bin
drwxr-xr-x 2 apache apache 4096 Mar 19 17:26 cgi-bin
drwxr-xr-x 3 apache apache 4096 Mar 19 17:26 html
drwxr-xr-x 2 apache apache 4096 Mar 19 17:26 init
drwxr-xr-x 2 apache apache 4096 Mar 19 17:26 upgrade
As you can see I even tried to change ownership to apache. I figured it wasn't here.
- Messages log - error_reporting( E_ALL );
Code: Select all
Mar 19 20:35:44 FC2builder zms[4975]: ERR [Error, insufficient privileges for requested action]
Mar 19 20:35:49 FC2builder zmu[4978]: ERR [AA:1]
Mar 19 20:35:54 FC2builder zmu[4981]: ERR [AA:1]
Mar 19 20:36:00 FC2builder zmu[4983]: ERR [AA:1]
Mar 19 20:36:06 FC2builder zmu[4985]: ERR [AA:1]
Debug
PHP Variables
Code: Select all
Variable Value
_REQUEST["view"] watch
_REQUEST["mid"] 1
_REQUEST["bandwidth"] medium
_REQUEST["ZMSESSID"] 40b4266f87b3d39b48cc23221bf60c39
_GET["view"] watch
_GET["mid"] 1
_COOKIE["bandwidth"] medium
_COOKIE["ZMSESSID"] 40b4266f87b3d39b48cc23221bf60c39
_SERVER["HTTP_HOST"] 192.168.10.35
_SERVER["HTTP_USER_AGENT"] Mozilla/5.0 (X11; U; Linux i686; en-US; rv:1.7.6) Gecko/20050302 Firefox/1.0.1 Fedora/1.0.1-1.3.2
_SERVER["HTTP_ACCEPT"] text/xml,application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
_SERVER["HTTP_ACCEPT_LANGUAGE"] en-us,en;q=0.5
_SERVER["HTTP_ACCEPT_ENCODING"] gzip,deflate
_SERVER["HTTP_ACCEPT_CHARSET"] ISO-8859-1,utf-8;q=0.7,*;q=0.7
_SERVER["HTTP_KEEP_ALIVE"] 300
_SERVER["HTTP_CONNECTION"] keep-alive
_SERVER["HTTP_REFERER"] http://192.168.10.35/zm/index.php
_SERVER["HTTP_COOKIE"] bandwidth=medium; ZMSESSID=40b4266f87b3d39b48cc23221bf60c39
_SERVER["PATH"] /sbin:/usr/sbin:/bin:/usr/bin:/usr/X11R6/bin
_SERVER["SERVER_SIGNATURE"] <address>Apache/2.0.51 (Fedora) Server at 192.168.10.35 Port 80</address>
_SERVER["SERVER_SOFTWARE"] Apache/2.0.51 (Fedora)
_SERVER["SERVER_NAME"] 192.168.10.35
_SERVER["SERVER_ADDR"] 192.168.10.35
_SERVER["SERVER_PORT"] 80
_SERVER["REMOTE_ADDR"] 192.168.10.10
_SERVER["DOCUMENT_ROOT"] /var/www/html
_SERVER["SERVER_ADMIN"] root@localhost
_SERVER["SCRIPT_FILENAME"] /usr/lib/zm/html/index.php
_SERVER["REMOTE_PORT"] 34266
_SERVER["GATEWAY_INTERFACE"] CGI/1.1
_SERVER["SERVER_PROTOCOL"] HTTP/1.1
_SERVER["REQUEST_METHOD"] GET
_SERVER["QUERY_STRING"] view=watch&mid=1
_SERVER["REQUEST_URI"] /zm/index.php?view=watch&mid=1
_SERVER["SCRIPT_NAME"] /zm/index.php
_SERVER["PHP_SELF"] /zm/index.php
_SERVER["PATH_TRANSLATED"] /usr/lib/zm/html/index.php
_SERVER["argv"]
Array
(
[0] => view=watch&mid=1
)
_SERVER["argc"] 1
_ENV["SELINUX_INIT"] YES
_ENV["CONSOLE"] /dev/pts/0
_ENV["TERM"] linux
_ENV["INIT_VERSION"] sysvinit-2.85
_ENV["PATH"] /sbin:/usr/sbin:/bin:/usr/bin:/usr/X11R6/bin
_ENV["RUNLEVEL"] 5
_ENV["runlevel"] 5
_ENV["PWD"] /
_ENV["LANG"] en_US.UTF-8
_ENV["PREVLEVEL"] N
_ENV["previous"] N
_ENV["SHLVL"] 2
_ENV["_"] /sbin/initlog
http://cordel.no-ip.info:10000/info.php