Hi - I have just started using FCKeditor. Its great! I have however hit a problem.
I have it all working and integrated using javascript where the html is created by perl. I am now starting to use it for a real job. I have been copying large chunks of text from other documents into the editor. The problem is - certain word combinations in the edit text cause it to crash!
So far if I have any of the words 'enhanced natural .co' (anywhere in the text in that order) or ''selection from'' anywhere in the text in that order or 'update information from <anything>', when I submit the form the editor crashes. Other than that - everything is working fine.
Plainly there may be other combinations that cause failure but I have isolated these combinations. This bug seems bizarre.
Can anyone help?
Thanks
I have just found this in the forum - a two year old issue - anyone think this has anything to do with the problems?
---------------------------------------------------------
I've installed FCKeditor into my MediaWiki installation. When it works, I love it. However, it fails about 50% of the time.
Basically, I do an edit on an existing page and when I save I get an Internal Server Error.
Here's the text from the Apache server log:
[Thu Sep 21 16:29:08 2006] [error] [client 10.129.1.109] mod_security: Access denied with code 500. Pattern match "((select|grant|delete|insert|drop|alter|replace|truncate|update|create|rename|describe)[[:space:]]+[A-Z|a-z|0-9|\\\\*| |\\\\,]+[[:space:]]+(from|into|table|database|index|view)[[:space:]]+[A-Z|a-z|0-9|\\\\*| |\\\\,]|UNION SELECT.*\\\\'.*\\\\'.*,[0-9].*INTO.*FROM)" at POST_PAYLOAD [id "300013"] [rev "1"] [msg "Generic SQL injection protection"] [severity "2"] [hostname "warner.support"] [uri "/index.php?title=Main_Page&action=submit"]
Before you pass me off to Apache, bear in mind that I've also asked them for assistance and am fearful they will send me back to FCK.
---------------------------------------------------------
Info on the way I have integrated the editor:
A perl program submits the following fragment embedded in a normal html definition
$edit_data contains the last set of data when it was submitted
<script type="text/javascript">
var oFCKeditor = new FCKeditor('editor_data');
oFCKeditor.BasePath = "../editor/";
oFCKeditor.Height = 500 ;
oFCKeditor.Value = '$edit_data' ;
oFCKeditor.Create();
</script>
I have it all working and integrated using javascript where the html is created by perl. I am now starting to use it for a real job. I have been copying large chunks of text from other documents into the editor. The problem is - certain word combinations in the edit text cause it to crash!
So far if I have any of the words 'enhanced natural .co' (anywhere in the text in that order) or ''selection from'' anywhere in the text in that order or 'update information from <anything>', when I submit the form the editor crashes. Other than that - everything is working fine.
Plainly there may be other combinations that cause failure but I have isolated these combinations. This bug seems bizarre.
Can anyone help?
Thanks
I have just found this in the forum - a two year old issue - anyone think this has anything to do with the problems?
---------------------------------------------------------
I've installed FCKeditor into my MediaWiki installation. When it works, I love it. However, it fails about 50% of the time.
Basically, I do an edit on an existing page and when I save I get an Internal Server Error.
Here's the text from the Apache server log:
[Thu Sep 21 16:29:08 2006] [error] [client 10.129.1.109] mod_security: Access denied with code 500. Pattern match "((select|grant|delete|insert|drop|alter|replace|truncate|update|create|rename|describe)[[:space:]]+[A-Z|a-z|0-9|\\\\*| |\\\\,]+[[:space:]]+(from|into|table|database|index|view)[[:space:]]+[A-Z|a-z|0-9|\\\\*| |\\\\,]|UNION SELECT.*\\\\'.*\\\\'.*,[0-9].*INTO.*FROM)" at POST_PAYLOAD [id "300013"] [rev "1"] [msg "Generic SQL injection protection"] [severity "2"] [hostname "warner.support"] [uri "/index.php?title=Main_Page&action=submit"]
Before you pass me off to Apache, bear in mind that I've also asked them for assistance and am fearful they will send me back to FCK.
---------------------------------------------------------
Info on the way I have integrated the editor:
A perl program submits the following fragment embedded in a normal html definition
$edit_data contains the last set of data when it was submitted
<script type="text/javascript">
var oFCKeditor = new FCKeditor('editor_data');
oFCKeditor.BasePath = "../editor/";
oFCKeditor.Height = 500 ;
oFCKeditor.Value = '$edit_data' ;
oFCKeditor.Create();
</script>
Re: Certain words cause editor crash.
Put a textarea
test with those strings again and you'll understand that FCKeditor isn't crashing.
Re: Certain words cause editor crash.
Hi - I tried the things you suggested and it made no difference. Possibly when you say read the doc there is a part I should read that I have not read yet? If so - please point me at the relevant part?
However - I do seem to have found a less than ideal fix. By disabling Mod_Security the problem goes away. I'm sure this is not a good idea?
By creating a file .htaccess with the following in it:
SecFilterEngine Off
SecFilterScanPOST Off
and putting this file in the root of the website the problem goes away.
This link
https://support.webhost.co.nz/?group=op ... icleid=159
explains.
If anyone knows of a way round having to do this please let me know.