WordPress.org

Ready to get started?Download WordPress

Forums

wp-FileManager
[resolved] Root access (6 posts)

  1. rolfnilsson
    Member
    Posted 8 months ago #

    Hi,

    a friend of mine are using my server as webserver. I installed wordpress for him and now he installed wp-filemanager. Then he gets root access to the server. He can see and download all the files on the server from /. What have I or him done wrong?

    http://wordpress.org/plugins/wp-filemanager/

  2. anantshri
    Member
    Plugin Author

    Posted 8 months ago #

    You need to change the setting for home directory. however he will have the ability to change it whenever he wants.

    Also this plugin was suppose to be for administrators, I never conceptualized this scenario, while designing the permission model.

  3. rolfnilsson
    Member
    Posted 8 months ago #

    Okay, now I know. Thank you for the fast answer.

  4. Gadget57
    Member
    Posted 6 months ago #

    rolfnilsson,
    I have been able to change access ability to various users with Advanced Access Manager. You can find it at

    Thanks,
    Mike

  5. anantshri
    Member
    Plugin Author

    Posted 6 months ago #

    Thanks for the heads up.
    However i would still suggest the permission model is not suppose to be used by this plugin. considering the various possible abuse scenario's of this plugin it is restricted only to admin.

    However if you have spotted a way to make it workable for your specific environment, feel free to write a blog post or a article about the same. However i will not be able to mark is as an official method.

  6. ETGSupport
    Member
    Posted 2 months ago #

    Are you nuts? You created a plugin that anyone can install and browse and download files from the entire server?

Reply

You must log in to post.

About this Plugin

About this Topic

Tags

No tags yet.