Re: GSoC2016 Call for Students

2016-03-25 Thread Ankush Mishra
I am willing to explain it here, just that adding all this detail in might be heavy to the proposal, I'll add a line or so about it to the proposal. In fact, I had to skip a lot of detail in my proposal because it felt too long. Anyway, my project should allow the ability to add multiple

Re: Re: GSoC2016 Call for Students

2016-03-25 Thread Maxim Solodovnik
I would like to see your updated plan Actually I believe you should drive this project :) On Fri, Mar 25, 2016 at 8:26 PM, Ankush Mishra wrote: > Do you want me to add that detail in? I might have missed that detail from > the bug issue. Still have 4 hours remaining.

Re: Re: GSoC2016 Call for Students

2016-03-25 Thread Ankush Mishra
Do you want me to add that detail in? I might have missed that detail from the bug issue. Still have 4 hours remaining. Also, I think Sebastian might have gone off to sleep if he's in NZ. Ankush Mishra On 25 Mar 2016 19:48, "Ankush Mishra" wrote: > I think that

Re: Re: GSoC2016 Call for Students

2016-03-25 Thread Ankush Mishra
I think that export/import of user Calendar for iCal isn't exactly CalDAV but is fairly easy to implement. Ankush Mishra On 25 Mar 2016 19:44, "Maxim Solodovnik" wrote: > I believe it shouldn't be full featured CalDav server > Minimum requirements to export full user

Fwd: Re: GSoC2016 Call for Students

2016-03-25 Thread Ankush Mishra
Hey Maxim, From the Bug Tracker: https://issues.apache.org/jira/browse/OPENMEETINGS-553 The title only talks about syncing events using CalDAV and export/import of iCal. Now, that I think about it, it could quite possibly mean that as well. Do you want me to add that to the proposal? I still

[CVE-2016-2164] Arbitrary file read via SOAP API

2016-03-25 Thread Maxim Solodovnik
Severity: Critical Vendor: The Apache Software Foundation Versions Affected: Apache OpenMeetings 1.9.x - 3.0.7 Description: When attempting to upload a file via the API using the importFileByInternalUserId or importFile methods in the FileService, it is possible to read arbitrary files from the

[CVE-2016-2163] Stored Cross Site Scripting in Event description

2016-03-25 Thread Maxim Solodovnik
Severity: Moderate Vendor: The Apache Software Foundation Versions Affected: Apache OpenMeetings 1.9.x - 3.0.7 Description: When creating an event, it is possible to create clickable URL links in the event description. These links will be present inside the event details once a participant

[CVE-2016-0784] ZIP file path traversal

2016-03-25 Thread Maxim Solodovnik
Severity: Moderate Vendor: The Apache Software Foundation Versions Affected: Apache OpenMeetings 1.9.x - 3.1.0 Description: The Import/Export System Backups functionality in the OpenMeetings Administration menu (http://domain:5080/openmeetings/#admin/backup) is vulnerable to path traversal via

Re: GSoC2016 Call for Students

2016-03-25 Thread Dmitriy -
Hello Sebastian, Last version of proposal is here https://dropmefiles.com/3q2MK Many thanks for all. On Fri, Mar 25, 2016 at 3:05 PM, Maxim Solodovnik wrote: > Hello Ankush, Sebastian, > > just have checked the proposal > Are we sure we going to turn OM to CalDAV client?

Re: GSoC2016 Call for Students

2016-03-25 Thread Maxim Solodovnik
Hello Ankush, Sebastian, just have checked the proposal Are we sure we going to turn OM to CalDAV client? I was sure OM going to be CalDAV server Additionally there might be good idea to add ability to display custom user calendars (like calendar.google.com) fullcalendar can o it for us for

Re: [DISCUSSION] GSOC 2016 ideas

2016-03-25 Thread Dmitriy -
Yeah, I downloaded previous version on the site yesterday, but we have enough time to make some changes. I updated the proposal: https://dropmefiles.com/MUggI On Fri, Mar 25, 2016 at 3:20 AM, seba.wag...@gmail.com < seba.wag...@gmail.com> wrote: > Ah it's already submitted. I will apply to