• Azbuildstuff

    (@azbuildstuff)


    Past events will not display in admin/events. They do display on the front end. All other plugins are disabled. Switched to generic TwentyFifteen theme. Disabled and or removed all security in htacess.
    cPanel Server PHP 5.6.16 Apache 2.4 SQL 5.5.48
    When I try to filter All Events it bounces me out of admin.

    Disabled ModSecurity and everything works. This on a base install as explained above. Never had a plugin or site conflict with ModSecurity before. Can you take a look at your code and see if this can be resolved. Can not run without ModSecurity.

    Thank you.

    https://www.ads-software.com/plugins/events-manager/

Viewing 5 replies - 1 through 5 (of 5 total)
  • Plugin Support angelo_nwl

    (@angelo_nwl)

    maybe you can try to check your php logs or enable wp_debug to see if there’s any other error which can help us.

    Thread Starter Azbuildstuff

    (@azbuildstuff)

    Thank you for the response.

    wp_debug is enabled and I am not getting any errors in admin or main log. I checked the servers error log and nothing there. It is as if Mod sees Event filter as a threat and blocks it. Similar to the problem Event had with cPanel CSF last November in the sense that Event Calander filter seems to be triggering a false positive.

    We have about 30 other WordPress sites on the shared server and others on other servers and have never seen anything like this before.

    Apache/2.4.18 (Unix) OpenSSL/1.0.1e-fips mod_bwlimited/1.4 mod_fcgid/2.3.9
    PHP 5.6.16

    Thread Starter Azbuildstuff

    (@azbuildstuff)

    Here is the ModSecurity record of the security response to Events Calander All Events filter action.

    CRITICAL 302 SQL Injection Attack: SQL Tautology Detected
    Request:
    GET/wp-admin/edit.php?s=&post_status=all&post_type=event&_wpnonce=e6796e2654&_wp_http_referer=%2Fwp-admin%2Fedit.php%3Fpost_type%3Devent&action=-1&m=0&scope=all&filter_action=Filter&paged=1&action2=-1
    Action Description:
    Access denied with redirection to http:/domain.com/ using status 302 (phase 2).
    Justification:
    Pattern match “(?i:([\\s’\”\\(\\)]*?)([\\d\\w]++)([\\s'\"\\(\\)]*?)(?:(?:=|<=>|r?like|sounds\\s+like|regexp)([\\s’\”\\(\\)]*?)\\2|(?:!=|<=|>=|<>|<|>|\\^|is\\s+not|not\\s+like|not\\s+regexp)([\\s'\"\\(\\)]*?)(?!\\2)([\\d\\w]+)))” at ARGS:_wp_http_referer.

    Plugin is definitely triggering ModSecurity.

    caimin_nwl

    (@caimin_nwl)

    Which version of Events Manager and WordPress are you using?

    Can you test with all other plugins deactivated and while running the default WordPress theme?

    Thread Starter Azbuildstuff

    (@azbuildstuff)

    Through this whole trouble shooting prosess all pluggins have been disabled, WP 4.4.2, switched to 2015 and latest EC 5.6.2

Viewing 5 replies - 1 through 5 (of 5 total)
  • The topic ‘Past Events Missing in Admin’ is closed to new replies.