Are the xss and other security issues that were posted in this forum taken care of in the latest svn version of pligg?
Some kind of announcement should be posted to let folks know what's going on with it.
![]() |
| | LinkBack | Thread Tools | Display Modes |
| |||
| |
| |||
| Quote:
They probably shouldn't have been posted to the open forum, but now that they are "out there", I just wanted to make sure there was already a security patch. People should be notified and encouraged to upgrade as well to protect their pligg sites when stuff like that is found and patched. Last edited by Rodney; 10-10-2006 at 08:56 PM.. Reason: added more info :) |
| ||||
|
Rodney, that's why 8.1.0 was released. Because there were a lot of holes patched and we felt that they were big enough holes that they warranted a quick release. We've never had this many people tesing Pligg at one time and they're finding things that have never been reported before.
__________________ I accept donations for my time helping users like you on the forum and IRC. |
| |||
| Quote:
The whole post was removed, but I think it clearly stated the problems were in the 8.1.0 version of pligg. |
| ||||
|
Yeah, that's why Jit mentioned maybe even another release with the fixes you mentioned.
__________________ I accept donations for my time helping users like you on the forum and IRC. |
| ||||
|
Just to confirm. As soon as those were issues were brought up within minutes they were fixed in the svn. We havent released antoher update yet b/c we want to make sure we have fixed all similar issues we can find and then release an official update within a day or two. Pligg was tested by a lot of people before being released but as KB said the digg article has brought in soooo many people using pligg that other things have come up. Jitgos Jitgos |
| ||||
|
do you mean these: xss: http://www.pligg.com/forum/showthrea...light=security xss and sql injection http://www.pligg.com/forum/showthrea...light=security both have been fixed.
__________________ Anatomy of the Pligg template Help needed |
| |||
| Quote:
BTW, some problems were fixed incorrectly (ej. applying strip_tags instead of intval) |
| ||||
|
i will try and look for them in the forum. xknown thanks again for the security updates.
__________________ Anatomy of the Pligg template Help needed |
![]() |
« Previous Thread
|
Next Thread »
| Thread Tools | |
| Display Modes | |
| |
Similar Threads | ||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| 9.9.5 Specific Release Notes for Security Issues | margotb | Installation and Upgrade Help | 10 | 08-02-2008 10:11 AM |
| Use Pligg Security System for Non-pligg sites | byron | Modification Tutorials | 1 | 06-19-2007 12:49 PM |
| Reporting Security Vulnerabilities | jitgos | Bug Report | 0 | 10-09-2006 09:56 PM |





Linear Mode

