Fair warning to everyone, 9.9 is RIDDLED with security holes. My pligg 9.9 site was running less than 24 hours and my hosting provider shut it down because it had been compromised and other scripts installed that were doing bad things. A few internet searches shows quite a few SQL injection bugs and total lack of sanitation of input parameters as well as a nice hack to get anyone's password.
If you are running pligg 9.9, you will be compromised very, very soon. Posting a quaint warning that there are security holes that have fixes and workarounds and not posting those fixes or workarounds is a complete disservice to the 16,000 people who have downloaded this version.
Does anyone know if these are only issues with 9.9 and can an older version be used? Due to the nature of these issues I am assuming it is probably all versions of pligg that are vulnerable.
Users beware, again, your 9.9 sites are wide open for attack and all anyone has to do is a quick google search to find your site and its all over.







Linear Mode




