You are not logged in.
elwins wrote:
Its default code
In such case, I would advice uninstalling the plugin. It’s not safe to use.
Last edited by Gocom (2011-12-17 05:45:53)
Rah-plugins | What? I’m a little confused… again :-) <txp:is_god />
Offline
elwins
I’ve already donethe category thing, and more besides, in my (unreleased) modded version. I can’t remember how many of the security loopholes I closed offhand. Maybe some, maybe none — it was a loooong time ago I last looked at it. I’m due to revisit this over the next few weeks if you can wait a bit.
Gocom
In case you’re at a loose end over the holidays, could you please jot down some of the security issues and let me have them by e-mail. I can see a bunch of them in the code above (unescaped things, lack of doSlash(), etc) which I’ve probably caught already, but in case I missed any I’d appreciate your expertise on this. Thanks, man.
Last edited by Bloke (2011-12-17 08:23:00)
The smd plugin menagerie — for when you need one more gribble of power from Textpattern.
Txp Builders – finely-crafted code, design and Txp
Offline
Bloke wrote:
I’ve already donethe category thing, and more besides, in my (unreleased) modded version. I can’t remember how many of the security loopholes I closed offhand. Maybe some, maybe none — it was a loooong time ago I last looked at it. I’m due to revisit this over the next few weeks if you can wait a bit.
maybe you can give me now that category thing? I Just need to get visual side done, and then later, security side.
Last edited by elwins (2011-12-17 14:34:55)
Offline
elwins wrote:
maybe you can give me now that category thing? I Just need to get visual side done, and then later, security side.
Not right now. I’m travelling and it’s at home. maybe when I get back.
The smd plugin menagerie — for when you need one more gribble of power from Textpattern.
Txp Builders – finely-crafted code, design and Txp
Offline