Textpattern CMS support forum
You are not logged in. Register | Login | Help
- Topics: Active | Unanswered
Re: [request] Articles Rating plugin - very-very needed
Which ones Jukka?
Offline
Re: [request] Articles Rating plugin - very-very needed
tye wrote:
Which ones Jukka?
Without disclosing the actual vulnerabilities, for instance geo_vote allows attacker full server control. I’ve sent the details to Geoff yesterday after reviewing the code.
Others are, expect cbe_helpful, are very old and I haven’t reviewed their source code in recent history to say anything about them. But, as it’s worth, I wouldn’t necessarily recommend using orphaned plugins.
I’ve found way too many security vulnerabilities and holes from Textpattern websites and plugins as of late :/
Offline
Re: [request] Articles Rating plugin - very-very needed
Note: cbe_helpful is based on wlk_helpful, minus some bugs (especially when you switch from percentage display to absolute values, and vice versa)
Offline