News:

CPG Release 1.6.29
During HTML5 upload, keep pseudo blank code 200 messages from triggering error condition
added Russian language
correct failure to use theme menu icons in album manager
minor vulnerabilities mitigation

Main Menu

Security Patch

Started by haggis, October 19, 2003, 03:52:01 AM

Previous topic - Next topic

0 Members and 1 Guest are viewing this topic.

haggis

Will there be (is there now) a security patch for the SQL injection vulnerability in 1.0, 1.1, etc.? The FAQ suggests one will be available Real Soon Now. Version 1.2 doesn't mention it one way or the other. Having been bitten by the previous vulnerability I'm eager to patch as soon as possible.

Tarique Sani

AFAIK and can check the code the SQL injection flaw was fixed by Greg himself BUT never marked as fixed
SANIsoft PHP applications for E Biz

Joachim Müller

I'll edit the faq asap

GauGau